While we welcome applications from everywhere, please note that at this stage we are prioritizing candidates who arealready based in Stockholmandeligible to work in Sweden without visa sponsorship.
Reporting to: VP Operations
You'll own Bambuser's information security management system (ISMS), our data privacy and compliance frameworks, and our operational risk registers. Day to day, that means you're the person making sure and supporting the business that we adhere to the regulations we're subject to, that our policies are sane and current, and that we walk into every audit ready rather than scrambling.
We're a fast-moving scale-up, so we need you thinking the way we all try to think: what can be automated, templated, or scheduled instead of done by hand again? If you find yourself doing the same manual task twice, we want you to build the system that makes sure you never do it a third time, and ideally, that nobody else on the team has to either.
Main duties and responsibilities
ISMS Governance & Audit Readiness
Own and maintain the ISO 27001 governance framework, driving continuous improvement of the ISMS to sail through surveillance audits and recertification. Prepare for and run internal and external audits end to end: scoping, evidence collection, stakeholder coordination, and findings remediation. Build playbooks and control documentation that hold up under scrutiny, not just look good on paper.
Keeping Policies Sharp, Not Just Compliant
Own the full ISMS library. Review what exists for relevance, overlap, and gaps, and right-size it to match the actual risk profile, not more, not less. Drive adoption across the org through clear communication and practical enablement so policies get followed in practice.
The Face of Security to Customers and Vendors
Serve as the go-to contact for enterprise customer security reviews, owning the information security sections of RFPs and keeping the Trust Center current. Lead the rollout of the RFP AI tool. On the procurement side, act as the information security reviewer for new tools and vendors, assessing data handling, access, and integration risk before adoption, AI tools included.
Staying Ahead of Regulation, Including AI
Track the regulatory landscape across all markets: GDPR and international privacy law, information security standards, sector-specific rules. Turn that into concrete controls and clear internal ownership. Keep an eye on where AI regulation (like the EU AI Act) is heading, and start building the groundwork, risk classification and usage guidelines, before it becomes urgent.
Security Testing and Training That Sticks
Coordinate and support penetration testing engagements: scoping with vendors, arranging internal access, chasing findings through to remediation. Own the security training program end to end, designing and delivering onboarding and recurring awareness training, and keeping it fresh as threats and regulations shift.
Systems, Not Just Processes
Lead adoption of Bambuser's new operating model, making sure people understand and own their part in it. Turn security workflows that currently live in someone's head into documented, scalable processes. Wherever there's a recurring task, evidence collection, training reminders, audit scheduling, the default should be to automate it rather than track it manually.
Data Privacy and Risk
Oversee GDPR and international privacy compliance across every market, looping in external counsel when needed. Run the Senior Management risk assessment process, keeping the corporate Risk Register current and tied to what the business actually cares about.
Requirements
Experience: 5+ years in information security compliance, IT audit, or risk management, ideally in B2B SaaS or another fast-growing tech company.
ISO 27001: A track record of implementing or maintaining ISO/IEC 27001 certifications. Experience running or supporting penetration testing programs is a plus.
Privacy know-how A strong, practical grasp of GDPR in multi-tenant SaaS environments.
Regulatory radar: Familiarity with where AI regulation (like the EU AI Act) is headed and what it means for a tech business.
Pragmatism: You can turn complex regulatory requirements into workflows that don't grind the business to a halt.
Communication: You're comfortable translating technical security risk into business terms, for executives, for enterprise customers, and for a room full of people at a training session.
An automation instinct: You default to building the system rather than repeating the task, comfortable with workflow automation, reminders, scheduling tools, and AI-assisted drafting to cut busywork, both your own and everyone else's, so time goes toward the work that actually needs a human.
Proactive and solutions-oriented: You identify risks, spot patterns, and anticipate future needs, rather than waiting for problems to surface.
Bonus: Experience working in or with publicly listed companies, including familiarity with their internal control requirements.

We are here to reshape commerce as you know it. 💫
We lead the way towards a world where businesses thrive through community-driven, authentic, interactive experiences.
Because people expect better from the brands that they decide to engage with. So no more purely transactional customer relations. No more anonymous online shopping. No more low-engaging retail exchanges.
Let's shape the future together.