SINGU
SINGU
New

Head of Information Security and Compliance

Brak informacji o wynagrodzeniu
C-Level / ManagerFull-time·B2B·Umowa o pracę
#401064·Dodano 7 dni temu·6
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

ISO 27001 LeadershipGDPR & Data PrivacyRisk Management & GovernanceIncident Response & BCP/DRCustomer Security Assurance

Firma i stanowisko

SINGU is an international SaaS group operating in multiple countries through acquisitions that created a group with several entities in three countries, each at different levels of security maturity requiring unification under one coherent information security and compliance program.

Wymagania

  • Experience leading information security and compliance as senior security leader
  • Successfully managed ISO 27001 through at least one full audit cycle
  • Practical application of GDPR in multiple countries
  • Experienced in maturing security programs across businesses at varying stages, especially in acquisition-driven groups
  • Pragmatic approach to security balancing real risk reduction and business velocity
  • Credible communicator with customers, auditors, and boards, able to maintain technical rigor without blocking deals
  • Professional security certification such as CISSP, CISM or equivalent
  • Strong professional English communication skills; Polish is helpful but not required

Obowiązki

  • Lead ISO 27001 and Cyber Essentials Plus implementation, audits, recertification, and integrate newly acquired businesses
  • Manage the Information Security Management System (ISMS) and maintain current, credible policies
  • Oversee GDPR compliance across three jurisdictions, including processing records, DPIAs, transfers, subject requests, and breach notifications
  • Handle customer security assurance: questionnaires, due diligence packs, security terms in contracts and DPAs; participate in deal-related security discussions
  • Own end-to-end incident response: planning, executing response, and ensuring effective post-mortems
  • Manage business continuity and disaster recovery for group systems, including annual tests and tabletop exercises with leadership
  • Define and verify security baselines for endpoints and internal systems such as CRM, ERP, email, and collaboration
  • Maintain risk register, access reviews, and control testing, reporting directly to the executive team
  • Manage relationships with external partners such as MSPs, penetration testers, security vendors, and cyber insurance providers
  • Implement effective security awareness programs that engage employees

What This Role Is Not:

  • Responsible for product and infrastructure security, which belong to Platform Engineering
  • Responsible for daily administration of laptops and internal systems, which belong to IT Operations

Benefity

  • Full ownership of security for an international SaaS group with direct executive access
  • Opportunity to build and shape the security program with real budget and mandate
  • Security role visible and instrumental in enabling revenue growth
  • Competitive salary aligned to seniority
  • Private medical care
  • Sport card
  • Life insurance
  • Annual training budget
  • Team integration budget
Opieka zdrowotna
Karta sportowa
Ubezpieczenie
Dofinansowanie szkoleń
Spotkania integracyjne

Inne informacje

Informujemy, że administratorem danych jest Velis RET sp. z o.o. z siedzibą w Krakowie, ul. Podole 60 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Rocket Jobs oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.

SINGU

SINGU

8 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz