We make PDF easy
Information Security Officer – Compliance
Location
Switzerland
Posted
26 days ago
Salary
0
Seniority
Senior
Job Description
Information Security Officer – Compliance
Smallpdf
• Own and maintain the Register of Processing Activities (ROPA) — currently established but requiring ongoing expansion and review. • Ensure compliance with GDPR, Swiss FADP (revDSG), and CCPA requirements across all company operations. • Manage data subject request (DSR) workflows and ensure timely, compliant responses. • Own the retention and deletion policy — define, implement, and enforce data lifecycle rules. • Maintain and improve the company's privacy policies (website, HR, product-level). • Maintain the processor register and DPA repository. • Ensure all active vendors/processors have reviewed DPAs with appropriate safeguards (SCCs, Swiss addenda). • Establish and run an annual vendor review cadence. • Map and document international data transfers and safeguards. • Own the company's Technical and Organizational Measures (TOMs) documentation. • Drive formalization and periodic testing of security controls. • Coordinate penetration testing with external partners. • Build toward a security monitoring and incident response capability. • Own the risk register — maintain it, drive risk owners to close items, report to leadership. • Evaluate and recommend security tooling (e.g., CVE scanning, static analysis integration, SIEM). • Track emerging regulatory requirements (AI Act, DORA, NIS2) and assess applicability. • Prepare the company for potential ISO 27001 or SOC 2 certification when strategically appropriate. • Coordinate with external legal counsel (currently MLL) on regulatory assessments and policy drafting. • Respond to customer compliance questionnaires and security assessments. • Support sales and pre-sales with compliance documentation, certifications overview, and security posture materials. • Ensure product-level compliance considerations (e.g., OSS license management, SBOM generation) are integrated into engineering workflows.
Job Requirements
- 3–5+ years of experience in information security, data protection, or compliance roles — ideally in a B2B software or SaaS environment.
- Working knowledge of GDPR and Swiss FADP, including hands-on experience with ROPAs, DPAs, DSR handling, and data transfer mechanisms (SCCs, adequacy decisions).
- Familiarity with security frameworks and controls: ISO 27001, SOC 2, or similar — you don't need to have led a certification, but you should understand the requirements.
- Ability to build and maintain a risk register and drive risk mitigation across teams.
- Strong written and verbal communication in English (working language). German is a significant plus for Swiss regulatory context and local vendor interactions.
- Pragmatic and structured: you can prioritize what matters in a 50-person company, not gold-plate processes designed for 5,000.
- Comfortable working independently — this is a one-person function with leadership support, not a large team.
Benefits
- 30 vacation days - yep, you read that right - you can take them whenever you need them.
- Flexibility: we have flexible working hours.
- Need a long break? We offer sabbatical leave to employees who’ve been with us for over two years.
- 16 weeks parental leave - 100% of your salary - for all new parents.
- Don’t leave your four-legged friends at home; our Zurich office is pet-friendly.
- A well-being budget of up to 2,000 CHF every year that can be used for training and development (plus days off for courses or training) and for physical and mental well-being purposes.
- Possibility of a Phantom stock option plan - PSOP (Conditions apply).
