Your tasks
- Own the ISO program end-to-end: take ISO/IEC 27001 to certification, with ISO/IEC 42001 (AI management system) as the next stage — from approving the prepared document set through internal audits and management reviews to a passed certification audit
- Assume the Information Security Officer (ISB) function: approve policies and the Statement of Applicability, steer the risk register and risk owners, represent the ISMS to the certification body
- Translate EU regulation into living processes: EU AI Act, Cyber Resilience Act (including vulnerability-reporting processes and on-call arrangements) and NIS2 — you keep us verifiably compliant and on top of deadlines
- Scope, procure and steer external penetration tests; prioritise findings and drive them into the engineering roadmap; provide credible test evidence for customers and partners
- Own the compliance documents in the product and for customers: review, maintain and polish DPAs, TOMs, DPIA templates, the sub-processor list and further evidence
- Build outward trust: security/trust page, vendor questionnaires, tender and assessment responses; lead security conversations with our customers' data-protection, compliance and IT-security stakeholders and with analysts
- Technically vouch for every security and certification claim on the website, in contracts and in sales material — we never say “certified” before it is true, and you are the guardian of that rule
Not part of the role: sales, hands-on pentesting, and code or architecture security — that is what the engineering team is for. You are governance, evidence and external credibility.