Chief Information Security Officer (CISO)

Sympa Oy

Espoo

On-site

EUR 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Lunch and cultural benefits
Professional growth support

Job summary

Sympa Oy in Espoo, Finland, is seeking a hands-on Chief Information Security Officer to lead information security, compliance, quality governance, and internal IT services in a growing SaaS company.

You will report to the CTO, own ISO 27001 and ISO 9001 programs, drive risk management, audits, and supplier governance, and coach the Security, Compliance, and IT team across Engineering, Product, Legal, and Finance.

Qualifications

  • Hands-on technical understanding and practical execution is required.
  • Experience leading security, compliance, IT, and governance in SaaS.
  • Strong communication in English and Finnish; ability to collaborate cross-functionally.

Responsibilities

  • Own and continuously develop Sympa's information security, compliance, quality, and internal IT capabilities.
  • Drive ISO 27001 and ISO 9001 management systems, controls, and audits.
  • Lead incident management, risk treatment, and awareness activities.
  • Manage internal IT services, identity and access management, and end-user services.
  • Support customer security reviews, audits, tenders, and assurance processes.

Skills

Hands-on security
CISO leadership
ISO 27001
ISO 9001
Risk management
Audits & compliance
Cloud security
CI/CD security
Team leadership

Education

Degree in Computer Science or related field
Professional certifications (CISSP/CISM/CISA)

Job description

Looking for an opportunity to shape, improve, and scale security, compliance, and IT in a growing SaaS company?

At Sympa, information security, compliance, quality, and IT are closely connected to how we operate as a SaaS company and how we build trust with our customers.

We are looking for a hands-on Chief Information Security Officer (CISO) to lead Sympa’s information security, compliance, and quality governance, while also owning our internal IT services and office IT environment, as we continue to grow as a SaaS company.

Location: Espoo, Finland (Hybrid)

Type: Full-time, permanent

Starting date: August-September 2026

For over 20 years, Sympa has helped some of the largest companies in the Nordics put people at the centre of their strategy. Today, we support close to 1,000 customers and continue to invest in our platform, people, and ways of working.

As part of our continued growth, we are now looking for a hands‑on Chief Information Security Officer (CISO) who will report to the CTO and help strengthen and evolve our security, compliance, quality, and IT capabilities while ensuring they continue to support the needs of our business, customers, and employees.

Information security and quality are central to our customer promise. Sympa is ISO 27001 and ISO 9001 certified, and this role plays a key part in maintaining and continuously improving our governance, controls, and operational excellence while supporting future compliance initiatives.

This is a broad CISO and IT role combining CISO responsibilities with ownership of internal IT and compliance governance. You will have the opportunity to shape Sympa's security, compliance, and IT capabilities while working closely with teams across the company to turn ideas, plans, and requirements into practical solutions and measurable improvements.

You will influence long-term direction while remaining closely involved in implementation, operations, and day-to-day decision-making. You will work closely with Engineering, Product, Legal, Sales, Customer Success, HR, Finance, and the Leadership Team while leading a small team responsible for Security, Compliance, and IT.

What you will do

As CISO, you will own and continuously develop Sympa's information security, compliance, quality, and internal IT capabilities.

Your responsibilities include:

  • Leading Sympa's information security strategy, governance model, policies, controls, and risk management practices
  • Owning and continuously improving our ISO 27001 and ISO 9001 management systems and certifications
  • Driving security, compliance, audit, and continuous improvement initiatives across the company
  • Leading information security incident management, awareness activities, and risk treatment processes
  • Owning the direction, governance, performance, and budget of Sympa's internal IT services and office IT environment
  • Ensuring secure, reliable, and cost-effective end-user services, identity and access management, business systems, devices, and collaboration tools
  • Working closely with Engineering and Product teams to support secure software development, cloud security, vulnerability management, and compliance
  • Supporting customer security reviews, audits, tenders, and contract discussions
  • Maintaining customer-facing security and compliance documentation and assurance materials
  • Managing supplier and vendor security governance
  • Leading, coaching, and developing the Security, Compliance, and IT team
  • Building a culture of security, quality, accountability, and continuous improvement across Sympa
What do we offer?

Sympa combines the agility of a growth company with the stability of an established SaaS business. In this role, you will have real ownership, visibility, and influence over how security, compliance, quality, and IT evolve across the organization.

For the right person, this is an opportunity to step into a broad CISO and IT role with real ownership and the ability to leave a lasting mark on how a growing SaaS company operates. You will work closely with teams across the business, help shape key decisions, and contribute to building scalable ways of working that support both our customers and our future growth.

You will join an experienced and collaborative international environment with high ownership, low hierarchy, lunch and cultural benefits, and support for continuous learning and professional growth.

What do we value in our candidates?

