Head of Security, Compliance & IT

Inriver

Malmö kommun

Hybrid

SEK 1,400,000 - 2,200,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Inriver is hiring a senior security leader to own the security strategy, product security, privacy, compliance and internal IT across a global SaaS environment. You will report to the CFO, partner with engineering and legal, and drive a modern security program aligned with multiple regulatory standards.

You will lead a cross-functional team, manage SOC/MDR partnerships, and ensure secure architecture and governance across five locations with hybrid on-site work from Malmö.

Qualifications

  • Experience developing security strategies and roadmaps with business impact.
  • 5+ years in information security, with 2+ years in a senior leadership role.
  • Excellent stakeholder management and communication skills.
  • Leadership of compliance audits (ISO 27001 and SOC 2 Type 2).
  • Deep knowledge of GDPR, NIS2, and EU data regulations.
  • Strong knowledge of Microsoft Azure, Entra ID, and cloud security.
  • Experience leading and developing small technical teams within budget.
  • Eligible to work in the EU and fluent in English.

Responsibilities

  • Set and deliver the security strategy and multi-year roadmap.
  • Partner with Engineering to embed secure SDLC and remediation SLAs.
  • Lead vulnerability management and third-party testing.
  • Own Azure security posture and cloud security program leadership.
  • Run internal IT operations across multiple locations and cost management.
  • Manage enterprise risk, third-party risk and security awareness.
  • Lead security incidents with the incident response team and Legal.
  • Oversee ISO 27001, SOC 2 Type 2, GDPR, and other audits end-to-end.
  • Engage with customers on security reviews and enterprise due diligence.

Skills

Security strategy
Leadership
Stakeholder mgmt
Cloud security
Azure security
Compliance programs
Threat modelling
Incident response
IT management
English proficiency
Budget management

Tools

SAST tools
DAST tools
SOC/MDR tooling

Job description

At Inriver, we help brands deliver better product experiences - everywhere their customers are. From the first product detail to the final purchase decision, we make product information work smarter. When our platform is secure, our teams ship with confidence and it enhances customer trust. More than 1,600 global brands trust their product data with us.

About The Role

You’ll own our security strategy and roadmap - and you’ll deliver it. You’ll lead a small, sharp team across Security and IT, work through a 24/7 managed detection and response partner, and partner with engineering teams that own the security of the code they write. You’ll be the person our customers, our leadership team and our auditors talk to about security. You’ll work from our HQ office in Malmö, supporting our remote locations in Stockholm, Amsterdam, Davao and Manila.

Internal IT sits in this role too - the Microsoft 365 and Entra ID estate, device management, identity lifecycle, our SaaS portfolio and IT cost. That’s deliberate. Most of what makes a company secure - identity, access, endpoints, joiner-mover-leaver, patching - is IT work, so one owner means those foundations get built properly rather than negotiated between two functions.

This is a high-impact role reporting to the CFO, working closely with the wider leadership team, Legal and HR. You’ll be close enough to the work to be credible with engineers, and hands‑on when it counts - but you won’t be triaging every alert, and we’ve built the operating model so that you don’t have to.

Why you’ll love this role
  • Own Enterprise Security, Product Security, Privacy, Compliance and internal IT end-to-end, across a global, PE-backed mid-size SaaS company
  • A mandate that’s already agreed. Our gate-and-block operating model - security gates that can hold a release - is signed off by the CEO, CTO and CPO. Not a best-effort understanding.
  • 24/7 monitoring is funded. We’re onboarding a managed SOC/MDR partner. Non-major incidents are handled by them, not by you at 3am.
  • Engineering owns its own findings, remediated against SLAs you agree together. You build the gates and the capability; you don’t chase tickets.
  • You’re not the risk owner of last resort. Material cyber risk is accepted by the business leaders whose decisions create it, and your escalation path doesn’t stop at your manager.
  • Run a modern Microsoft Azure security stack, a real product-security program embedded in our SaaS SDLC, and compliance across SOC 2, ISO 27001, ISO 27701, GDPR, NIS2, the EU Data Act and the EU AI Act
What you’ll do
  • Set the security strategy and roadmap - and deliver it. Build a multi-year plan grounded in business risk, get it funded, and lead the initiatives in it to completion.
  • Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, set the quality gates, and agree the remediation SLAs product teams work to.
  • Lead vulnerability management and penetration testing. Scope and commission internal and third-party testing across web application, API and cloud, manage the specialists who run it, and drive findings to closure.
  • Own the security posture of our Azure environment. Harden our infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC) and lead our Cloud Security Engineer so our product runs on secure architecture.
  • Run internal IT as a foundation, not a help desk. Own the M365 and Entra ID estate, device management, identity and access lifecycle, and the IT experience of our people across five locations - including the joiner-mover-leaver and access review processes our certifications depend on.
  • Own the SaaS estate, IT procurement and IT cost. Rationalise what we run, negotiate what we buy, and keep spend defensible.
  • Lead major security incidents as a core member of the Security Incident Response Team - coordinating our response, our partner, Legal and the leadership team, through to the lessons learned that stop it happening twice. Our managed SOC handles everything below that threshold, including out of hours.
  • Run our compliance program end-to-end across ISO 27001, ISO 27701, SOC 2 Type 2 and GDPR, plus NIS2, the EU Data Act and the EU AI Act. Take ISO and SOC 2 audits to the finish line.
  • Own enterprise risk, third-party risk, BCP/DR and security awareness, with vendor due diligence and contractual safeguards run in close collaboration with Legal.
  • Be our voice on security with customers. Represent Inriver in customer and prospect engagements, and partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence - keeping our Trust Center an accurate reflection of what we actually do.
  • Own the Security, Compliance and IT budgets, including staffing - and make sure material cyber risk reaches the CFO, the executive team and the board when it needs to.
What you’ll bring

