Information Security & Compliance Manager (all genders)
Core
End-to-end ownership of the Information Security Management System (ISMS), leading ISO 27001 re-certification, managing risk, and ensuring compliance with GDPR, NIS2, and the AI Act for a cloud-native SaaS company.
Role type
Senior Information Security & Compliance Manager (GRC)
Builds
Matured ISMS, automated security monitoring, and compliant operational frameworks for a European retail tech SaaS platform.
Domain
Information Security, Governance, Risk, and Compliance (GRC) in the SaaS/Cloud sector.
Required skills
ISO 27001 (2022) implementation and audit leadership, risk management (ISO 31000/COSO), GDPR framework management, cloud security auditing (GCP/Azure), secure SDLC integration, vendor risk management, regulatory landscape monitoring (NIS2/AI Act).
Preferred skills
CISM, CISSP, CISA, ISO 27001 Lead Implementer/Auditor, experience with GRC platforms (Vanta, Drata), ISO 9001 knowledge.
Technologies
GCP, Azure, CI/CD, Infrastructure-as-Code, Vanta, Drata.
Responsibilities
Lead ISO 27001 re-certification audit cycle, define and build tailored ISMS processes, run company-wide risk management programs, partner with Engineering to embed security-by-design, support Legal/Sales on customer due diligence, oversee vendor risk management, maintain ISO 9001 and GDPR frameworks.
Seniority
Senior, hands-on IC with strategic ownership.