Information Security Officer Governance Risk Compliance positions focus on delivering results in their domain. This page aggregates open Information Security Officer Governance Risk Compliance roles and what employers typically expect.
ROLE HIGHLIGHTS: - Information Security Officer – Governance, Risk & Compliance - Location: Espoo, Finland - Department: Security, Architecture & Governance - Reports to: VP Security - Employment type: Permanent - Workplace model: Hybrid - Employment is subject to applicable security screening (incl. SUPO, where required) WHY THIS ROLE MATTERS: As an Information Security Officer, you'll own and mature ICEYE's Security Governance, Risk and Compliance program across a multi-country, multi-regulator footprint, including Finland, Germany, Spain, Poland, the UK and Greece amongst others. ICEYE operates at the intersection of commercial space technology and sovereign defence, so our compliance posture (ISO 27001, NIS2, NIST, CRA and related frameworks) has to be credible to customers who include governments and defence agencies. You'll be the person who keeps that posture accurate, current and audit-ready, working closely with the VP Security, security architecture, legal and engineering teams, as a senior individual contributor. WHO WE ARE ICEYE is the world leader in sovereign intelligence from space. We deliver persistent monitoring capabilities to detect and respond to changes in any location on Earth. ICEYE owns the world's largest and most advanced SAR (synthetic aperture radar) satellite constellation. To our customers we provide intelligence with unmatched quality, latency and revisit times, in any weather, day or night. To governments who choose to operate their own constellation we provide this proven capability as a sovereign system. ICEYE-built constellations serve customers in defence and intelligence, environmental monitoring, insurance and emergency management. We enable fast decisions that contribute to a safer future. Founded and headquartered in Finland, ICEYE operates globally with over 1000 employees across Europe, North America, the Middle East, and Asia-Pacific. YOUR DAY-TO-DAY RESPONSIBILITIES - Own and continuously improve ICEYE's ISO 27001 ISMS, including risk assessments, the risk register, Statement of Applicability, internal audits and certification/surveillance audit cycles. - Track and operationalise NIS2 obligations across ICEYE's in-scope entities, translating regulatory requirements into concrete policies, controls and evidence. - Assess the Cyber Resilience Act (CRA) and other emerging EU product-security regulation against ICEYE's products, and work with the relevant teams to close gaps ahead of enforcement deadlines. - Maintain a cross-jurisdiction compliance view (NIST, ISO 27001, NIS2, CRA, and national frameworks in Finland, Germany, Spain, Poland, the UK and Greece), keeping crosswalks and control mappings current as regulation evolves. - Run third-party and vendor security risk assessments, and support client/customer due diligence and security questionnaires. - Prepare clear, concise compliance and risk reporting for senior leadership, including status against certifications, audits and remediation plans. - Own and maintain information security policies, standards and supporting documentation, ensuring they stay practical and enforceable rather than shelfware. - Act as a day-to-day point of contact for external auditors, certification bodies and regulators on GRC matters. WHAT WE’RE LOOKING FOR Must haves: - Proven hands-on experience running ISO 27001 (implementation, internal audit, or certification maintenance) in a real organisation, not just theoretical knowledge. - Working knowledge of NIS2 and how its obligations translate into practical controls and reporting. - Familiarity with NIST frameworks (e.g. NIST CSF, 800-53) and how they map to ISO 27001 and other standards. - Awareness of the Cyber Resilience Act (CRA) and its implications for products with digital elements. - Experience building or maintaining a risk register and running structured risk assessments. - Strong stakeholder management skills, with the ability to influence engineering, legal and leadership without formal auth…