We don’t expect you to tick every single box, but for this role we do need most of the following:

  • Proven track record of developing and implementing security strategies and roadmaps with real business impact - not a control framework on paper.
  • 5+ years in information security, software engineering or similar, with at least 2 years in a senior leadership role (Head of Security, CISO or equivalent) in a mid-size SaaS, cloud or product company.
  • Excellent stakeholder management and communication skills - you can explain security posture and risk to management so they can act on it.
  • Leadership and coordination of major security incidents. You’ve run the response, not just been in the room.
  • Leadership of compliance audits (ISO 27001 and/or SOC 2 Type 2), end-to-end.
  • Experience presenting the company to customers - security reviews, RFXs and enterprise due diligence.
  • Development and implementation of application security and cloud security programs.
  • Deep, current knowledge of Microsoft Azure infrastructure and Azure security, plus strong IT management experience across Microsoft services (Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle and IT cost management.
  • Strong, current knowledge of GDPR, NIS2, the EU Data Act and the EU AI Act.
  • Experience leading and developing small, technical teams within a constrained budget - and the willingness to do operational, hands‑on work alongside them.
  • Excellent written and spoken business English, eligibility to work in the EU, and based within commuting distance of our Malmö office for hybrid on‑site work.
Nice to have
  • Working with an outsourced SOC/MDR and with external pen testers
  • Vetting and leading the implementation of SAST/SCA/DAST tooling
  • Privacy and data protection
  • Third-party risk, BCP/DR or security awareness programs
  • Generative and agentic AI security
  • Operating across multiple geographies, including the US and the Philippines
  • Recognised certifications such as CISSP or CISM
Why Inriver

At Inriver, you’ll join a global company with a product at the centre - and people who genuinely care about building something meaningful together.

In our Malmö office, you’ll find things like:

  • Tuesday Fika
  • Friday breakfasts to start the day together
  • A running club and social activities for anyone who wants to join
  • A welcoming mix of focused work, collaboration, and a few laughs along the way

We work in a hybrid setup, with flexibility and trust as a baseline.

Inriver is a global leader in Product Information Management (PIM), helping more than 1,600 brands create outstanding product experiences. Behind our success is a team of talented, collaborative, and passionate people who enjoy solving complex challenges and making an impact for customers around the world.

Headquartered in Malmö, Sweden, we have colleagues across multiple locations globally, bringing together diverse perspectives, expertise, and experiences. For more information, visit www.inriver.com or follow us on LinkedIn.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Security, Compliance & IT
Head of Security, Compliance & IT

inRiver inc • Malmö kommun

Hybrid
SEK 1,400,000 - 2,100,000
Hybrid work setup
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

inRiver inc • Malmö kommun

Hybrid
SEK 1,800,000 - 3,200,000
Hands-On CISO — SaaS Security & Compliance Leader (Hybrid)
Hands-On CISO — SaaS Security & Compliance Leader (Hybrid)

inRiver inc • Malmö kommun

On-site
SEK 1,800,000 - 3,200,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

inriver • Sweden

Hybrid
SEK 1,400,000 - 2,100,000
Tuesday Fika
Friday breakfasts
Running club
+1
Hybrid CISO — SaaS Security & Compliance Leader
Hybrid CISO — SaaS Security & Compliance Leader

inriver • Sweden

On-site
SEK 1,400,000 - 2,100,000
IT Infrastructure Specialist
IT Infrastructure Specialist

Inriver • Malmö kommun

Hybrid
SEK 520,000 - 750,000
Hybrid work setup
Tuesday Fika
Friday breakfasts
+2
Senior Forward Deployed Engineer
Senior Forward Deployed Engineer

inRiver inc • Malmö kommun

Hybrid
SEK 900,000 - 1,200,000
Hybrid work setup
Travel opportunities
Senior Product Marketing Manager
Senior Product Marketing Manager

Inriver • Malmö kommun

Hybrid
SEK 800,000 - 1,000,000
Hybrid work in Malmö
Tuesday Fika
Friday breakfasts
+1
Chief Security, Compliance & IT Strategy
Chief Security, Compliance & IT Strategy

Inriver • Malmö kommun

Hybrid
SEK 1,400,000 - 2,200,000
Senior Product Marketing Manager
Senior Product Marketing Manager

inRiver inc • Malmö kommun

Hybrid
SEK 900,000 - 1,300,000