Manager - Information Security (Compliance)

Basware

Espoo

On-site

EUR 90,000 - 120,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Basware is seeking a Manager - Information Security (Compliance) to lead governance, risk, and assurance activities across the organization. You will guide customers, auditors and internal teams with practical, risk‑based information security guidance and drive continual improvement of the security compliance program.

The role partners with business and solution owners to ensure audit readiness, maintain the risk register, and support remediation actions.

Qualifications

  • Minimum of two years’ experience in information security or security compliance.
  • Strong knowledge of recognised information security control frameworks and assurance standards (ISO/IEC 27002, PCI DSS, NIST CSF, ISAE).
  • Practical experience of information security risk management including identification, assessment, treatment and reporting.
  • Experience supporting internal or external audits, evidence collection, control testing and remediation tracking.

Responsibilities

  • Customer and stakeholder assurance: manage security advisory requests from customers, prospects and partners; provide practical information security guidance to colleagues and stakeholders.
  • Risk, supplier assurance and business continuity: conduct third‑party risk assessments, maintain the risk register, and support BIA reviews.
  • Audit and corrective action management: plan and coordinate internal audits, gather evidence, and track corrective actions with owners.
  • Compliance initiatives and awareness: develop security training and drive compliance improvements with clear plans and stakeholder communication.

Skills

Security governance
Risk management
Audit support
Stakeholder engagement
Information security controls

Job description

At Basware, we deliver mission-critical cloud solutions that empower organizations to unlock their full potential. Our products are designed to bring clear and compelling value to our customers, and we’re looking for talented and forward-thinking professionals who can help us shape the future of our technology.

We are seeking a Manager - Information Security (Compliance),an experienced security compliance specialist who thrives at the intersection of governance, risk management, and stakeholder engagement. In this role, you will help ensure that Basware maintains a robust and effective security compliance program while supporting customers, auditors, suppliers, and internal teams with practical, risk-based guidance.

The Information Security Compliance team supports the organisation in maintaining an effective, risk-based information security management system. The Manager - Information Security (Compliance) will coordinate key compliance, assurance and risk management activities, working closely with business and solution owners to strengthen security governance, support audit readiness and drive continual improvement.

Customer and stakeholder assurance
  • Manage the Security Advisory process, including completion of due diligence questionnaires, requests for information and general information security queries from customers, prospects, partners and customer-facing colleagues.
  • Provide practical information security and compliance advice to colleagues, projects, solution owners and business stakeholders, escalating material risks where appropriate.
Risk, supplier assurance and business continuity
  • Conduct and support third-party information security risk assessments and periodic supplier reviews, documenting findings, risks, recommendations and follow-up actions.
  • Maintain the information security risk register, coordinate periodic risk reviews, monitor treatment actions and support the CISO and risk owners in recording clear, proportionate and current risk information.
  • Support business continuity activities, including assisting business owners with the completion and review of Business Impact Analyses and tracking related actions.
Audit and corrective action management
  • Plan, coordinate and perform internal information security audits, record audit evidence and findings, and monitor agreed corrective actions and opportunities for improvement.
  • Support external audits and assurance activities by coordinating evidence, engaging relevant control owners and responding to auditor queries.
  • Agree appropriate corrective actions and implementation dates with control owners, and proactively support delivery to ensure agreed timelines are achieved.
Compliance initiatives and awareness
  • Develop appropriate security training and communications that promote a positive information security culture.
  • Manage assigned compliance initiatives and improvement activities, maintaining clear plans, priorities, dependencies and stakeholder communications.
Experience and technical knowledge
  • Minimum of two years’ experience working in information security or security compliance.
  • Strong knowledge of recognised information security control frameworks and assurance standards, such as ISO/IEC 27002, PCI DSS, the NIST Cybersecurity Framework and ISAE standards.
  • Practical experience of information security risk management, including risk identification, assessment, treatment, monitoring and reporting.
  • Experience supporting internal or external audits, evidence collection, control testing and remediation tracking.
Communication and stakeholder engagement
  • Strong written and verbal communication skills, with the ability to explain security and compliance requirements clearly to technical and non-technical audiences.
  • Strong influencing and stakeholder management skills, with the confidence to provide constructive challenge and secure commitment to agreed actions.
Planning, organisation and working style
  • Effective project management and organisational skills, with the ability to manage competing priorities, actions and stakeholders.
  • A structured, detail-focused and improvement-oriented approach, with sound judgement and the ability to work both independently and collaboratively.
Professional qualifications
  • Relevant professional certification or training in information security, audit, risk or compliance is desirable.
  • Experience with AI tools, frameworks or applications is considered a strong asset. We highly value candidates who demonstrate curiosity, a proactive mindset and a willingness to explore and incorporate AI-driven technologies into their work. We encourage growth in this area and provide opportunities for experimentation and learning.
Why Basware?

We’re a purpose-driven company with a global footprint and a collaborative culture. At Basware, you’ll work with passionate professionals, cutting-edge technology, and a shared commitment to innovation and excellence.

Basware. Now it all just happens.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - Information Security (Compliance)
Manager - Information Security (Compliance)

Basware • Tampere

On-site
EUR 90,000 - 130,000
Security Compliance Manager: Risk, Audits & Governance
Security Compliance Manager: Risk, Audits & Governance

Basware • Tampere

On-site
EUR 90,000 - 130,000
Security Compliance Manager - Audit, Risk & Governance
Security Compliance Manager - Audit, Risk & Governance

Basware • Espoo

On-site
EUR 90,000 - 120,000
Senior Cloud Developer
Senior Cloud Developer

Basware • Espoo

On-site
EUR 60,000 - 80,000
Senior Product Manager
Senior Product Manager

Basware • Espoo

Hybrid
EUR 90,000 - 130,000
Flexible work arrangements
International environment
Work-life balance
Senior Product Manager
Senior Product Manager

Basware • Tampere

Hybrid
EUR 90,000 - 120,000
SaaS Sales - Senior Account Executive
SaaS Sales - Senior Account Executive

Basware • Espoo

On-site
EUR 90,000 - 120,000
Great culture
Home-based option
Global reach
Senior Cloud Developer
Senior Cloud Developer

Basware Oyj • Espoo

On-site
EUR 90,000 - 120,000
HR AI & Technology Lead
HR AI & Technology Lead

Basware • Espoo

Hybrid
EUR 90,000 - 150,000
Flexible hybrid work arrangements
Competitive salary
Wellbeing benefits
+1
Information Security Manager (GRC Engineering) (m/f/d)
Information Security Manager (GRC Engineering) (m/f/d)

Pliant GmbH • Finland

Hybrid
EUR 90,000 - 130,000
Remote-friendly
Competitive salary
Lunch card