We are looking for a builder-minded, hands‑on leader who is excited by the opportunity to shape, improve, and scale security, compliance, and IT in a growing SaaS company.

You enjoy building as much as leading. You get energy from improving how things work, solving problems, helping teams succeed, and turning ideas into practical outcomes that support business goals.

You are comfortable moving between strategic discussions, customer conversations, audits, incidents, operational decisions, and improvement initiatives. You understand how to adapt your approach based on what the business needs most at a given moment.

You enjoy environments where progress comes through collaboration, initiative, and personal ownership rather than large teams or complex organizational structures.

The following skills and experience are needed to succeed:
  • Hands‑on technical understanding and willingness to stay close to implementation and operational realities
  • 8+ years of experience across information security, risk management, compliance, IT, or related areas
  • Experience in senior security, compliance, IT, or technology operations leadership role
  • Strong hands‑on knowledge of ISO 27001 and ISO 9001 management systems, audits, controls, and continuous improvement
  • Strong communication skills in Finnish and English, both written and spoken
  • Good understanding of security frameworks and regulations such as ISO 27001, NIST, GDPR, SOC 2, CIS Controls, or similar
  • Experience leading enterprise IT services, identity and access management, end‑user services, supplier management, budgeting, and procurement
  • Experience working in SaaS, cloud, software product, HR tech, or other technology‑driven environments
  • Understanding of cloud platforms, secure software development, CI/CD practices, vulnerability management, and product security
  • Experience managing teams, coaching people, and driving cross‑functional initiatives
  • Experience supporting customer security reviews, audits, tenders, and assurance processes
  • Proven ability to operate effectively in environments where leaders are expected to combine strategic ownership with practical execution
  • Degree in Computer Science, Engineering, Information Systems, Business Administration, or equivalent practical experience
  • Professional certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or similar are considered an advantage
Interested?

Great! Send us your application via the system and tell us more about yourself. The position will be filled as soon as we find the right candidate.

If you have questions about the role, feel free to contact the hiring manager:

Arttu Heikkilä
CTO
arttu.heikkila@sympa.com

8+ years of experience across information security, risk management, compliance, IT, or related areas, Experience in senior security, compliance, IT, or technology operations leadership role, Strong hands‑on knowledge of ISO 27001 and ISO 9001 management systems, audits, controls, and continuous improvement, Strong communication skills in Finnish and English, both written and spoken, Good understanding of security frameworks and regulations such as ISO 27001, NIST, GDPR, SOC 2, CIS Controls, or similar, Experience leading enterprise IT services, identity and access management, end‑user services, supplier management, budgeting, and procurement, Experience working in SaaS, cloud, software product, HR tech, or other technology‑driven environments, Understanding of cloud platforms, secure software development, CI/CD practices, vulnerability management, and product security, Experience managing teams, coaching people, and driving cross‑functional initiatives, Experience supporting customer security reviews, audits, tenders, and assurance processes, Degree in Computer Science, Engineering, Information Systems, Business Administration, or equivalent practical experience

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Sympa • Finland

Hybrid
EUR 150,000 - 210,000
Lunch and cultural benefits
Learning and development support
CISO & Internal IT Leader for Scalable SaaS Security
CISO & Internal IT Leader for Scalable SaaS Security

Sympa Oy • Espoo

Hybrid
EUR 120,000 - 180,000
Lunch and cultural benefits
Professional growth support
Lead Security Engineer
Lead Security Engineer

Sineeng • Tampere

On-site
EUR 120,000 - 180,000
Paid Time Off
Health & Wellness Package
Lunch Benefit
+14
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Neste • Espoo

On-site
EUR 90,000 - 120,000
Security compliance specialist
Security compliance specialist

GleSYS AB • Helsinki

Hybrid
EUR 50,000 - 70,000
30 days of vacation
Parental leave top-ups
Wellness allowance
+3
Senior Defensive Cyber Security Consultant
Senior Defensive Cyber Security Consultant

Elisa Oyj • Helsinki

Hybrid
EUR 90,000 - 130,000
Staff Security Engineer
Staff Security Engineer

Supermetrics • Helsinki

On-site
EUR 90,000 - 130,000
Equity
Home office allowance
Annual personal learning budget
+1
Hybrid CISO: Security, Compliance & IT Leadership
Hybrid CISO: Security, Compliance & IT Leadership

Sympa • Finland

Hybrid
EUR 150,000 - 210,000
Lunch and cultural benefits
Learning and development support
Software Engineer, S-ID
Software Engineer, S-ID

S Ryhma • Helsinki

Hybrid
EUR 65,000 - 95,000
Performance-based bonus
Extensive employee benefits
Career growth opportunities
Software Engineer, S-ID
Software Engineer, S-ID

Arina • Helsinki

Hybrid
EUR 90,000 - 120,000
Bonus program
Extensive employee benefits