yandex
I
ICEYE
Страна
Финляндия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Information Security Officer – Governance, Risk & Compliance

ИИОценка ИИ

Исключительно интересная позиция в компании-лидере рынка космических технологий с глобальным присутствием. Четко прописанные обязанности, гибридный формат работы и работа с передовыми стандартами безопасности делают вакансию очень привлекательной для GRC-специалистов.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
ИИОценка ИИ

Высокая сложность обусловлена необходимостью глубоких знаний специфических фреймворков (ISO 27001, NIS2, NIST) и опытом работы в регулируемых отраслях (космос, оборона). Роль подразумевает высокий уровень ответственности за комплаенс в нескольких юрисдикциях.

Анализ зарплаты

Медиана75 000 €
Рынок60 000 € – 90 000 €
ИИОценка ИИ

Зарплата в объявлении не указана, однако для позиции Senior GRC Officer в Финляндии (Эспоо) рыночный диапазон обычно составляет от 65 000 до 85 000 евро в год в зависимости от опыта. Учитывая специфику оборонного и космического секторов, компенсация может быть выше среднего по рынку.

Сопроводительное письмо

I am writing to express my strong interest in the Information Security Officer – GRC position at ICEYE. With a solid background in managing ISO 27001 ISMS and navigating complex regulatory landscapes like NIS2 and NIST, I am confident in my ability to mature your security governance program. My experience in operationalizing compliance across multiple jurisdictions aligns perfectly with ICEYE’s global footprint and its critical role in sovereign intelligence.

Throughout my career, I have focused on making security policies practical and enforceable rather than just 'shelfware.' I have successfully led internal audits, managed risk registers, and served as the primary point of contact for external auditors. I am particularly excited about the opportunity to work at the intersection of commercial space technology and defense, ensuring that ICEYE’s security posture remains credible and audit-ready for government and defense clients.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в ICEYE уже сейчас

Присоединяйтесь к лидеру в области космической разведки и станьте ключевым экспертом по кибербезопасности в ICEYE!

Описание вакансии

Information Security Officer – Governance, Risk & Compliance

Откликнуться

ROLE HIGHLIGHTS:

\* Information Security Officer – Governance, Risk & Compliance

\* Location: Espoo, Finland

\* Department: Security, Architecture & Governance

\* Reports to: VP Security

\* Employment type: Permanent

\* Workplace model: Hybrid

\* Employment is subject to applicable security screening (incl. SUPO, where required)

WHY THIS ROLE MATTERS:

As an Information Security Officer, you'll own and mature ICEYE's Security Governance, Risk and Compliance program across a multi-country, multi-regulator footprint, including Finland, Germany, Spain, Poland, the UK and Greece amongst others. ICEYE operates at the intersection of commercial space technology and sovereign defence, so our compliance posture (ISO 27001, NIS2, NIST, CRA and related frameworks) has to be credible to customers who include governments and defence agencies. You'll be the person who keeps that posture accurate, current and audit-ready, working closely with the VP Security, security architecture, legal and engineering teams, as a senior individual contributor.

WHO WE ARE

ICEYE is the world leader in sovereign intelligence from space. We deliver persistent monitoring capabilities to detect and respond to changes in any location on Earth.

ICEYE owns the world's largest and most advanced SAR (synthetic aperture radar) satellite constellation. To our customers we provide intelligence with unmatched quality, latency and revisit times, in any weather, day or night. To governments who choose to operate their own constellation we provide this proven capability as a sovereign system.

ICEYE-built constellations serve customers in defence and intelligence, environmental monitoring, insurance and emergency management. We enable fast decisions that contribute to a safer future.

Founded and headquartered in Finland, ICEYE operates globally with over 1000 employees across Europe, North America, the Middle East, and Asia-Pacific.

YOUR DAY-TO-DAY RESPONSIBILITIES

\* Own and continuously improve ICEYE's ISO 27001 ISMS, including risk assessments, the risk register, Statement of Applicability, internal audits and certification/surveillance audit cycles.

\* Track and operationalise NIS2 obligations across ICEYE's in-scope entities, translating regulatory requirements into concrete policies, controls and evidence.

