About the role
As our next CISO, you’ll own Enterprise Security, Product Security, Privacy and Compliance end‑to‑end, covering strategy, operations and the hands‑on work. You’ll work from our HQ office in Malmö, supporting remote locations in Stockholm, Amsterdam, Davao and Manila. This high‑impact role reports to the CFO and collaborates closely with the leadership team, Legal and HR. You’ll modernise and strengthen the security function across the organisation.
Why you’ll love this role
- Own Enterprise Security, Product Security, Privacy and Compliance across a global, PE‑backed mid‑size SaaS company
- Run a modern Microsoft Azure security stack and a product‑security program embedded in our SaaS SDLC
- Maintain compliance with SOC 2, ISO 27001, ISO 27701, GDPR and lead readiness for NIS 2, the EU Data Act and the EU AI Act
- Lead a small, sharp team
- Work closely with the CFO and the leadership team
What you’ll do
- Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, and triage, identify mitigations and prioritise security fixes for developers. Lead vulnerability management and analyse or test exploitability.
- Plan, oversee and execute penetration testing for our product. Cover web application, API and cloud testing. Run internal tests to find and validate exploitable issues and manage third‑party pen‑testers for broader‑scope engagements.
- Own the security posture of our Azure environment. Harden infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC, etc.) and lead our Cloud Security Engineer to ensure the product runs on secure Azure architecture.
- Own enterprise risk, third‑party risk, BCP/DR and the security awareness program. Execute phishing tests as part of the awareness programme.
- Own the SOC. Triage, investigate and respond to alerts from our MSSP/MDR/SOC and Microsoft Defender, including out‑of‑hours. Be the on‑call escalation point for incidents 24/7 and lead containment, recovery and post‑incident learning.
- Own security incident response. From the first alert to the post‑mortem, conduct triage, containment, eradication, recovery and lessons‑learned to prevent recurrence.
- Run our compliance programme end‑to‑end. Manage ISO 27001, ISO 27701, SOC 2 Type 2, GDPR and other EU‑relevant frameworks. Take audits to the finish line, write and manage policies in our GRC tool.
- Run third‑party / vendor risk management. In close collaboration with Legal, conduct due diligence, contractual safeguards, ongoing monitoring and offboarding.
- Represent Inriver externally on security, privacy and compliance topics. Partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence processes. Help customers understand Inriver’s security posture and keep the Trust Center accurate.
- Risk management. Own the risk management programme and elevate risks to the CFO and executive team as needed.
- Budget management. Own the security and compliance budgets.
What you’ll bring
- 5+ years in information security or software engineering with at least 2 years in a senior leadership role (CISO, Head of Security or equivalent) at a mid‑size SaaS/cloud/product company.
- Hands‑on technical depth – run incident response, review code and IaC, exploit or triage real vulnerabilities.
- Strong IT management across Microsoft services (Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle, procurement and IT cost management, ideally across both security and broader IT.
- Track record of leading 24/7 SOC operations or working closely with an MSSP/SOC, including out‑of‑hours response.
- Deep knowledge of Microsoft Azure infrastructure and Azure security.
- Proven ownership of ISO 27001, ISO 27701 and SOC 2 Type II programmes end‑to‑end.
- Strong knowledge of GDPR, NIS 2, the EU Data Act and the EU AI Act.
- Software engineering or DevOps background – able to read and write code (e.g. Python, C#) and collaborate with engineers as a peer.
- Hands‑on experience with a GRC platform, preferably Drata.
- Application security background: secure SDLC, SAST/SCA/DAST, threat modelling, vulnerability management, exploitability analysis and pen‑testing.
- Experience leading and developing small, technical teams within a constrained budget.
- Excellent written and spoken business English.
- Must be eligible to work in the EU. Based in Malmö or within commuting distance to the Malmö office for a hybrid basis.
Nice to have
- Exposure to generative and agentic AI security.
- Experience working in a mid‑size SaaS organisation.
- Experience operating across multiple geographies, including the US and the Philippines.
- Active membership in the security community.
- Recognised certifications such as CISSP, CISM, etc.
Why Inriver
- A supportive team culture with space to learn, lead and grow.
- A workplace where your voice matters and your work makes a real difference to a global SaaS business.
- Flexible hybrid setup with trust as a baseline.
- Office perks: Tuesday Fika, Friday breakfasts, running club and social activities.