Information Security Specialist - Karnov Group

Karnov Group Denmark A/S

København

Hybrid

DKK 700,000 - 950,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Karnov Group Denmark A/S is seeking an Information Security Specialist to translate customer security, AI and privacy requirements into actionable information security requirements and to embed security into our products and cloud architecture. You will maintain ISMS, collaborate with cross-functional teams, and support day-to-day compliance activities.

The role requires 3–5 years in Information Security/IT Risk, strong knowledge of ISO 27001 and related standards, cloud experience (GCP/Azure),

Qualifications

  • 3–5 years of experience in Information Security, IT Risk, or Technical GRC roles (SaaS, FinTech, LegalTech or cloud-native)
  • Solid understanding of ISO 27001, ISAE 3402, SOC 2, CIS Benchmarks, and NIS2
  • Experience in cloud environments (GCP/Azure) and secure software lifecycle (OWASP)
  • Experience in vendor risk assessments and customer security evaluations
  • Strong ability to translate technical risks into business language for stakeholders

Responsibilities

  • Define security baselines for cloud platforms, APIs, and application development (DevSecOps).
  • Maintain customer-facing security documentation and respond to security questionnaires.
  • Conduct risk assessments of third-party vendors, SaaS tools, and AI service providers.
  • Support ISMS governance, monitor control effectiveness and provide remediation guidance.
  • Coordinate security initiatives with Information Security, Privacy, Security Operations and other teams across Europe

Skills

Information Security
IT Risk
GRC
Cloud security
Vendor risk assessments
Stakeholder management
ISO 27001

Education

Bachelor's degree in Computer Science, Information Security, Business Information Systems, or equivalent

Job description

Are you motivated by bridging the gap between governance, risk, and technical implementation? Do you want to play a pivotal role in maturing security across modern SaaS platforms, cloud environments, and emerging AI capabilities?

At Karnov Group, we are transforming into a leading digital legal-tech and information services company. We are looking for an Information Security Specialist to join our pan-European team. In this role, you will ensure our security standards, policies, and regulatory obligations are effectively embedded into our digital products, development practices, and cloud architecture.

About the job | Governance, Risk and Technical Assurance

Your primary focus will be to understand, assess and translate customer security, AI and privacy requirements and regulatory requirements into a coherent set of information security requirements that define Karnov Group’s organisational security level and the security level for our digital products. You will ensure that the requirements are relevant, operationally applicable and communicated to our technical teams. At the same time, you support day-to-day compliance activities by keeping security controls and evidence up to date, maintain security policies and principles as part of managing and developing our Information Security Management System (ISMS).

Among other things, you will be responsible for:

  • Product & Development alignment: Collaborate with product, development, and architecture teams to define security baselines for cloud platforms, APIs, and application development (DevSecOps).
  • Customer assurance & Sales enablement: Maintain customer facing technical security documentation and collaborate with sales/legal teams to address security questionnaires and customer security requirements.
  • Supply Chain Risk Management: Conduct risk and security assessments of third-party vendors, SaaS tools and AI service providers
  • Controls & ISMS Management: Support the continuous improvement of our Information Security Management System (ISMS), monitoring control effectiveness and providing actionable remediation guidance.
  • Cross-European Collaboration: Work closely with Information Security, Privacy, Security Operations and Technical teams across our European entities to coordinate cohesive security initiatives.

You will be part of the Group Information Security, Privacy and Compliance team. You will join a competent team and a centrally located workplace in Copenhagen — near Nørreport Station. Partly remote work is part of our work-life-balance.

About you | Excellent analytical & problem-solving skills | Stakeholder management skills

You are a security professional who understands both the regulatory landscape and how modern cloud/SaaS platforms operate. You don’t view security as a blocker, but as an enabler for business growth and customer trust.

