Information Security Officer

super

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Open annual leave
Employee assistance programme
Training & development support

Job summary

super is seeking a senior information security governance leader to own company-wide policy, risk, and compliance for a multi-market sports, gaming, and fan-experiences technology organisation. This role emphasizes governance, awareness, and board-level reporting rather than hands-on engineering.

You will drive the policy framework, lead security training programs, coordinate audits, and ensure alignment with ISO 27001 and GDPR across diverse teams and regions.

Qualifications

  • Proven experience in information security governance, risk, and compliance (GRC) in a regulated, multi-market environment.
  • Deep knowledge of ISO 27001, GDPR, and related security standards.
  • Experience owning security policy frameworks and running awareness programs.
  • Hands-on experience operating a GRC platform and driving cross-team compliance.

Responsibilities

  • Own and maintain the company-wide information security policy framework and alignment with business needs.
  • Update the security compliance strategy and operate the GRC platform across the organization.
  • Design and deliver security awareness and training programmes for different teams.
  • Drive compliance adoption across business units and close gaps proactively.
  • Track policy exceptions and remediation progress.
  • Coordinate with external auditors and provide regular compliance reporting to leadership and risk committees.

Skills

GRC knowledge
Policy & compliance
Stakeholder management
Audit coordination
Security awareness

Tools

GRC platform

Job description

Role overview

Own company-wide information security governance, policy, and compliance for a multi-market sports, gaming, and fan‑experiences technology organisation. This is a governance and compliance role focused on security policies, awareness and training, and ensuring every team understands and follows through on its compliance obligations, rather than a hands‑on technical security engineering position.

Responsibilities
  • Own and maintain the company-wide information security policy framework, keeping it current, coherent, and aligned with the business, and act as the internal authority on relevant standards such as ISO 27001 and GDPR.
  • Update and drive the security compliance strategy, including operation of the GRC platform, so policies are clear and effectively communicated across the organisation.
  • Design and deliver security awareness and training programmes tailored to different teams and tribes, so people understand their compliance obligations and how to meet them.
  • Drive compliance adoption across business units, validate that teams complete required steps, and establish escalations so gaps are surfaced and closed proactively.
  • Track and report on policy exceptions and remediation progress.
  • Own the PII compliance plan, including the programme to deprecate unencrypted PII, and produce reporting escalated to the Board and Risk Committee where necessary.
  • Coordinate with external auditors, manage evidence collection for audits and certifications, and provide regular compliance reporting to leadership, the Board, and the Risk Committee.
Requirements
  • Proven experience in information security governance, risk, and compliance (GRC), ideally within a regulated, multi-market environment.
  • Deep practical knowledge of ISO 27001, GDPR, and related security and data‑protection standards.
  • Experience owning security policy frameworks and running security awareness and training programmes.
  • Hands‑on experience operating a GRC platform and driving compliance across many teams.
  • Track record of coordinating internal and external audits and managing audit evidence.
  • Excellent stakeholder‑management and communication skills, with the ability to influence and drive compliance without direct authority, plus experience reporting to senior leadership, boards, or risk committees.
Nice to have
  • Relevant certifications such as CISM, CISA, ISO 27001 Lead Implementer or Auditor, or CISSP.
  • Experience with data‑protection and PII programmes.
  • Exposure to fast‑scaling technology, gaming, or fintech organisations.
Benefits and work setup
  • Medical or health insurance, open annual leave, employee assistance programme, and training and learning development support, with additional benefits varying by country and shared during the hiring process.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Governance & Compliance Leader
Security Governance & Compliance Leader

super • United States

Remote
USD 180,000 - 240,000
Medical insurance
Open annual leave
Employee assistance programme
+1
Information Security Governance, Risk & Compliance Manager
Information Security Governance, Risk & Compliance Manager

JustMarkets • United States

Remote
USD 120,000 - 190,000
20 vacation days
10 sick leave days
Public holidays per policy
+5
Director, Security Compliance and Trust
Director, Security Compliance and Trust

gomotive • United States

Remote
USD 225,000 - 305,000
Health insurance
Equity potential
401k plan
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s

Stott and May • New York (NY)

On-site
USD 180,000 - 260,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

harnessinc • United States

Remote
USD 150,000 - 164,000
Monthly internet reimbursement
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining • Tucson (AZ)

On-site
USD 90,000 - 120,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity