SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security Officer – Governance, Risk & Compliance

ICEYE - Espoo, Finland - Hybrid - posted 2026-08-06

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ICEYE, the world leader in sovereign intelligence from space, is seeking an Information Security Officer to own and mature the company's Security Governance, Risk and Compliance program across a multi-country, multi-regulator footprint including Finland, Germany, Spain, Poland, the UK and Greece. This is a senior individual contributor role reporting to the VP Security within the Security, Architecture & Governance department. You will be responsible for maintaining and continuously improving ICEYE's ISO 27001 Information Security Management System (ISMS), including risk assessments, risk registers, Statements of Applicability, internal audits and certification/surveillance audit cycles. You'll track and operationalize NIS2 obligations across in-scope entities, translating regulatory requirements into concrete policies, controls and evidence. You'll assess the Cyber Resilience Act (CRA) and other emerging EU product-security regulations against ICEYE's products and work with relevant teams to close gaps ahead of enforcement deadlines. You'll maintain a cross-jurisdiction compliance view spanning NIST, ISO 27001, NIS2, CRA and national frameworks, keeping crosswalks and control mappings current as regulation evolves. You'll run third-party and vendor security risk assessments, support client/customer due diligence and security questionnaires, and prepare clear compliance and risk reporting for senior leadership. You'll own and maintain information security policies, standards and supporting documentation, ensuring they remain practical and enforceable. You'll serve as the day-to-day point of contact for external auditors, certification bodies and regulators on GRC matters. Required qualifications include proven hands-on experience running ISO 27001 in a real organization, working knowledge of NIS2 and its practical control implications, familiarity with NIST frameworks and their mapping to ISO 27001, awareness of the Cyber Resilience Act, experience building and maintaining risk registers and running structured risk assessments, strong stakeholder management skills, comfort operating independently across multiple countries and regulatory regimes, and a relevant certification such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor. Awareness of emerging AI governance frameworks (ISO 42001, NIST AI Risk Management Framework, EU AI Act) is also required. Nice-to-have qualifications include experience in defence, space, aerospace or other regulated/sovereign-sensitive industries, exposure to classified information handling frameworks (EUCI, NATO equivalents, national security clearance regimes) and familiarity with GRC tooling such as ServiceNow GRC, OneTrust or Vanta.

Similar roles