Required qualifications:
  • Min. 3–5 years of experience in Information Security, IT Risk, or Technical GRC roles (ideally within SaaS, FinTech, LegalTech, or cloud-native environments).
  • Proven understanding of security frameworks such as ISO/IEC 27001, ISAE 3402, SOC 2, CIS Benchmarks, and NIS2.
  • Solid grasp of cloud environments (GCP/Azure), application security principles (OWASP), and modern software delivery lifecycles.
  • Experience in conducting vendor risk assessments and answering customer security evaluations.
  • Strong stakeholder management: Ability to translate complex technical risks into clear business language for non-technical stakeholders.
  • Fluency in English (both written and verbal) is required; additional European languages (Spanish, French, Danish, or Swedish) are a plus.
  • Bachelor’s degree in Computer Science, Information Security, Business Information Systems, or equivalent.
Preferred certifications (or experience with):

Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CRISC, CISM, CISA, CCSP, or cloud security credentials (e.g., Azure AZ-500 / SC-100, GCP Professional Cloud Security Engineer).

About Us | Psychological Safety | "we walk the talk"

Now is the perfect time to become part of Karnov Group! At Karnov Group, you will experience a company in rapid development, where the business is being rethought and digitized, and where we are continuously transforming from a traditional publishing house into a modern information technology company. Karnov Group is a leading provider of critical information across law, tax, auditing and accounting in Denmark, Sweden, Norway, France and Spain. Our solutions are based on reliable knowledge authored by experts and delivered through technology.

Psychological Safety is a cornerstone that supports our cultural values. In our daily operations, we act in accordance with and live up to these values by simply ”walk the talk”. You therefore become part of an attractive work culture and a dynamic environment within an ambitious company, with talented colleagues who support and respect one another. We believe that close collaboration across the entire company helps us serve our customers in the best possible way.

We look forward to hearing from you!

If you have any questions regarding the role or the process, feel free to contact Pia Lundberg Allentoft Miller, Group Chief Information Security Officer (Group CISO), via e-mail: pia.miller@karnovgroup.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Specialist - Karnov Group
Information Security Specialist - Karnov Group

Karnov Group Denmark • København

Hybrid
DKK 800,000 - 1,100,000
Partly remote work
Central Copenhagen location
Security & Compliance Specialist for SaaS & Cloud
Security & Compliance Specialist for SaaS & Cloud

Karnov Group Denmark A/S • København

Hybrid
DKK 700,000 - 950,000
Remote-Eligible Cloud & GRC Information Security Lead
Remote-Eligible Cloud & GRC Information Security Lead

Karnov Group Denmark • København

Hybrid
DKK 800,000 - 1,100,000
Partly remote work
Central Copenhagen location
Information Security Manager | Biotech | Boston or Copenhagen Applied
Information Security Manager | Biotech | Boston or Copenhagen Applied

Black Swans Exist ApS • København

On-site
DKK 900,000 - 1,300,000
Technical Consultant – Security Architecture
Technical Consultant – Security Architecture

SoftwareOne • Søborg

On-site
DKK 850,000 - 1,150,000
Global company culture
Structured onboarding and mentoring
President’s Club
+2
Technical Consultant – Security Architecture
Technical Consultant – Security Architecture

SoftwareONE Deutschland GmbH • Gladsaxe Kommune

Hybrid
DKK 900,000 - 1,300,000
Global company culture
Onboarding and mentoring
President’s Club
+2
Technical Consultant – Security Architecture
Technical Consultant – Security Architecture

SoftwareONE Deutschland GmbH • Denmark

Hybrid
DKK 900,000 - 1,500,000
Global culture
Onboarding & mentoring
President’s Club
+2
Chief Consultant Cybersecurity New København, Capital Region of Denmark, Denmark
Chief Consultant Cybersecurity New København, Capital Region of Denmark, Denmark

Greenhouse Software, Inc. • København

Hybrid
DKK 900,000 - 1,200,000
Bonus
Lunch program
Office snacks
+4
Information Security & Compliance Manager
Information Security & Compliance Manager

Teton • København

On-site
DKK 900,000 - 1,200,000
Senior Security Specialist
Senior Security Specialist

Systematic • Aarhus

On-site
DKK 900,000 - 1,100,000
Physiotherapist massages
In-house hairdresser
Sports clubs
+4