- Hack days to challenge you and your team, plus build amazing things.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Project Manager
Apex SystemsApex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by three Virginia Tech clas
Cybersecurity Project Manager Location: Columbus, IN, US Remote Employment Type: Contract Pay Range: $50 - $60 per hour Role Overview We are seeking a Cybersecurity Project Manager to manage, develop, and implement projects of varying complexity. This role involves partnering with business stakeholders to ensure successful project completion, with a focus on cybersecurity implementation. The ideal candidate will have technical fluency in cybersecurity, experience in GRC or Cybersecurity Program Management, and strong project management skills. Key Responsibilities - Facilitate project planning sessions to determine the scope and objectives of each project. - Develop project plans, establish timelines, identify milestones, and track performance. - Manage project risk, identifying and implementing solutions or alternatives. - Oversee project planning, scheduling, and tracking while ensuring comprehensive documentation. - Engage in stakeholder coordination, influence, and negotiation to drive project success. - Promote cross-functional collaboration and support operational readiness planning. - Monitor and communicate project status to the project team and other stakeholders. - Guide and coach team members through various stages of the project. Required Qualifications Education: A college, university, or equivalent degree is required. Experience: An intermediate level of relevant work experience is required, typically 3-5 years. This includes experience in GRC or Cybersecurity Program Management. Technical Skills: - Familiarity with NIST SP 800‑171. - Technical fluency to manage cybersecurity implementation. - Knowledge of security tools. - Knowledge of agile frameworks. Preferred Qualifications - Experience with 1-2 project cycles in a regulated industry. - CMMC Certified Professional (CCP) certification. - Project Management Professional (PMI-PMP) certification. - Scrum Master certification. Compensation & Benefits The estimated pay rate for this position is between $50.00 and $60.00 per hour. Please note that the final salary offered may vary based on factors such as the candidate's experience, qualifications, and location. This employer is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Apex uses a virtual recruiter as part of the application process. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide. Employee Type: Contract Remote: Yes Location: Columbus, IN, US Pay Range: $50 - $60 per hour
Enterprise Cybersecurity Security Analyst
Booz Allen HamiltonBooz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp
Enterprise Cybersecurity Security Analyst The Opportunity: Support mission-critical cybersecurity operations for Booz Allen's Impact Level 5 (IL5) environment by administering advanced security tools including CrowdStrike Falcon EDR/AV, Tenable Cloud Security Enterprise, and BigID. Deploy and manage endpoint detection and response (EDR) capabilities to identify and mitigate threats in real time, conduct vulnerability assessments across cloud and hybrid infrastructure, and implement data loss prevention (DLP) strategies to safeguard sensitive information. Collaborate with cross-functional teams to ensure operational excellence, compliance with Department of Defense (DoD) security standards, and continuous maturity of the organization's security posture. Drive execution of zero-trust principles and proactive threat mitigation strategies in a high-sensitivity government environment. You Have: - 5+ years of experience in cybersecurity operations or security engineering - Experience administering cybersecurity tools such as CrowdStrike Falcon, Tenable, or BigID, vulnerability management, and DLP platforms - Experience performing threat detection, incident analysis, and response activities in enterprise environments - Experience supporting vulnerability scanning, remediation workflows, and risk assessments - Ability to collaborate with IT, risk, and operations teams to maintain secure and compliant environments - Ability to obtain a Top Secret clearance - Bachelor's degree Nice If You Have: - Experience deploying and managing security tools in high-classification or IL5 environments - Experience with DoD compliance frameworks such as Risk Management Framework (RMF), NIST 800-53, or Defense Federal Acquisition Regulation Supplement (DFARS) - Experience integrating security tools with Security Information and Event Management (SIEM) or Security Orchestration, Automation, and Response (SOAR) platforms - Knowledge of scripting or automation using Python, PowerShell, or similar for security workflows - Knowledge of cloud security architectures, such as AWS, Azure, or Google Cloud, and hybrid environment security controls - Top Secret clearance - Security+, CISSP, GIAC, or CrowdStrike Certified Falcon Administrator (CCFA) Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Principal Cyber Security Engineer
Memorial Sloan Kettering Cancer CenterMemorial Sloan Kettering Cancer Center is among the world’s leading institutions for cancer study and treatment. It is also the oldest private cancer center, established in 1884
