Information Security Governance Specialist

Frontify

Sankt Gallen

Vor Ort

CHF 140.000 - 190.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

25 days annual leave
Parental leave
Pension fund contributions

Zusammenfassung

Frontify, headquartered in St. Gallen with offices in London and New York, is seeking a seasoned Information Security Governance professional. You will own the governance of security programs, drive automation and AI in GRC, and partner with auditors to ensure trust with customers and stakeholders.

You’ll work in a hybrid setup, attending the St. Gallen office weekly, collaborating across teams to elevate our compliance posture and risk management in a SaaS environment.

Qualifikationen

  • 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.
  • Experience as subject‑matter expert in SOC 2 and ISO 27001 audits.
  • Hands-on with modern GRC platforms (Vanta and Conveyor).
  • Strong automation mindset and ability to apply AI to governance processes.
  • Fluent in English; German is a plus.

Aufgaben

  • Own customer security assurance, ensuring questionnaires and audit inquiries are handled accurately and efficiently.
  • Drive day-to-day operation and continuous improvement of compliance programs (ISO 27001, SOC 2, TISAX).
  • Serve as subject‑matter expert during audits and ensure the control environment is audit-ready.
  • Transform compliance into a continuous process by introducing automation and AI into GRC workflows.
  • Design and improve AI-enabled GRC workflows, leveraging LLMs for policy management and risk assessments.
  • Strengthen vendor risk management by scaling assessments through automation.
  • Contribute to continuous improvement of security awareness programs.

Kenntnisse

Information security governance
GRC
Automation
Risk communication

Tools

Vanta
Conveyor

Jobbeschreibung

We're all about helping brands turn ideas into impact. Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns. Our people empower thousands of marketers and designers — including teams at Uber, Microsoft, Volkswagen, and Telefónica — to build engaging brands. With headquarters in St. Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy. And we’re on the lookout for new team members to share our vision. If you’re ready for a brand-new adventure, keep reading!

Your team With the mission of creating a home where all brands (including our own) are safe, the Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders. Security, pragmatism and user friendliness are our guiding principles. Outside of work, we’re gamers, avid bookworms and kickboxers.

Your mission

Trust is what enables the world's leading brands to build on Frontify. Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify. Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.

A key focus of the role is driving the next stage of our security governance maturity. Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits. You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness. This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value.

Your responsibilities
  • You’ll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.

  • You’ll drive the day‑to‑day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.

  • You’ll serve as the subject‑matter expert during audits and ensure our control environment remains effective and audit‑ready.

  • You’ll help transform compliance from a point‑in‑time activity into a continuous process by introducing automation and AI into our Vanta‑based GRC program. This includes improving evidence collection, control monitoring, and access review processes.

  • You’ll design and improve AI‑enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.

  • You’ll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher‑risk vendors receive appropriate human review.

  • You’ll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training.

Your story
  • You’re comfortable working in a hybrid format, with the ability to come to our St. Gallen office once per week.

  • You have 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.

  • You’ve been the subject‑matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.

  • You’re hands‑on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.

  • You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.

  • You’re genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.

  • You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.

  • A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.

  • You speak English fluently. German is a plus.

What we offer
  • A minimum of 25 days annual leave per year
  • Parental, family care, and bereavement leave
  • Daily sickness benefits and accident insurance
  • Paid educational and wellbeing days off
  • Wellbeing, learning and development, and commuter allowance
  • Home office setup budget
  • Pension fund: contributions paid 60% by us and 40% by you
  • Access to exclusive perks and discounts from hundreds of top brands
  • Workation: Work from inspiring locations around the world for up to 45 days per year!
  • Invite to our summer company meet‑up

Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future. We’re committed to an inclusive hiring experience. If you need any support or adjustments during the recruitment process, please let your Talent Partner know when scheduling. Any information shared will be treated confidentially.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Frontend Engineer
Senior Frontend Engineer

Frontify • Sankt Gallen

Hybrid
CHF 120.000 - 170.000
25 days leave
Parental leave
Sickness benefits
+9
Customer Success Manager – 8-month FTC
Customer Success Manager – 8-month FTC

Frontify • Sankt Gallen

Vor Ort
CHF 90.000 - 120.000
25 days annual leave
Education and wellbeing days
Stocked kitchen
+2
Technical Project Manager
Technical Project Manager

Frontify • Sankt Gallen

Hybrid
CHF 120.000 - 160.000
25 days annual leave
Parental leave
Sickness benefits
+7
Professional Services Intern FTC 6 months (50%)
Professional Services Intern FTC 6 months (50%)

Embodied AI • Sankt Gallen

Hybrid
CHF 13.000 - 20.000
25 days annual leave
Educational and wellbeing days off
Stocked kitchen
+1
Professional Services Intern FTC 6 months (50%)
Professional Services Intern FTC 6 months (50%)

Frontify • Sankt Gallen

Vor Ort
CHF 17.000 - 28.000
25 days annual leave
Educational days off
Wellbeing days off
+2
Information Security Risk Manager
Information Security Risk Manager

Sygnum Bank • Zürich

Vor Ort
CHF 140.000 - 190.000
Salary + incentive scheme
Mentoring program
Sabbatical after 5 years
AI-Driven Security Governance & GRC Specialist
AI-Driven Security Governance & GRC Specialist

Frontify • Sankt Gallen

Hybrid
CHF 140.000 - 190.000
25 days annual leave
Parental leave
Pension fund contributions
Full-Stack Software Engineer - AI-Native Product Development
Full-Stack Software Engineer - AI-Native Product Development

xorlab • Zürich

Hybrid
CHF 110.000 - 180.000
Hybrid working
Five weeks of paid vacation
Hardware budget
+2
Customer Success Engineer Cyber Security (Zurich, 100%)
Customer Success Engineer Cyber Security (Zurich, 100%)

xorlab AG • Zürich

Hybrid
CHF 90.000 - 120.000
Employee shares
Transparent compensation
High ownership
+5
Full-Stack Software Engineer - AI-Native Product Development Zürich, Switzerland Employee Software Development
Full-Stack Software Engineer - AI-Native Product Development Zürich, Switzerland Employee Software Development

xorlab AG • Zürich

Hybrid
Confidential
Hybrid working
Office in Zurich
Hardware budget
+4