Information Security Officer (ISO)

Ignite Next GmbH

Lausanne

Vor Ort

CHF 110.000 - 150.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Verschicke keinen generischen Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Corintis, based on the EPFL campus near Lausanne, seeks an Information Security Officer to shape and execute its security program. You will lead governance, risk, and compliance efforts, align controls with business needs, and drive KPIs that measure maturity and effectiveness.

You will collaborate with R&D, Customer Success, IT and Operations to embed security across the organization and maintain ISO27001, SOC 2 and GDPR compliance.

Qualifikationen

  • At least 5 years of experience in Information Security with a strong background in GRC.
  • Proven ability to conduct information security risk assessments, gap analyses and drive KPIs/OKRs.
  • Hands-on experience implementing ISO 27001, SOC 2 Type II, CIS Controls v8.1, and GDPR.
  • Strong understanding of business continuity and disaster recovery management.
  • Familiarity with modern GRC platforms such as Drata or Vanta for compliance automation.

Aufgaben

  • Partner with Head of IT Security & Compliance to define and execute Corintis’ information security program.
  • Lead risk assessments, gap analyses, and internal audits to identify weaknesses and remediation.
  • Develop and track governance KPIs; present reports to senior leadership.
  • Ensure ongoing compliance with ISO 27001, SOC 2, GDPR and related standards.
  • Promote security training and awareness across the organization.

Jobbeschreibung

Working with many of the world’s largest tech companies, our solutions improve compute sustainability and tackle the excessive electricity consumption associated with data center cooling, which consumes more electricity than New York and London combined.

Ranked as the No.1 Engineering startup in Switzerland for 2025, Corintis offers a friendly and team-oriented workplace, bringing together over 105 people from over 25 nationalities to solve the most significant computing challenges of tomorrow. Based on the EPFL campus near Lausanne, we are closely connected to the local ecosystem and are located a few minutes walk from Lake Geneva.

THE ROLE

The Information Security Officer (ISO) partners closely with the Head of IT Security & Compliance to shape and execute Corintis’ information security program.

The ISO plays a key role in Governance, Risk, and Compliance (GRC) management, developing and implementing security requirements and controls that align with business goals, customer expectations, and applicable compliance standards.

This role is responsible for performing risk assessments, conducting gap analyses, and contributing to metrics and key performance indicators (KPIs) that measure the maturity and effectiveness of Corintis’ security posture.

As a champion of proactive risk management and a strong security culture, the ISO ensures that information security best practices are integrated across all areas of the organization.

