Information Security Officer

Corintis

Lausanne

Vor Ort

CHF 140.000 - 190.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Corintis is seeking an Information Security Officer to shape and execute the security program, lead risk assessments, and align controls with ISO 27001, SOC 2 and GDPR. You will work with legal, privacy, compliance, and engineering teams to mature governance and drive measurable security outcomes.

You will own risk reporting, KPI development, and ongoing audits while promoting a security‑minded culture across R&D, IT, operations, and customer success. Lausanne area, hybrid/onsite collaboration.

Qualifikationen

  • At least 5 years of experience in Information Security.
  • Proven track record in information security risk assessments.
  • Experience with compliance gap analyses and KPI/OKR development.
  • Hands-on implementation/maintenance of ISO 27001, SOC 2, CIS Controls, and GDPR.
  • Knowledge of business continuity and disaster recovery.
  • Balanced approach to risk management with operational efficiency.
  • Familiarity with GRC platforms like Drata or Vanta.
  • Strong organizational skills and project management experience.
  • Excellent communication and stakeholder management.
  • Relevant certifications (CRISC, CISM, CISSP, ISO 27001 Lead Implementer) preferred.

Aufgaben

  • Partner with the Head of IT Security & Compliance to define and execute Corintis’ information security program.
  • Support the development and continuous improvement of the company’s security framework.
  • Define and track Key Performance Indicators (KPIs) to evaluate the maturity and effectiveness of the security program.
  • Prepare and present risk, compliance, and performance reports to senior leadership and relevant committees.
  • Support ongoing compliance with ISO 27001, SOC 2, and GDPR.
  • Collaborate across functions—R&D, Customer Success, IT, and Operations.
  • Continuously review, refine, and strengthen existing governance and security practices.
  • Lead and perform regular risk assessments, compliance gap analyses, and internal audits to identify security weaknesses and remediation.
  • Support customer and third‑party due diligence activities.
  • Maintain the corporate risk register, documenting risks, mitigation strategies, and progress.
  • Ensure executive visibility of key risks and risk trends through structured reporting.
  • Monitor and evaluate the security compliance of business operations.
  • Design and implement pragmatic, fit‑for‑purpose security controls.
  • Oversee the ISMS operation and continual improvement.
  • Track evolving standards and regulatory requirements.
  • Partner with legal, privacy, and compliance teams on contractual/regulatory aspects.
  • Serve as a visible advocate for information security across the organization.
  • Contribute to security awareness initiatives and training sessions.
  • Promote a risk‑conscious mindset across all departments.
  • Support the incident response process with internal and external coordination.

Kenntnisse

Information Security
Risk Assessments
GRC
Compliance
Security KPIs/OKRs
Communication
Project Management

Tools

ISO 27001
SOC 2
GDPR
Drata
Vanta

Jobbeschreibung

ABOUT CORINTIS

Corintis offers innovative microfluidic cooling technologies for AI chips/GPUs and CPUs used in data centers. Working with many of the world’s largest tech companies, our solutions improve compute sustainability and tackle the excessive electricity consumption associated with data center cooling, which consumes more electricity than New York and London combined. Ranked as the No.1 Engineering startup in Switzerland for 2025, Corintis offers a friendly and team-oriented workplace, bringing together over 105 people from over 25 nationalities to solve the most significant computing challenges of tomorrow. Based on the EPFL campus near Lausanne, we are closely connected to the local ecosystem and are located a few minutes walk from Lake Geneva.


THE ROLE

The Information Security Officer (ISO) partners closely with the Head of IT Security & Compliance to shape and execute Corintis’ information security program. The ISO plays a key role in Governance, Risk, and Compliance (GRC) management, developing and implementing security requirements and controls that align with business goals, customer expectations, and applicable compliance standards. This role is responsible for performing risk assessments, conducting gap analyses, and contributing to metrics and key performance indicators (KPIs) that measure the maturity and effectiveness of Corintis’ security posture. As a champion of proactive risk management and a strong security culture, the ISO ensures that information security best practices are integrated across all areas of the organization.


KEY RESPONSIBILITIES


  • Partner with the Head of IT Security & Compliance to define and execute Corintis’ information security program.

  • Support the development and continuous improvement of the company’s security framework.

  • Define and track Key Performance Indicators (KPIs) to evaluate the maturity and effectiveness of the security program.

  • Prepare and present risk, compliance, and performance reports to senior leadership and relevant committees.

  • Support ongoing compliance with key standards such as ISO 27001, SOC 2, and GDPR.

  • Collaborate across functions—particularly with R&D, Customer Success, IT, and Operations.

  • Continuously review, refine, and strengthen existing governance and security practices.

