Information Security Governance Specialist

Frontify AG
London, UK
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English, German
Job source

Tech stack

Artificial Intelligence Spreadsheets Software as a Service Cyber Security Tisax Large Language Models RSA Archer Platform

Job description

With headquarters in St. Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy. And we’re on the lookout for new team members to share our vision. If you’re ready for a brand-new adventure, keep reading! Your team With the mission of creating a home where all brands (including our own) are safe, the Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders. Security, pragmatism and user friendliness are our guiding principles. Outside of work, we’re gamers, avid bookworms and kickboxers. Your mission

Trust is what enables the world’s leading brands to build on Frontify. Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify. Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.

A key focus of the role is driving the next stage of our security governance maturity. Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits. You’ll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness. This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value., * You’ll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.

  • You’ll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.
  • You’ll serve as the subject matter expert during audits and ensure our control environment remains effective and audit-ready.
  • You’ll help transform compliance from a point-in-time activity into a continuous process by introducing automation and AI into our Vanta-based GRC program. This includes improving evidence collection, control monitoring, and access review processes.
  • You’ll design and improve AI-enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.
  • You’ll strengthen Frontify’s vendor risk management program by scaling security assessments through automation while ensuring higher-risk vendors receive appropriate human review.
  • You’ll contribute to the continuous improvement of Frontify’s security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training., If there’s a fit, you’ll meet our Talent Partner to discuss your experience and explore whether Frontify is the right place for you. This description outlines the primary duties of the role, which may evolve in response to business needs and company growth. We’re looking for someone comfortable with change and excited to contribute to a dynamic environment. If this sounds like you, come join us and help shape what’s next. We may conduct preliminary checks for successful candidates, depending on the role and in line with local laws. We’ll share all relevant details during the interview process. We use third party artificial intelligence (AI) tools to record and transcribe interviews and to help our team review candidate profiles. These tools do not replace human judgment, and all evaluations and final hiring decisions are made by our recruitment team. Please see our Privacy Notice for more information about how we process your data, and how to exercise your privacy rights (https://www.frontify.com/en/legal/privacy-notice)

Requirements

  • You’re comfortable working in a hybrid format, with the ability to come to our London office once per week.
  • You have 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.
  • You’ve been the subject matter expert in SOC 2 and/or ISO 27001 audits - not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.
  • You’re hands-on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.
  • You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.
  • You’re genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.
  • You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.
  • A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.
  • You speak English fluently. German is a plus.

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension, We understand that every candidate’s experience is different. If you’re interested in this role but don’t tick all the boxes, we still encourage you to apply. Why join us?

  • Thrive with the tools and support to shape your future at Frontify.

  • Be part of a product that connects brands and people with a human touch.

  • Enjoy flexibility, opportunities to grow, and exposure to innovative technologies and ideas.

  • Join a vibrant, social team-whether you love animals, yoga, or travel, we’ve got the Slack channels for you!

What we offer

  • Private health benefits and health cash plan

  • Pension scheme: 5% matched

  • A minimum of 25 days of annual leave per year

  • Paid educational and wellbeing days off

  • Wellbeing, learning and development, and commuter allowance

  • Home office setup budget- Weekly free office lunch
  • Localized benefits

About the company

Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns. Our people empower thousands of marketers and designers - including teams at Uber, Microsoft, Volkswagen, and Telefónica - to build engaging brands.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:32 min

Recognizing the persistence and utility of spreadsheet applications

John Bettiol · WWC 2022

2:15 min

Overcoming cultural resistance to achieve international security compliance standards

Ali Yazdani Ali Yazdani · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

6:10 min

Transitioning agile recruiting teams away from manual spreadsheet management

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

Videos

See all

Related articles

See all