np. Python, Warszawa, Startup

Head of Information Security and Compliance

location-pointer-icon Warszawa, Kraków
30000 - 43000 PLN
Brutto / Miesiąc / Umowa o pracę
Security
remote

A fast-growing international SaaS group is redefining how the world's most ambitious real estate companies run their operations. Their unified CAFM platform powers the daily operations of over 250 million m² of real estate worldwide, supporting more than 500,000 professionals across 100,000+ buildings in 35+ countries.


The role:

This is the senior security role in the group, and it is yours to build. You will hold the certifications, front the audits, and be the person customers, insurers, and the board ultimately rely on.

The group has grown fast through acquisition: several entities across three countries, each at a different level of maturity, with overlapping but non-identical obligations. Your job is to bring them onto one coherent, credible programme — and keep it that way through the next acquisition. You will do it with a small team and a lot of autonomy. Pragmatism matters more here than process for its own sake.


What you'll own:

  • ISO 27001 and Cyber Essentials Plus across every entity: scope, evidence, audits, recertification, and pulling newly acquired businesses in; if SOC 2 becomes commercially necessary, you make that call and lead it
  • The ISMS and the policies behind it — current, genuinely used, and credible to an auditor
  • GDPR across three jurisdictions — processing records, DPIAs, transfers, subject requests, breach notification
  • Customer security assurance — questionnaires, due diligence packs, and security terms in contracts and DPAs; you join the calls where deals are won or stalled on security
  • Incident response, end to end — you own the plan, you run the response, and you make sure the post-mortem actually changes something
  • Business continuity and disaster recovery for group systems, tested at least annually, plus tabletop exercises with the leadership team
  • Security baselines for endpoints and internal systems (CRM, ERP, email, collaboration) — IT Operations implements, you set them and verify them
  • Risk register, access reviews, and control testing, reported straight to the executive team
  • External partners — MSPs, penetration testers, security vendors, and the cyber insurance relationship
  • Security awareness that people absorb rather than click through

What we're looking for:

  • Led information security and compliance, ideally as the most senior security person in the business
  • Taken ISO 27001 through at least one full audit cycle and know where the bodies are buried
  • Applied GDPR in practice, in more than one country
  • Matured security across businesses at different stages, ideally in a group built by acquisition
  • Builds programmes pragmatically — can tell the difference between real risk reduction and theatre, and protects business velocity while cutting the latter
  • Credible in front of customers, auditors, and the board; can hold a technical line without becoming the reason a deal dies
  • CISSP, CISM, or equivalent
  • Strong professional English; Polish is useful, not essential

What's on offer:

  • Full ownership of security for an international SaaS group, with direct access to the executive team
  • A programme you shape rather than inherit — real problems, real budget, and the mandate to fix them properly
  • Security here enables revenue; it is a visible commercial role, not a back-office one
  • Competitive salary, aligned to the seniority of the role
  • Private medical care, sport card, life insurance, annual training budget, team integration budget
  • Krakow or Warsaw, hybrid
TechHunt
Agency
< 10
Branża
Other, AR/VR, Blockchain
Założona
2010

Ta strona używa plików cookie, aby zapewnić Ci lepsze wrażenia podczas przeglądania.

Dowiedz się więcej o tym, jak używamy plików cookie i jak zmienić preferencje dotyczące plików cookie w naszej Polityka plików cookie.

Zmień ustawienia
Zapisz Akceptuj wszystkie cookies