Head of Security, Compliance & IT
Inriver · Remote · posted Sep 18, 2026
Open to candidates in 27 countries
Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
What this role actually asks for
Extracted by RemoteHuntMust have
- •Own security strategy and roadmap
- •Lead security and IT teams
- •Manage compliance (SOC 2, ISO 27001, GDPR)
- •Experience with Azure security stack
- •Hands-on operational work
Nice to have
- •Experience with outsourced SOC/MDR
- •Privacy and data protection
- •Third-party risk management
- •Generative AI security
Tools and technologies
Worth checking before you apply
- ⚠office-required
The full posting
At Inriver, we help brands deliver better product experiences - everywhere their customers are. From the first product detail to the final purchase decision, we make product information work smarter. When our platform is secure, our teams ship with confidence and it enhances customer trust. More than 1,600 global brands trust their product data with us. Now we’re looking for a hands-on Head of Security, Compliance & IT to take over from our outgoing CISO and lead the next chapter of our Enterprise Security, Product Security, Privacy, Compliance and internal IT function. About the role You’ll own our security strategy and roadmap - and you’ll deliver it. You’ll lead a small, sharp team across Security and IT, work through a 24/7 managed detection and response partner, and partner with engineering teams that own the security of the code they write. You’ll be the person our customers, our leadership team and our auditors talk to about security. You’ll work from our HQ office in Malmö, supporting our remote locations in Stockholm, Amsterdam, Davao and Manila. Internal IT sits in this role too - the Microsoft 365 and Entra ID estate, device management, identity lifecycle, our SaaS portfolio and IT cost. That’s deliberate. Most of what makes a company secure - identity, access, endpoints, joiner-mover-leaver, patching - is IT work, so one owner means those foundations get built properly rather than negotiated between two functions. This is a high-impact role reporting to the CFO, working closely with the wider leadership team, Legal and HR. You’ll be close enough to the work to be credible with engineers, and hands-on when it counts - but you won’t be triaging every alert, and we’ve built the operating model so that you don’t have to. Why you’ll love this role 💙
- Own Enterprise Security, Product Security, Privacy, Compliance and internal IT end-to-end, across a global, PE-backed mid-size SaaS company
- A mandate that’s already agreed. Our gate-and-block operating model - security gates that can hold a release - is signed off by the CEO, CTO and CPO. Not a best-effort understanding.
- 24/7 monitoring is funded. We’re onboarding a managed SOC/MDR partner. Non-major incidents are handled by them, not by you at 3am.
- Engineering owns its own findings, remediated against SLAs you agree together. You build the gates and the capability; you don’t chase tickets.
- You’re not the risk owner of last resort. Material cyber risk is accepted by the business leaders whose decisions create it, and your escalation path doesn’t stop at your manager.
- Run a modern Microsoft Azure security stack, a real product-security program embedded in our SaaS SDLC, and compliance across SOC 2, ISO 27001, ISO 27701, GDPR, NIS2, the EU Data Act and the EU AI Act What you’ll do
- Set the security strategy and roadmap - and deliver it. Build a multi-year plan grounded in business risk, get it funded, and lead the initiatives in it to completion.
- Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, set the quality gates, and agree the remediation SLAs product teams work to.
- Lead vulnerability management and penetration testing. Scope and commission internal and third-party testing across web application, API and cloud, manage the specialists who run it, and drive findings to closure.
- Own the security posture of our Azure environment. Harden our infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC) and lead our Cloud Security Engineer so our product runs on secure architecture.
- Run internal IT as a foundation, not a help desk. Own the M365 and Entra ID estate, device management, identity and access lifecycle, and the IT experience of our people across five locations - including the joiner-mover-leaver and access review processes our certifications depend on.
- Own the SaaS estate, IT procurement and IT cost. Rationalise what we run, negotiate what we buy, and keep spend defensible.
- Lead major security incidents as a core member of the Security Incident Response Team - coordinating our response, our partner, Legal and the leadership team, through to the lessons learned that stop it happening twice. Our managed SOC handles everything below that threshold, including out of hours.
- Run our compliance program end-to-end across ISO 27001, ISO 27701, SOC 2 Type 2 and GDPR, plus NIS2, the EU Data Act and the EU AI Act. Take ISO and SOC 2 audits to the finish line.
- Own enterprise risk, third-party risk, BCP/DR and security awareness, with vendor due diligence and contractual safeguards run in close collaboration with Legal.
- Be our voice on security with customers. Represent Inriver in customer and prospect engagements, and partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence - keeping our Trust Center an accurate reflection of what we actually do.
- Own the Security, Compliance and IT budgets, including staffing - and make sure material cyber risk reaches the CFO, the executive team and the board when it needs to. What you’ll bring We don’t expect you to tick every single box, but for this role we do need most of the following: ✔️ Proven track record of developing and implementing security strategies and roadmaps with real business impact - not a control framework on paper. ✔️ 5+ years in information security, software engineering or similar, with at least 2 years in a senior leadership role (Head of Security, CISO or equivalent) in a mid-size SaaS, cloud or product company. ✔️ Excellent stakeholder management and communication skills - you can explain security posture and risk to management so they can act on it. ✔️ Leadership and coordination of major security incidents. You’ve run the response, not just been in the room. ✔️ Leadership of compliance audits (ISO 27001 and/or SOC 2 Type 2), end-to-end. ✔️ Experience presenting the company to customers - security reviews, RFXs and enterprise due diligence. ✔️ Development and implementation of application security and cloud security programs. ✔️ Deep, current knowledge of Microsoft Azure infrastructure and Azure security, plus strong IT management experience across Microsoft services (Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle and IT cost management. ✔️ Strong, current knowledge of GDPR, NIS2, the EU Data Act and the EU AI Act. ✔️ Experience leading and developing small, technical teams within a constrained budget - and the willingness to do operational, hands-on work alongside them. ✔️ Excellent written and spoken business English, eligibility to work in the EU, and based within commuting distance of our Malmö office for hybrid on-site work. Nice to have ✔️ Working with an outsourced SOC/MDR and with external pen testers ✔️ Vetting and leading the implementation of SAST/SCA/DAST tooling ✔️ Privacy and data protection ✔️ Third-party risk, BCP/DR or security awareness programs ✔️ Generative and agentic AI security ✔️ Operating across multiple geographies, including the US and the Philippines ✔️ Recognised certifications such as CISSP or CISM Why Inriver 💙 At Inriver, you’ll join a global company with a product at the centre - and people who genuinely care about building something meaningful together. In our Malmö office, you’ll find things like: Tuesday Fika☕ Friday breakfasts to start the day together A running club and social activities for anyone who wants to join A welcoming mix of focused work, collaboration, and a few laughs along the way We work in a hybrid setup, with flexibility and trust as a baseline. Ready to apply? 📬 We’d love to hear from you. If you’re curious but not 100% sure, we still encourage you to apply. We’re happy to explore the fit together!
Is this one actually worth your time?
RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.