Polysense is scaling fast. We're building operational intelligence software that's reshaping how food manufacturers work. Customers like Agristo, Lotus Biscoff, and La Lorraine are already running on it. As we grow, so do the expectations around how we handle data, infrastructure, and trust. Security and compliance are no longer nice to have. They're core to how we operate and how we sell.
The mission
To build a security and compliance foundation that Polysense's customers can trust, holds up to external scrutiny, and scales with a company that isn't slowing down.
What you’ll be doing
Information security frameworks
- Own ISO 27001 and SOC 2 from end to end – gap analysis, policy development, implementation, certification, and ongoing maintenance.
- Drive NIS2 and CRA compliance as they become increasingly relevant to our operating environment, ensuring obligations are documented and met.
- Develop and maintain the internal policy library: information security policies, access control, risk management, incident response, and everything in between.
- Coordinate with external auditors and specialists during certification cycles, preparing Polysense for conversations and managing the process through to completion.
- Own GDPR compliance – register of processing activities, data protection impact assessments, vendor and sub‑processor reviews, and continuous updates as the product evolves.
- Be the internal reference point for anything data protection related, answering questions from sales, legal, and customers.
- Handle inbound customer security questionnaires and deliver confident, accurate responses.
- Run internal audits and manage relationships with penetration testing partners, owning findings and tracking remediation.
- Build and own the incident response plan, defining roles, response times, and ensuring the plan is tested and understood.
Key point
You do not need deep offensive security skills, but you do need to understand how deep‑tech SaaS or HW/SW SaaS products are built, where they break, and how to close gaps before they become problems.
What you bring – Background & experience
- Meaningful hands‑on experience in a security, compliance or IT role with a clear focus on information security frameworks.
- Solid working knowledge of ISO 27001, SOC 2, GDPR and NIS2, applied in practice.
- Background in IT to understand system architecture and exposure points.
- Familiarity with the tech stack of a deep‑tech SaaS or hardware/software SaaS company – you need to speak the language.
- Experience with Azure, Azure DevOps or a compliance‑automation platform like Vanta.
- Experience in a startup or scale‑up environment – building without a playbook.
- Nice to have: exposure to the food manufacturing or food tech industry.
Mindset & way of working
- You own it fully and set the direction, build the processes, and drive them forward without waiting to be asked.
- Compliance enables, not blocks – you ensure good security makes the business faster, not slower.
- Clear communicator across the board; you translate technical compliance requirements into language that makes sense to all stakeholders and bring people along with you.
What success looks like
- ISO 27001 certification is achieved and maintained through a clear, repeatable process you built and own.
- SOC 2 compliance is structured, documented, and progressing on a timeline you control.
- GDPR, NIS2 and CRA obligations are up to date, owned, and never a source of last‑minute scrambling.
- Customer security questionnaires are handled quickly, accurately, and without pulling in half the company to answer them.
- An incident response plan exists, is tested, and the team knows how to use it.
- Security is embedded in how Polysense builds and ships, not bolted on after the fact.