Information Security Lead (OT Security, Video Data Privacy & SOC 2)
Tech Stack / Keywords
Firma i stanowisko
Our client is a Swiss AI scale-up with a platform monitoring manufacturing lines through cameras. Their product operates in plants worldwide across various industries including glass, food and beverage, consumer goods, building materials, and wood. The platform integrates within customers' industrial networks, interfaces with machines, and processes footage containing plant staff, raising significant security and privacy concerns that the role addresses.
Wymagania
- 6+ years of hands-on experience in information security encompassing implementation and operation of controls.
- Practical experience with SOC 2 audits in product or SaaS environments, preferably extending ISO 27001 programs.
- Expertise in OT/industrial network security, including segmentation, Purdue model, IEC 62443, secure remote access, and third-party system security for PLCs and line equipment.
- Solid knowledge of data privacy practices including GDPR, DPIAs, privacy by design, anonymisation, and handling of personal data for AI training.
- Proficiency in English at C1 level for policy writing and customer communications.
- Pragmatic, independent work style suitable for a fast-paced, young company environment.
Nice to have:
- German language skills.
- Certifications: CISSP, CISM, CISA, GICSP, ISA/IEC 62443, ISO 27001 Lead Implementer or Lead Auditor, CIPP/E.
- Knowledge of Swiss revFADP, NIS2, EU AI Act.
- Experience with compliance tooling like Vanta, Drata or Secureframe.
- Cloud security experience on AWS, GCP or Azure, and container technologies including Kubernetes.
- Background in manufacturing, machine vision, IIoT, or video surveillance products.
Obowiązki
- Define integration and connectivity of cameras, on-site devices, and equipment into OT networks including segmentation, firewall rules, cloud connectivity, remote access, hardening, and patching.
- Serve as the security liaison with customers’ IT, OT, and security teams through questionnaires, architecture reviews, documentation, and calls.
- Lead SOC 2 compliance activities building on ISO 27001, including gap assessment, controls mapping to Trust Services Criteria, policy creation, evidence collection, and auditor collaboration.
- Manage privacy for video and image data including DPIAs, data-flow mapping, retention/deletion policies, access controls, and rules for footage use in AI training.
- Advise customers on workplace camera regulations and related employee monitoring laws.
- Own security risk register, vendor risk assessments, incident-response planning, and advise engineering on SOC 2 required controls for cloud and development practices.
Benefity
- Participation in interesting and demanding projects.
- Flexible working hours.
- A great, non-corporate atmosphere.
- Possibility to work remote or hybrid (2 days per week in office).
- Opportunities for development and promotion.
- Attractive package of benefits.
Inne informacje
Informujemy, że administratorem danych jest Transition Technologies MS S.A. z siedzibą w Warszawie, ul. Chmielna 69. Masz prawo do żądania dostępu, sprostowania, usunięcia danych osobowych oraz innych praw określonych w RODO. Dane są przetwarzane w celu realizacji procesu rekrutacji zgodnie z obowiązującymi przepisami prawnymi.
Transition Technologies MS
20 aktywnych ofert