Information Security Officer – Governance, Risk & Compliance
Core
Own and mature the Security Governance, Risk and Compliance program across a multi-country footprint for a sovereign space intelligence company, ensuring compliance posture is credible to government and defence customers.
Role type
Senior individual contributor Information Security Officer (GRC)
Builds
Compliance posture, risk registers, security policies, and audit-ready documentation for a space technology and defence intelligence product.
Domain
Space technology, sovereign defence, and regulated industries
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001 implementation and audit, NIS2 regulatory translation, NIST framework mapping, Cyber Resilience Act assessment, risk register management, stakeholder influence, cross-jurisdictional compliance navigation, AI governance awareness
Preferred skills
Defence or aerospace industry experience, classified information handling frameworks, GRC tooling proficiency
Technologies
ISO 27001, NIS2, NIST CSF, NIST 800-53, CRA, ISO 42001, NIST AI RMF, ServiceNow GRC, OneTrust, Vanta
Responsibilities
Own and improve ISO 27001 ISMS including risk assessments and audits; Track and operationalise NIS2 obligations; Assess Cyber Resilience Act implications; Maintain cross-jurisdiction compliance views; Run third-party security risk assessments; Prepare compliance reporting for senior leadership; Maintain security policies and standards; Act as point of contact for external auditors and regulators
Seniority
Senior, hands-on IC