\* Assess the Cyber Resilience Act (CRA) and other emerging EU product-security regulation against ICEYE's products, and work with the relevant teams to close gaps ahead of enforcement deadlines.

\* Maintain a cross-jurisdiction compliance view (NIST, ISO 27001, NIS2, CRA, and national frameworks in Finland, Germany, Spain, Poland, the UK and Greece), keeping crosswalks and control mappings current as regulation evolves.

\* Run third-party and vendor security risk assessments, and support client/customer due diligence and security questionnaires.

\* Prepare clear, concise compliance and risk reporting for senior leadership, including status against certifications, audits and remediation plans.

\* Own and maintain information security policies, standards and supporting documentation, ensuring they stay practical and enforceable rather than shelfware.

\* Act as a day-to-day point of contact for external auditors, certification bodies and regulators on GRC matters.

WHAT WE’RE LOOKING FOR

Must haves:

\* Proven hands-on experience running ISO 27001 (implementation, internal audit, or certification maintenance) in a real organisation, not just theoretical knowledge.

\* Working knowledge of NIS2 and how its obligations translate into practical controls and reporting.

\* Familiarity with NIST frameworks (e.g. NIST CSF, 800-53) and how they map to ISO 27001 and other standards.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • ISO 27001
  • Compliance
  • Risk Assessment
  • Internal Audit
  • NIST 800-53
  • GRC
  • NIS2
  • NIST CSF
  • Cyber Resilience Act

Возможные вопросы на собеседовании

Проверка практического опыта управления системой менеджмента информационной безопасности.

Расскажите о вашем опыте внедрения или поддержки сертификации ISO 27001: с какими основными трудностями вы столкнулись при подготовке Statement of Applicability?

Оценка готовности кандидата к работе с новыми европейскими регуляциями.

Как вы планируете операционализировать требования директивы NIS2 для компании, работающей в нескольких странах ЕС?

Проверка навыков управления рисками в цепочке поставок.

Каков ваш подход к проведению оценки рисков информационной безопасности сторонних поставщиков и вендоров?

Оценка умения переводить технические требования на язык бизнеса.

Как вы структурируете отчетность по рискам и комплаенсу для высшего руководства (VP Security и выше), чтобы она была информативной и способствовала принятию решений?

Проверка знаний в области безопасности продуктов.

Какое влияние, по вашему мнению, окажет Cyber Resilience Act (CRA) на разработку продуктов в такой технологической компании, как ICEYE?

Похожие вакансии

H
HuntTech
1 400 ₽ – 1 700 ₽

Senior Аналитик ИБ

SeniorУдалённо
SoC · SIEM · Positive Technologies · EDR · Windows · Linux · SQL · Docker · Git · Information Security
+10 навыков
Г
ГНИВЦ
300 000 ₽ – 340 000 ₽

Инженер SIEM

Удалённо
MaxPatrol SIEM · MaxPatrol EDR · MaxPatrol VM · Python · Bash · PowerShell · SQL · ElasticSearch · Linux · Windows · Docker · Zabbix · Grafana
+13 навыков
DI
Done IT
50 000 ₽ – 150 000 ₽

Специалист по тестированию на проникновение (пентестер) в сфере ИБ

SeniorУдалённо
C++ · Python · Docker · Golang · Rust · Active Directory · PowerShell · Linux · Network Security
+9 навыков
А
Альфа-Банк
Не указана

Руководитель команды AppSec

LeadУдалённо
AppSec · SSDLC · Agile · CI/CD · Microservices · Docker · Kubernetes · OWASP Top 10 · OWASP Mobile Top 10 · CWE Top 25 · Risk Assessment · Threat Modeling
+12 навыков
Э
Экспобанк
Не указана

Директор по информационной безопасности

HeadУдалённо
Information Security · Cybersecurity · Audit · Risk Management · Compliance · Infrastructure Security
+6 навыков
МБ
МТС Банк
Не указана

Руководитель направления по информационной безопасности (методология и аудит)

HeadУдалённо
Information Security · Audit · BPMN · PCI DSS · ГОСТ 57580 · Risk Management · Compliance
+7 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

I
ICEYE
Финляндия