Head of Security, Compliance & IT

inRiver inc

Malmö kommun

Hybrid

SEK 1,400,000 - 2,100,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work setup

Job summary

Inriver in Malmö is seeking a hands-on Head of Security, Compliance & IT to lead our Enterprise Security, Product Security, Privacy, Compliance and internal IT functions across a global, PE-backed SaaS company.

You will own the security strategy and roadmap, run a small, focused team, and partner with engineering, Legal and HR while engaging customers, auditors and regulators on security.

Qualifications

  • Proven track record of developing security strategies with real business impact.
  • 5+ years in information security or similar, with at least 2 years in a senior leadership role in a mid-size SaaS/cloud company.
  • Excellent stakeholder management and communication skills.
  • Leadership and coordination of major security incidents.
  • Experience leading compliance audits (ISO 27001 and/or SOC 2 Type 2).
  • English business proficiency; eligibility to work in the EU; based within commuting distance of Malmö for hybrid on-site.

Responsibilities

  • Set the security strategy and roadmap, develop a multi-year plan grounded in business risk, fund it, and lead initiatives.
  • Embed secure SDLC, threat modelling and remediation SLAs in pipelines with product teams.
  • Lead vulnerability management and penetration testing across web apps, API, and cloud.
  • Own the security posture of the Azure environment and lead the Cloud Security Engineer.
  • Run internal IT (M365/Entra ID, device management, identity lifecycle, IT cost) across multiple locations.
  • Lead major security incidents as a core member of the IR team, coordinating with Legal and leadership.
  • Run end-to-end compliance programs across ISO 27001, ISO 27701, SOC 2 Type 2, GDPR, NIS2, EU Data Act and EU AI Act.
  • Own enterprise risk and third-party risk, including BCP/DR and vendor due diligence.
  • Be our security voice with customers in security reviews, RFPs and due diligence.

Skills

Security strategy
Leadership
Stakeholder mgmt
Azure security
Compliance audits
GDPR knowledge
IT management
Security incident response
IA/Threat modelling

Tools

Azure Defender
Intune/MDM
Defender for Cloud
PIM

Job description

At Inriver, we help brands deliver better product experiences - everywhere their customers are. From the first product detail to the final purchase decision, we make product information work smarter. When our platform is secure, our teams ship with confidence and it enhances customer trust. More than 1,600 global brands trust their product data with us.

Now we’re looking for a hands-on Head of Security, Compliance & IT to take over from our outgoing CISO and lead the next chapter of our Enterprise Security, Product Security, Privacy, Compliance and internal IT function.

About the role

You’ll own our security strategy and roadmap - and you’ll deliver it. You’ll lead a small, sharp team across Security and IT, work through a 24/7 managed detection and response partner, and partner with engineering teams that own the security of the code they write. You’ll be the person our customers, our leadership team and our auditors talk to about security. You’ll work from our HQ office in Malmö, supporting our remote locations in Stockholm, Amsterdam, Davao and Manila.

Internal IT sits in this role too - the Microsoft 365 and Entra ID estate, device management, identity lifecycle, our SaaS portfolio and IT cost. That’s deliberate. Most of what makes a company secure - identity, access, endpoints, joiner-mover-leaver, patching - is IT work, so one owner means those foundations get built properly rather than negotiated between two functions.

This is a high-impact role reporting to the CFO, working closely with the wider leadership team, Legal and HR. You’ll be close enough to the work to be credible with engineers, and hands-on when it counts - but you won’t be triaging every alert, and we’ve built the operating model so that you don’t have to.

Why you’ll love this role

Own Enterprise Security, Product Security, Privacy, Compliance and internal IT end-to-end, across a global, PE-backed mid-size SaaS company

A mandate that’s already agreed. Our gate-and-block operating model - security gates that can hold a release - is signed off by the CEO, CTO and CPO. Not a best-effort understanding.

24/7 monitoring is funded. We’re onboarding a managed SOC/MDR partner. Non-major incidents are handled by them, not by you at 3am.

Engineering owns its own findings, remediated against SLAs you agree together. You build the gates and the capability; you don’t chase tickets.

You’re not the risk owner of last resort. Material cyber risk is accepted by the business leaders whose decisions create it, and your escalation path doesn’t stop at your manager.

Run a modern Microsoft Azure security stack, a real product-security program embedded in our SaaS SDLC, and compliance across SOC 2, ISO 27001, ISO 27701, GDPR, NIS2, the EU Data Act and the EU AI Act

What you’ll do

Set the security strategy and roadmap - and deliver it. Build a multi-year plan grounded in business risk, get it funded, and lead the initiatives in it to completion.

Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, set the quality gates, and agree the remediation SLAs product teams work to.

Lead vulnerability management and penetration testing. Scope and commission internal and third-party testing across web application, API and cloud, manage the specialists who run it, and drive findings to closure.

Own the security posture of our Azure environment. Harden our infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC) and lead our Cloud Security Engineer so our product runs on secure architecture.