KEY RESPONSIBILITIES
GOVERNANCE
  • Partner with the Head of IT Security & Compliance to define and execute Corintis’ information security program.
  • Support the development and continuous improvement of the company’s security framework.
  • Define and track Key Performance Indicators (KPIs) to evaluate the maturity and effectiveness of the security program.
  • Prepare and present risk, compliance, and performance reports to senior leadership and relevant committees.
  • Support ongoing compliance with key standards such as ISO 27001, SOC 2, and GDPR.
  • Collaborate across functions—particularly with R&D, Customer Success, IT, and Operations.
  • Continuously review, refine, and strengthen existing governance and security practices.
RISK MANAGEMENT
  • Lead and perform regular risk assessments, compliance gap analyses, and internal audits to identify security weaknesses and recommend remediation.
  • Support customer and third‑party due diligence activities.
  • Maintain the corporate risk register, documenting identified risks, mitigation strategies, and resolution progress.
  • Ensure executive visibility of key risks and risk trends through structured reporting and stakeholder communication.
COMPLIANCE MANAGEMENT
  • Monitor and evaluate the security compliance of business operations.
  • Design and implement pragmatic, fit‑for‑purpose security controls.
  • Oversee the operation and continuous improvement of Corintis’ Information Security Management System (ISMS).
  • Track relevant standards and evolving customer, industry, and regulatory requirements.
TRAINING AND AWARENESS
  • Partner with legal, privacy, and compliance teams to manage contractual and regulatory aspects of information security.
  • Serve as a visible advocate for information security across the organization, fostering a culture of accountability and awareness.
  • Contribute to the company’s ongoing security awareness initiatives, including training sessions and targeted communications.
  • Promote a risk‑conscious mindset across all departments to ensure security principles are applied consistently throughout the business.
INCIDENT MANAGEMENT
  • Support the incident response process, coordinating with internal and external stakeholders.
  • Participate in post‑incident reviews to identify lessons learned and propose continuous improvements to processes and controls.
  • Provide leadership with timely reports on incident trends, risk metrics, and recommendations to enhance organizational resilience.
REQUIREMENTS
  • At least 5 years of experience in Information Security, with a strong background in GRC within technology‑driven or regulated environments.
  • Proven track record in conducting information security risk assessments, implementing risk mitigation strategies, and driving continuous improvement in security posture.
  • Demonstrated expertise in performing compliance gap analyses and developing measurable security KPIs and OKRs.
  • Hands‑on experience implementing and maintaining security standards such as ISO 27001, SOC 2 Type II, CIS Controls v8.1, and GDPR.
  • Solid understanding of business continuity and disaster recovery management.
  • Pragmatic approach to risk management, balancing security needs with operational efficiency.
  • Familiarity with modern GRC platforms such as Drata or Vanta for compliance automation and reporting.
  • Well‑rounded knowledge of information security beyond GRC.
  • Highly organized, capable of working independently, and experienced in applying project management methodologies.
  • Skilled at managing multiple priorities in a dynamic, fast‑paced, and agile environment.
  • Excellent communication and interpersonal skills, with the ability to engage confidently with auditors, customers, and cross‑functional teams.
  • Relevant professional certifications such as CRISC, CISM, CISSP, ISO 27001 Lead Implementer, or ISO 22301 Lead Implementer are strongly preferred.
THIS IS A GREAT FIT IF YOU
  • Enjoy working in a fast‑paced, innovation‑driven environment.
  • Are motivated by building and improving security programs from the ground up.
  • Bring a pragmatic mindset to security and compliance.
  • Take ownership of projects and enjoy shaping processes rather than simply maintaining them.
  • Value transparency, teamwork, and open communication across diverse technical and non‑technical teams.
  • Are curious by nature and committed to continuous learning.
THIS WON’T BE THE RIGHT ROLE FOR YOU IF
  • You prefer working in a large, highly structured organization with well‑established security frameworks already in place.
  • You’re looking for a role focused solely on policy writing or compliance checklists.
  • You are not comfortable navigating ambiguity or adapting priorities as the organization and its customer landscape evolve.
  • You would rather work fully remotely without regular in‑person collaboration.
  • You seek roles where customer interaction is minimal.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Officer (ISO)
Information Security Officer (ISO)

Next Matter • Lausanne

Vor Ort
CHF 120.000 - 170.000
Information Security Strategist & Risk Lead
Information Security Strategist & Risk Lead

Next Matter • Lausanne

Vor Ort
CHF 120.000 - 170.000
Strategic Information Security & GRC Lead
Strategic Information Security & GRC Lead

Ignite Next GmbH • Lausanne

Vor Ort
CHF 110.000 - 150.000
Supplier Quality Engineer
Supplier Quality Engineer

Ignite Next GmbH • Lausanne

Vor Ort
CHF 90.000 - 130.000
Director of Operations and Supply Chain
Director of Operations and Supply Chain

Founderful • Lausanne

Vor Ort
CHF 180.000 - 240.000
Director of Operations and Supply Chain
Director of Operations and Supply Chain

Corintis • Lausanne

Vor Ort
CHF 210.000 - 280.000
Supplier Quality Engineer
Supplier Quality Engineer

Corintis • Lausanne

Vor Ort
CHF 110.000 - 140.000
Contract Manufacturing Lead
Contract Manufacturing Lead

Ignite Next GmbH • Lausanne

Vor Ort
CHF 150.000 - 210.000
Information Security Governance Specialist
Information Security Governance Specialist

Frontify • Sankt Gallen

Hybrid
CHF 140.000 - 190.000
25 days annual leave
Parental leave
Pension fund contributions
Contract Manufacturing Lead
Contract Manufacturing Lead

Corintis • Lausanne

Vor Ort
CHF 120.000 - 180.000