Logga in
Sök med AILogga in
JobbSafariLediga jobbSecurity & Compliance Officer

Security & Compliance Officer

Bambuser AB

Sammanfattning

Join a fast-paced scale-up in Stockholm as a key player in managing the information security management system (ISMS) and ensuring compliance with data privacy regulations. You will oversee ISO 27001 governance, prepare for audits, and drive policy adoption while automating processes to enhance efficiency. This hybrid role requires a proactive approach to security and risk management, with a focus on continuous improvement and stakeholder engagement.
Visa hela jobbannonsen

Jobbet i korthet

Arbetstid

heltid


Stockholm

Ansök senast: Öppet tillsvidare
Publicerad: 2026-05-12

Beskrivning

While we welcome applications from everywhere, please note that at this stage we are prioritizing candidates who are already based in Stockholm and eligible to work in Sweden without visa sponsorship.

Reporting to: VP Operations

Job description

You'll own Bambuser's information security management system (ISMS), our data privacy and compliance frameworks, and our operational risk registers. Day to day, that means you're the person making sure and supporting the business that we adhere to the regulations we're subject to, that our policies are sane and current, and that we walk into every audit ready rather than scrambling.

We're a fast-moving scale-up, so we need you thinking the way we all try to think: what can be automated, templated, or scheduled instead of done by hand again? If you find yourself doing the same manual task twice, we want you to build the system that makes sure you never do it a third time, and ideally, that nobody else on the team has to either.

Main duties and responsibilities
  • ISMS Governance & Audit ReadinessOwn and maintain the ISO 27001 governance framework, driving continuous improvement of the ISMS to sail through surveillance audits and recertification. Prepare for and run internal and external audits end to end: scoping, evidence collection, stakeholder coordination, and findings remediation. Build playbooks and control documentation that hold up under scrutiny, not just look good on paper.
  • Keeping Policies Sharp, Not Just CompliantOwn the full ISMS library. Review what exists for relevance, overlap, and gaps, and right-size it to match the actual risk profile, not more, not less. Drive adoption across the org through clear communication and practical enablement so policies get followed in practice.
  • The Face of Security to Customers and VendorsServe as the go-to contact for enterprise customer security reviews, owning the information security sections of RFPs and keeping the Trust Center current. Lead the rollout of the RFP AI tool. On the procurement side, act as the information security reviewer for new tools and vendors, assessing data handling, access, and integration risk before adoption, AI tools included.
  • Staying Ahead of Regulation, Including AITrack the regulatory landscape across all markets: GDPR and international privacy law, information security standards, sector-specific rules. Turn that into concrete controls and clear internal ownership. Keep an eye on where AI regulation (like the EU AI Act) is heading, and start building the groundwork, risk classification and usage guidelines, before it becomes urgent.
  • Security Testing and Training That SticksCoordinate and support penetration testing engagements: scoping with vendors, arranging internal access, chasing findings through to remediation. Own the security training program end to end, designing and delivering onboarding and recurring awareness training, and keeping it fresh as threats and regulations shift.
  • Systems, Not Just ProcessesLead adoption of Bambuser's new operating model, making sure people understand and own their part in it. Turn security workflows that currently live in someone's head into documented, scalable processes. Wherever there's a recurring task, evidence collection, training reminders, audit scheduling, the default should be to automate it rather than track it manually.
  • Data Privacy and RiskOversee GDPR and international privacy compliance across every market, looping in external counsel when needed. Run the Senior Management risk assessment process, keeping the corporate Risk Register current and tied to what the business actually cares about.


Requirements
  • Experience: 5+ years in information security compliance, IT audit, or risk management, ideally in B2B SaaS or another fast-growing tech company.
  • ISO 27001: A track record of implementing or maintaining ISO/IEC 27001 certifications. Experience running or supporting penetration testing programs is a plus.
  • Privacy know-how: A strong, practical grasp of GDPR in multi-tenant SaaS environments.
  • Regulatory radar: Familiarity with where AI regulation (like the EU AI Act) is headed and what it means for a tech business.
  • Pragmatism: You can turn complex regulatory requirements into workflows that don't grind the business to a halt.
  • Communication: You're comfortable translating technical security risk into business terms, for executives, for enterprise customers, and for a room full of people at a training session.
  • An automation instinct: You default to building the system rather than repeating the task, comfortable with workflow automation, reminders, scheduling tools, and AI-assisted drafting to cut busywork, both your own and everyone else's, so time goes toward the work that actually needs a human.
  • Proactive and solutions-oriented: You identify risks, spot patterns, and anticipate future needs, rather than waiting for problems to surface.
  • Bonus: Experience working in or with publicly listed companies, including familiarity with their internal control requirements.


Locations Stockholm Remote status Hybrid

Ansök till tjänsten

Security & Compliance Officer

Denna arbetsplats har annonserats på Compilation Source (Sweden)-tjänsten den 2026-05-12 och publicerades av Compilation Source (Sweden).

OM FÖRETAGET

Bambuser AB
Visa alla jobb för Bambuser AB

Hittade du inte vad du letade efter?

Beskriv med dina egna ord vad du söker, precis som om du skulle förklara det för en kompis. Josi hittar jobb som matchar dig på riktigt.
Testa nu

Sök efter fler liknande jobb

StockholmEkonomi och juridikCompliance officer

Läs också

Anna Eriksson sadlade om från ingenjör till lärare: ”Nu kan jag göra verklig skillnad!”
Jobbsökning

Anna Eriksson sadlade om från ingenjör till lärare: ”Nu kan jag göra verklig skillnad!”

Anna Eriksson jobbade som IT-utvecklare och trivdes med det men saknade känslan av att ha ett meningsfullt jobb. Det var så hon fick idén om att sadla om till lärare. Genom Teach for Sweden har hon fått möjlighet att läsa ledarskapsprogrammet och kan nu göra större skillnad för framtidens vuxna. – Det som lockade mig var […]

Lästid 2 min

Liknande jobb

Visa alla lediga jobb
CGI Sverige AB

Senior Security Engineer - Application

Stockholm
9/7 – tillsvidare

Jobb per stad

Det är enklare än någonsin att söka jobb – men svårare än någonsin att hitta rätt. Det vill vi ändra på. JobbSafari är din guide genom arbetslivet, byggd för att matcha rätt person med rätt möjlighet bland tusentals lediga jobb i Sverige.

JobbSafari är en del av Duunitori Group – Duunitori är Finlands största jobbsökmotor och en betrodd partner inom rekrytering, rekryteringsmarknadsföring och employer branding.

Stockholm, Sweden

JobbSafari AB

Grev Turegatan 11A

114 46 Stockholm, Sweden

info@jobbsafari.se

+46 (0) 8 515 10 774

Helsinki, Finland

Duunitori Oy

Toinen Linja 7

00530 Helsinki, Finland

asiakaspalvelu@duunitori.fi

+358 44 980 3558

Oslo, Norway

JobbSafari AB

c/o Accountor AS

Tangen 75

4608 Kristiansand, Norge

info@jobbsafari.se

+46 70 314 59 79

  • jobbsafari.se
  • duunitori.fi
  • jobbsafari.no
  • allaloner.se
  • jobbland.se