  • Lead and perform regular risk assessments, compliance gap analyses, and internal audits to identify security weaknesses and recommend remediation.

  • Support customer and third‑party due diligence activities.

  • Maintain the corporate risk register, documenting identified risks, mitigation strategies, and resolution progress.

  • Ensure executive visibility of key risks and risk trends through structured reporting and stakeholder communication.

  • Monitor and evaluate the security compliance of business operations.

  • Design and implement pragmatic, fit‑for‑purpose security controls.

  • Oversee the operation and continuous improvement of Corintis’ Information Security Management System (ISMS).

  • Track relevant standards and evolving customer, industry, and regulatory requirements.

  • Partner with legal, privacy, and compliance teams to manage contractual and regulatory aspects of information security.

  • Serve as a visible advocate for information security across the organization, fostering a culture of accountability and awareness.

  • Contribute to the company’s ongoing security awareness initiatives, including training sessions and targeted communications.

  • Promote a risk‑conscious mindset across all departments to ensure security principles are applied consistently throughout the business.

  • Support the incident response process, coordinating with internal and external stakeholders.


REQUIREMENTS


  • At least 5 years of experience in Information Security.

  • Proven track record in conducting information security risk assessments.

  • Demonstrated expertise in performing compliance gap analyses and developing measurable security KPIs and OKRs.

  • Hands‑on experience implementing and maintaining security standards such as ISO 27001, SOC 2 Type II, CIS Controls v8.1, and GDPR.

  • Solid understanding of business continuity and disaster recovery management.

  • Pragmatic approach to risk management, balancing security needs with operational efficiency.

  • Familiarity with modern GRC platforms such as Drata or Vanta for compliance automation and reporting.

  • Well‑rounded knowledge of information security beyond GRC.

  • Highly organized, capable of working independently, and experienced in applying project management methodologies.

  • Skilled at managing multiple priorities in a dynamic, fast‑paced, and agile environment.

  • Excellent communication and interpersonal skills.

  • Relevant professional certifications such as CRISC, CISM, CISSP, ISO 27001 Lead Implementer, or ISO 22301 Lead Implementer are strongly preferred.


THIS IS A GREAT FIT IF YOU


  • Enjoy working in a fast‑paced, innovation‑driven environment.

  • Are motivated by building and improving security programs from the ground up.

  • Bring a pragmatic mindset to security and compliance.

  • Take ownership of projects and enjoy shaping processes rather than simply maintaining them.

  • Value transparency, teamwork, and open communication across diverse technical and non‑technical teams.

  • Are curious by nature and committed to continuous learning.


THIS WON’T BE THE RIGHT ROLE FOR YOU IF


  • You prefer working in a large, highly structured organization with well‑established security frameworks already in place.

  • You’re looking for a role focused solely on policy writing or compliance checklists.

  • You are not comfortable navigating ambiguity or adapting priorities as the organization and its customer landscape evolve.

  • You would rather work fully remotely without regular in‑person collaboration.

  • You seek roles where customer interaction is minimal.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Officer (ISO)
Information Security Officer (ISO)

Next Matter • Lausanne

Vor Ort
CHF 120.000 - 170.000
Information Security Officer (ISO)
Information Security Officer (ISO)

Corintis • Lausanne

Hybrid
CHF 120.000 - 180.000
InfoSec & GRC Leader: Risk, Compliance, Governance
InfoSec & GRC Leader: Risk, Compliance, Governance

Corintis • Lausanne

Hybrid
CHF 120.000 - 180.000
Security & Compliance Leader: GRC & Risk Champion
Security & Compliance Leader: GRC & Risk Champion

Corintis • Lausanne

Vor Ort
CHF 140.000 - 190.000
Information Security Strategist & Risk Lead
Information Security Strategist & Risk Lead

Next Matter • Lausanne

Vor Ort
CHF 120.000 - 170.000
Office Operations Coordinator
Office Operations Coordinator

Corintis • Lausanne

Vor Ort
CHF 70.000 - 95.000
Office Operations Coordinator
Office Operations Coordinator

Ignite Next GmbH • Lausanne

Hybrid
CHF 70.000 - 100.000
Information Security Governance Specialist
Information Security Governance Specialist

Frontify AG. “Frontify” is a registered trademark of Frontify AG • Sankt Gallen

Hybrid
CHF 120.000 - 170.000
25 days annual leave
Pension fund
Home office setup budget
+1
Information Security Governance Specialist
Information Security Governance Specialist

Frontify • Sankt Gallen

Hybrid
CHF 140.000 - 190.000
25 days annual leave
Parental leave
Pension fund contributions
Delivery Lead
Delivery Lead

SICPA SA • Prilly

Vor Ort
CHF 120.000 - 180.000