Run internal IT as a foundation, not a help desk. Own the M365 and Entra ID estate, device management, identity and access lifecycle, and the IT experience of our people across five locations - including the joiner-mover-leaver and access review processes our certifications depend on.

Own the SaaS estate, IT procurement and IT cost. Rationalise what we run, negotiate what we buy, and keep spend defensible.

Lead major security incidents as a core member of the Security Incident Response Team - coordinating our response, our partner, Legal and the leadership team, through to the lessons learned that stop it happening twice. Our managed SOC handles everything below that threshold, including out of hours.

Run our compliance program end-to-end across ISO 27001, ISO 27701, SOC 2 Type 2 and GDPR, plus NIS2, the EU Data Act and the EU AI Act. Take ISO and SOC 2 audits to the finish line.

Own enterprise risk, third-party risk, BCP/DR and security awareness, with vendor due diligence and contractual safeguards run in close collaboration with Legal.

Be our voice on security with customers. Represent Inriver in customer and prospect engagements, and partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence - keeping our Trust Center an accurate reflection of what we actually do.

Own the Security, Compliance and IT budgets, including staffing - and make sure material cyber risk reaches the CFO, the executive team and the board when it needs to.

What you’ll bring

We don’t expect you to tick every single box, but for this role we do need most of the following:

Proven track record of developing and implementing security strategies and roadmaps with real business impact - not a control framework on paper.

5+ years in information security, software engineering or similar, with at least 2 years in a senior leadership role (Head of Security, CISO or equivalent) in a mid-size SaaS, cloud or product company.

Excellent stakeholder management and communication skills - you can explain security posture and risk to management so they can act on it.

Leadership and coordination of major security incidents. You’ve run the response, not just been in the room.

Leadership of compliance audits (ISO 27001 and/or SOC 2 Type 2), end-to-end.

Experience presenting the company to customers - security reviews, RFXs and enterprise due diligence.

Development and implementation of application security and cloud security programs.

Deep, current knowledge of Microsoft Azure infrastructure and Azure security, plus strong IT management experience across Microsoft services (Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle and IT cost management.

Strong, current knowledge of GDPR, NIS2, the EU Data Act and the EU AI Act.

Experience leading and developing small, technical teams within a constrained budget - and the willingness to do operational, hands-on work alongside them.

Excellent written and spoken business English, eligibility to work in the EU, and based within commuting distance of our Malmö office for hybrid on-site work.

Nice to have

Working with an outsourced SOC/MDR and with external pen testers

Vetting and leading the implementation of SAST/SCA/DAST tooling

Privacy and data protection

Third-party risk, BCP/DR or security awareness programs

Generative and agentic AI security

Operating across multiple geographies, including the US and the Philippines

Recognised certifications such as CISSP or CISM

Why Inriver

At Inriver, you’ll join a global company with a product at the centre - and people who genuinely care about building something meaningful together.

In our Malmö office, you’ll find things like:

  • Tuesday Fika

  • Friday breakfasts to start the day together

  • A running club and social activities for anyone who wants to join

  • A welcoming mix of focused work, collaboration, and a few laughs along the way

We work in a hybrid setup, with flexibility and trust as a baseline.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hands-On CISO — SaaS Security & Compliance Leader (Hybrid)
Hands-On CISO — SaaS Security & Compliance Leader (Hybrid)

inRiver inc • Malmö kommun

On-site
SEK 1,800,000 - 3,200,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

inRiver inc • Malmö kommun

Hybrid
SEK 1,800,000 - 3,200,000
Head of Security, Compliance & IT
Head of Security, Compliance & IT

Inriver • Malmö kommun

Hybrid
SEK 1,400,000 - 2,200,000
Hybrid CISO — SaaS Security & Compliance Leader
Hybrid CISO — SaaS Security & Compliance Leader

inriver • Sweden

On-site
SEK 1,400,000 - 2,100,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

inriver • Sweden

Hybrid
SEK 1,400,000 - 2,100,000
Tuesday Fika
Friday breakfasts
Running club
+1
Senior Forward Deployed Engineer
Senior Forward Deployed Engineer

inRiver inc • Malmö kommun

Hybrid
SEK 900,000 - 1,200,000
Hybrid work setup
Travel opportunities
IT Infrastructure Specialist
IT Infrastructure Specialist

Inriver • Malmö kommun

Hybrid
SEK 520,000 - 750,000
Hybrid work setup
Tuesday Fika
Friday breakfasts
+2
Security, Compliance & IT Leader (SaaS & Azure)
Security, Compliance & IT Leader (SaaS & Azure)

inRiver inc • Malmö kommun

On-site
SEK 1,400,000 - 2,100,000
Hybrid work setup
Chief Security, Compliance & IT Strategy
Chief Security, Compliance & IT Strategy

Inriver • Malmö kommun

Hybrid
SEK 1,400,000 - 2,200,000
Information Security Specialist
Information Security Specialist

Tacton Systems AB • Stockholms kommun

Hybrid
SEK 600,000 - 800,000
Flexible hybrid setup
33 days of paid time off
Premium occupational pension
+4