Senior Information Security & GRC Lead

ICEYE

Espoo

Hybrid

EUR 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ICEYE is seeking an Information Security Officer to own and mature the Security Governance, Risk & Compliance program across multiple countries. You’ll drive ISO 27001, NIS2 and CRA compliance, coordinating with governance, legal and engineering teams to ensure audit readiness and practical controls.

You will work in a hybrid model from Espoo, Finland, reporting to the VP Security, with responsibility for cross-jurisdiction frameworks and external audits.

Qualifications

  • Proven hands-on ISO 27001 implementation, audits or maintenance in a real org.
  • Knowledge of NIS2 obligations and translating them into controls and reporting.
  • Familiarity with NIST CSF and 800-53 mappings to ISO 27001/other standards.
  • Awareness of the Cyber Resilience Act (CRA) for products with digital elements.
  • Experience building or maintaining a risk register and running structured risk assessments.
  • Strong stakeholder management to influence engineering, legal and leadership without formal authority.

Responsibilities

  • Own and mature ICEYE's ISO 27001 ISMS, including risk assessments, risk register, SoA, audits and surveillance cycles.
  • Operationalise NIS2 obligations across ICEYE's entities, turning regulations into policies, controls and evidence.
  • Assess CRA and other EU product-security laws against ICEYE's products and close gaps before deadlines.
  • Maintain cross-jurisdiction compliance view (NIST, ISO 27001, NIS2, CRA) across Finland, Germany, Spain, Poland, UK, Greece.
  • Run third-party/vendor security risk assessments and support client due diligence.
  • Produce concise compliance/risk reporting for senior leadership with status against audits/remediation.
  • Maintain security policies and documentation; keep them practical and enforceable.
  • Serve as day-to-day contact for auditors, certification bodies and regulators on GRC matters.

Skills

ISO 27001
NIS2
NIST CSF
CRA awareness
Risk assessments
Stakeholder mgmt
Multi-country regulation
CISSP/CISM/CRISC
AI governance

Tools

GRC tooling (OneTrust etc.)
ServiceNow GRC

Job description

ICEYE is seeking an Information Security Officer to own and mature the Security Governance, Risk & Compliance program across multiple countries. You’ll drive ISO 27001, NIS2 and CRA compliance, coordinating with governance, legal and engineering teams to ensure audit readiness and practical controls.

You will work in a hybrid model from Espoo, Finland, reporting to the VP Security, with responsibility for cross-jurisdiction frameworks and external audits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer – Governance, Risk & Compliance
Information Security Officer – Governance, Risk & Compliance

ICEYE • Espoo

On-site
EUR 90,000 - 130,000
Global Facility Security Lead - Hybrid, Finland
Global Facility Security Lead - Hybrid, Finland

ICEYE • Espoo

Hybrid
EUR 90,000 - 120,000
GRC Engineering Lead - Security Automation & Compliance
GRC Engineering Lead - Security Automation & Compliance

Pliant • Helsinki

Hybrid
EUR 65,000 - 90,000
Attractive remuneration
Flexibility to work remotely
Company card for lunches and coffee
CISO & Internal IT Leader for Scalable SaaS Security
CISO & Internal IT Leader for Scalable SaaS Security

Sympa Oy • Espoo

Hybrid
EUR 120,000 - 180,000
Lunch and cultural benefits
Professional growth support
Facility Security Manager
Facility Security Manager

ICEYE • Espoo

Hybrid
EUR 90,000 - 120,000
Hybrid FP&A Analyst — Corporate Finance (Espoo)
Hybrid FP&A Analyst — Corporate Finance (Espoo)

ICEYE • Espoo

Hybrid
EUR 50,000 - 65,000
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Neste • Espoo

On-site
EUR 90,000 - 120,000
Cybersecurity Operations Leader — Inspire, Detect & Defend
Cybersecurity Operations Leader — Inspire, Detect & Defend

Neste • Espoo

On-site
EUR 110,000 - 165,000
Strategic CISO: Security Leadership, Risk & Compliance
Strategic CISO: Security Leadership, Risk & Compliance

Tieto • Vantaa

Hybrid
EUR 90,000 - 120,000
OT Cybersecurity Engineer – Nordic & UK (Travel)
OT Cybersecurity Engineer – Nordic & UK (Travel)

St1 Nordic Oy • Helsinki

On-site
EUR 90,000 - 120,000