
Information Security & Compliance Engineer
- SOC2
- ISO 27001
- Risk Management
- CISSP
- CISM
- CCSP
- Health insurance
Šbout us
Weāre on a mission to make flexible and hybrid work the norm, not just an "extra." We started back in 2015, and today our SaaS platform helps workspace operators and teams worldwide manage the future of work.
Weāve got offices in Sofia, the US, UK, and Australia, but weāre one global team of tech enthusiasts. We believe that freedom and flexibility lead to better work, and we build our products with that same mindset. If you love solving real-world problems with clean code, youāll fit right in.
About the role
Joining OfficeRnD means leading the forefront of securing data in a critical SaaS platform, in an environment where your contributions directly influence our success and customer trust. This pivotal role is central to ensuring our platform remains synonymous with security and trust for our clients. The successful candidate will be responsible for enhancing our robust information security framework, ensuring compliance with relevant standards, and leading our security initiatives to new heights.
What you'll do
- Lead the identification and mitigation of vulnerabilities within our security architecture, advancing our defense mechanisms against emerging threats;
- Maintain and exceed compliance with SOC 2 and ISO 27001 standards, embodying a culture of continuous improvement in our security practices;
- Direct security dialogue with customers and partners, reinforcing OfficeRnDās commitment to data security and integrity;
- Conduct comprehensive internal audits, access reviews, and security training sessions, including sophisticated phishing awareness programs;
- Implement and refine risk management strategies to proactively address potential security threats;
- Develop, enforce, and periodically review information security policies and procedures, ensuring alignment with industry best practices and regulatory requirements;
- Serve as the primary information security advisor within the organization, promoting a proactive approach to data protection and compliance.
What you need to succeed
- 2 + years of direct experience in information security and compliance. Within SaaS environments, present a significant advantage;
- Experience in achieving and upholding SOC 2 compliance and ISO 27001 certification, with a keen understanding of their critical success factors;
- Expertise in managing security-focused communications with customers and partners, adept at conveying complex security measures in an accessible manner;
- Strong knowledge of internal auditing, risk assessments, and security training methodologies;
- Commitment to staying up-to-date on the latest security trends and technologies, with professional certifications (e.g., CISSP, CISM, CCSP) highly regarded;
- Excellent collaboration and communication skills, capable of leading cross-departmental initiatives and instilling a security-first mindset across the company;
- Proficiency in spoken and written English.
What we offer
- Premium health insurance, including dental coverage
- 25 days of annual paid leave
- An additional day off to celebrate your birthday
- 3 paid volunteering days per year
- Full compensation for the first 3 days of sick leave
- Additional Parental leaveĀ
- To ease your commute, we provide you with either parking access or a public transport pass.
- Hybrid work model (minimum 40% of monthly working time onsite)
- Co-funded sports card to support your active lifestyle
- Learning and development opportunities
If this sounds like the right opportunity for you, weād love to talk!
Information Security & Compliance Engineer Ā· OfficeRnD