Information Security Officer – Governance, Risk & Compliance
ICEYEJob Description
📋 Description Own and continuously improve ICEYE's ISO 27001 ISMS, including risk assessments, the risk register Track and operationalise NIS2 obligations across ICEYE's in-scope entities with policies, controls Assess CRA and other EU product-security regulation against ICEYE's products and close gaps before Maintain cross-jurisdiction compliance view (NIST, ISO 27001, NIS2, CRA, Finland, Germany, Spain Run third-party/vendor security risk assessments and support due diligence and security Provide clear compliance/risk reporting to senior leadership, including status vs certifications 🎯 Requirements Hands-on ISO 27001 experience (implementation, internal audit, or certification maintenance). Knowledge of NIS2 and translating obligations into controls/reporting. Familiarity with NIST frameworks (CSF, 800-53) mapping to ISO 27001/standards. Aware of CRA and implications for digital products. Experience building/maintaining risk registers and structured risk assessments. Strong stakeholder management to influence engineering, legal and leadership without authority. 🎁 Benefits Benefits vary by location; details confirmed during process.