Information Security Governance Specialist

Frontify

Greater London

On-site

GBP 90,000 - 140,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Private health benefits
Pension scheme
25 days annual leave
Education and wellbeing days
Commuter allowance
Work from anywhere (World travel)
Summer company meet-up

Job summary

Frontify is seeking an experienced Information Security Governance professional to own customer security assurance, drive compliance programs, and act as the SME during audits. The role emphasizes automating governance processes and applying AI to enhance evidence collection and control monitoring.

The ideal candidate has 5+ years in SaaS/cloud risk, with hands-on experience in SOC 2 and ISO 27001 audits, and familiarity with Vanta and Conveyor. Hybrid London-based role with global scope.

Qualifications

  • 5+ years of information security governance, GRC, or technology risk in SaaS/cloud environments.
  • Experience leading SOC 2 and ISO 27001 audits—directly on controls and with auditors.
  • Hands-on with modern GRC platforms and a penchant for automation over manual work.

Responsibilities

  • Own customer security assurance, handling enterprise security questionnaires and audit inquiries accurately and efficiently.
  • Drive compliance programs (ISO 27001, SOC 2, TISAX) and stay ahead of regulatory requirements.
  • Serve as SME during audits and ensure control environment remains effective and audit-ready.
  • Lead automation and AI initiatives in Vanta-based GRC to improve evidence collection and monitoring.
  • Design and improve AI-enabled GRC workflows for policy management, risk assessments, and governance activities.

Skills

Security governance
SOC 2 audits
ISO 27001 audits
GRC platforms
Automation
AI in governance
Risk communication

Education

CISA
CISM
CISSP
CIPP

Tools

Vanta
Conveyor

Job description

We're all about helping brands turn ideas into impact. Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns. Our people empower thousands of marketers and designers — including teams at Uber, Microsoft, Volkswagen, and Telefónica — to build engaging brands.

With headquarters in St. Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy. And we’re on the lookout for new team members to share our vision. If you’re ready for a brand-new adventure, keep reading!

Our Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders. Security, pragmatism and user friendliness are our guiding principles. Outside of work, we’re gamers, avid bookworms and kickboxers.

Your mission

Trust is what enables the world's leading brands to build on Frontify. Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify. Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.

A key focus of the role is driving the next stage of our security governance maturity. Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits. You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness. This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value.

Your responsibilities
  • You'll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.
  • You'll drive the day‑to‑day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.
  • You'll serve as the subject matter expert during audits and ensure our control environment remains effective and audit‑ready.
  • You'll help transform compliance from a point‑in‑time activity into a continuous process by introducing automation and AI into our Vanta‑based GRC program. This includes improving evidence collection, control monitoring, and access review processes.
  • You'll design and improve AI‑enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.
  • You'll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher‑risk vendors receive appropriate human review.
  • You'll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training.
Your story
  • You're comfortable working in a hybrid format, with the ability to come to our London office once per week.
  • You have 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.
  • You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.
  • You're hands‑on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.
  • You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.
  • You're genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.
  • You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.
  • A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.
  • You speak English fluently. German is a plus.
What we offer
  • Private health benefits and health cash plan
  • Pension scheme: 5% matched
  • A minimum of 25 days of annual leave per year
  • Paid educational and wellbeing days off
  • Wellbeing, learning and development, and commuter allowance
  • Home office setup budget- Weekly free office lunch
  • Localized benefits
  • Workation: Work from inspiring locations around the world (45 days annually)
  • Invite to our summer company meet‑up

We understand that every candidate’s experience is different. If you’re interested in this role but don’t tick all the boxes, we still encourage you to apply.

Important to us

Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future. We’re committed to providing a fair and accessible recruitment process. If you have a disability and require reasonable adjustments at any stage, please speak with your Talent Partner. Any information you share will remain confidential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technical Support Engineer
Senior Technical Support Engineer

Frontify • Greater London

Hybrid
GBP 60,000 - 90,000
Private health benefits
Pension scheme (5% matched)
25 days annual leave
+5
Senior Technical Support Engineer
Senior Technical Support Engineer

Frontify • City Of London

On-site
GBP 65,000 - 95,000
Private health benefits
Pension scheme
25 days annual leave
+6
Solutions Consultant (EMEA & RoW)
Solutions Consultant (EMEA & RoW)

Frontify • Greater London

On-site
GBP 70,000 - 110,000
Private health benefits
Pension scheme
25 days annual leave
+6
Team Lead, Field and Partnerships Marketing
Team Lead, Field and Partnerships Marketing

Frontify • Greater London

Hybrid
GBP 90,000 - 120,000
Private health benefits
Pension scheme
25 days annual leave
+5
Sales Development Representative (German-Speaking)
Sales Development Representative (German-Speaking)

Frontify • Greater London

On-site
GBP 32,000 - 52,000
Private health benefits
Pension scheme
25 days annual leave
+4
Senior Enterprise Account Manager
Senior Enterprise Account Manager

Frontify • Greater London

On-site
GBP 70,000 - 95,000
Private health benefits
Pension scheme: 5% matched
Minimum 25 days annual leave
+8
Governance Risk and Compliance Manager
Governance Risk and Compliance Manager

Artificial • Greater London

Hybrid
GBP 90,000 - 130,000
Private medical insurance
Income protection insurance
Life insurance of 4 × base salary
+5
Senior Frontend Engineer
Senior Frontend Engineer

IFX Payments • Greater London

On-site
GBP 80,000 - 120,000
25 days annual leave
Birthday day off
Pension scheme
Security GRC Analyst
Security GRC Analyst

Clue • West of England

Hybrid
GBP 60,000 - 70,000
Governance, Risk and Compliance Manager
Governance, Risk and Compliance Manager

Artificial Labs Ltd • Greater London

Hybrid
GBP 90,000 - 130,000
Private medical insurance
Income protection insurance
Life insurance of 4 * base salary
+4