Remote job
Information Security Officer
Job details
About this role
Role overview Own company-wide information security governance, policy, and compliance for a multi-market sports, gaming, and fan-experiences technology organisation. This is a governance and compliance role focused on security policies, awareness and training, and ensuring every team understands and follows through on its compliance obligations, rather than a hands-on technical security engineering position.
Responsibilities - Own and maintain the company-wide information security policy framework, keeping it current, coherent, and aligned with the business, and act as the internal authority on relevant standards such as ISO 27001 and GDPR. - Update and drive the security compliance strategy, including operation of the GRC platform, so policies are clear and effectively communicated across the organisation. - Design and deliver security awareness and training programmes tailored to different teams and tribes, so people understand their compliance obligations and how to meet them. - Drive compliance adoption across business units, validate that teams complete required steps, and establish escalations so gaps are surfaced and closed proactively. - Track and report on policy exceptions and remediation progress. - Own the PII compliance plan, including the programme to deprecate unencrypted PII, and produce reporting escalated to the Board and Risk Committee where necessary. - Coordinate with external auditors, manage evidence collection for audits and certifications, and provide regular compliance reporting to leadership, the Board, and the Risk Committee.
Requirements - Proven experience in information security governance, risk, and compliance (GRC), ideally within a regulated, multi-market environment. - Deep practical knowledge of ISO 27001, GDPR, and related security and data-protection standards. - Experience owning security policy frameworks and running security awareness and training programmes. - Hands-on experience operating a GRC platform and driving compliance across many teams. - Track record of coordinating internal and external audits and managing audit evidence. - Excellent stakeholder-management and communication skills, with the ability to influence and drive compliance without direct authority, plus experience reporting to senior leadership, boards, or risk committees.
Nice to have - Relevant certifications such as CISM, CISA, ISO 27001 Lead Implementer or Auditor, or CISSP. - Experience with data-protection and PII programmes. - Exposure to fast-scaling technology, gaming, or fintech organisations.
Benefits and work setup - Medical or health insurance, open annual leave, employee assistance programme, and training and learning development support, with additional benefits varying by country and shared during the hiring process.