Title: Principal Cyber Security Engineer - Identity Access Management (Ping Suite) Location: New York United States Job Description: Job details About Us: The people of Memorial Sloan Kettering Cancer Center (MSK) are united by a singular mission: ending cancer for life. Our specialized care teams provide personalized, compassionate, expert care to patients of all ages. Informed by basic research done at our Sloan Kettering Institute, scientists across MSK collaborate to conduct innovative translational and clinical research that is driving a revolution in our understanding of cancer as a disease and improving the ability to prevent, diagnose, and treat it. MSK is dedicated to training the next generation of scientists and clinicians, who go on to pursue our mission at MSK and around the globe. Exciting Opportunity at MSK: Principal Cyber Security Engineer - Identity Access Management (IAM) At MSK, this role serves as a senior technical authority for Identity and Access Management, shaping secure, scalable identity solutions that protect critical systems, users, and data. The Principal Cyber Security Engineer partners across the enterprise to design, implement, and evolve modern identity platforms supporting workforce and external identities. Role Overview - Serve as a principal-level technical lead for enterprise Identity and Access Management (IAM) architecture and solutions - Design and implement secure authentication and authorization flows across workforce and external user populations - Lead enterprise-scale IAM initiatives leveraging modern federation and identity standards - Strong experience with PingFederate, PingID, PingOne Suite, including PingOne Protect, PingOne Verify and Davinci - Partner with security, application, and business stakeholders to align identity strategy with organizational needs - Provide hands-on technical leadership for advanced identity platforms and integrations - Drive identity security improvements including MFA, risk-based authentication, and adaptive access - Troubleshoot and resolve complex authentication, federation, and access issues across platforms - Influence IAM standards, best practices, and long-term identity roadmap across the enterprise Key Qualifications - Deep hands-on experience with SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, SCIM, and Auth0 - Proven experience delivering enterprise-scale IAM implementations and migrations - Experience managing identity solutions for both workforce and external/consumer identities - Strong experience with PingOne Suite, including PingOne SSO, MFA, Protect, and Risk - Advanced experience with cloud identity architectures in Azure, AWS, and GCP - Strong JavaScript experience for custom identity logic, orchestration, and flow extensions Core Skills - Ability to translate complex business requirements into secure, scalable identity solutions - Strong analytical and troubleshooting skills for browser-based authentication and identity flows - Advanced use of JSON for APIs, identity payloads, and event-driven integrations - Working knowledge of XML for federation metadata, policies, and configuration artifacts - Collaborative, influential mindset with the ability to lead through expertise and technical credibility - Working knowledge of programming languages (e.g. C#, Java, SQL) - Strong knowledge in managing Linux and Windows servers. Additional Information: - Schedule: 9:00 AM - 5:00 PM EST, Monday - Friday - Location: Hybrid: 99% remote with flexibility to come to NYC as needed. Must live in commutable distance to NYC - Reporting To Associate Director, Identity & Access Management Helpful Links: - Compensation Philosophy - Benefits Pay Range: $152,400.00 - $251,600.00 FSLA Status: Exempt Closing: At MSK, we believe in fair, competitive pay that reflects your job, experience, and skills. MSK is an equal opportunity and affirmative action employer committed to diversity and inclusion in all aspects of recruiting and employment. All qualified individuals are encouraged to apply and will receive consideration without regard to race, color, gender, gender identity or expression, sexual orientation, national origin, age, religion, creed, disability, veteran status or any other factor which cannot lawfully be used as a basis for an employment decision. Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. Application Process - 01 Step 1: Complete an Online Application - 02 Step 2: Interview Process - 03 Step 3: Provide References - 04 Step 4: Extension of Job Offer - 05 Step 5: Onboarding - 06 Step 6: New Employee Orientation Principal Cyber Security Engineer - Identity Access Management (Ping Suite) Department:Informatics & Information Technology Location: New York, NY
Mid Level Security Engineer – Identity and Endpoint
GuidehouseGuidehouse, a "next-generation consultancy" and a portfolio company of Veritas Capital, provides management, risk consulting, and technology services to help cl
• Guidehouse is seeking a mid-level Microsoft Security Engineer to support the design, configuration, deployment, tuning, and day-to-day operation of Microsoft 365 security and identity technologies • This role is hands-on and delivery-focused, supporting government and regulated-industry clients. • In addition to operational responsibilities, the engineer will play a key role in transitioning and handing off security operations capabilities to client teams, including documentation, training, and knowledge transfer. • Configure, deploy, and operate Microsoft 365 security technologies, including: Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps) • Microsoft Entra ID (Azure AD) • Conditional Access policies • Mobile Device Management (Intune) • Tune security controls, alerts, and policies to balance risk reduction with operational impact. • Support ongoing security operations, incident triage, and continuous improvement activities. • Integrate Microsoft security tools into broader client security architectures and operating models. • Implement and manage Conditional Access policies aligned to Zero Trust principles. • Support identity lifecycle management, MFA enforcement, and device-based access controls. • Configure and maintain mobile and endpoint security policies across enterprise environments. • Develop documentation, runbooks, and standard operating procedures (SOPs). • Conduct training sessions and working sessions with client operations teams. • Support phased handoff of security operations from Guidehouse to client personnel. • Ensure clients are enabled to independently sustain and mature their security capabilities. • Contribute technical content to proposals, whitepapers, and solution architectures. • Support capture teams by defining tool capabilities, operational approaches, and staffing models. • Participate in technical solution reviews and proposal color team feedback.




