Chief Information Security Officer (CISO)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
As our next CISO, youâll own the following areas end-to-end at Inriver - Enterprise Security, Product Security, Privacy, and Compliance - covering strategy, operations and the hands-on work. Youâll work from our HQ office in MalmĂś, supporting our remote locations in Stockholm, Amsterdam, Davao and Manila.
This is a high-impact role reporting to the CFO and close collaboration with the wider leadership team, and Legal and HR. You will get a genuinely hands-on mandate to modernize and strengthen Enterprise Security, Product Security, Privacy, and Compliance. For the right candidate, and depending on background and experience, there is potential for the broader IT function to also become part of this leadership scope.
Why youâll love this role
-
Own Enterprise Security, Product Security, Privacy, and Compliance - end-to-end across a global, PE-backed mid-size SaaS company
-
Run a modern Microsoft Azure security stack and a real product-security program embedded in our SaaS SDLC
-
Maintain compliance to SOC2, ISO 27001, ISO 27701, GDPR, NIS2, the EU Data Act and the EU AI Act.
-
Lead a small, sharp team
-
Work closely with the CFO & leadership team
What youâll do
-
Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, and triage, identify mitigations, and prioritize security fixes for developers. Lead vulnerability management and analyse or test exploitability.
-
Plan, oversee and execute penetration testing for our product (internal and third-party), covering web application, API and cloud testing. Youâll personally run hands-on internal tests to find and validate exploitable issues, and manage third-party pen-testers for broader-scope and specialised engagements.
-
Own the security posture of our Azure environment and harden our infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC, etc.) and lead our Cloud Security Engineer to ensure that our product runs on secure Azure architecture
-
Own enterprise risk, third-party risk, BCP/DR, and the security awareness program (including executing phishing tests)
-
Own the SOC. Triage, investigate and respond to alerts from our MSSP/MDR/SOC and Microsoft Defender - including out-of-hours when it matters. Be the on-call escalation point for security incidents 24/7 and lead containment, recovery and post-incident learning.
-
Own security incident response. From the first alert to the post-mortem - triage, containment, eradication, recovery, and the lessons-learned that stop it happening twice.
-
Run our compliance program end-to-end across ISO 27001, ISO 27701, SOC2 Type 2, and GDPR any other EU-relevant frameworks such as NIS2, the EU Data Act, the EU AI Act. Take ISO and SOC2 audits to the finish line, hands-on in our GRC tool including writing and managing policies.
-
Run third-party / vendor risk management, in close collaboration with Legal. This includes due diligence, contractual safeguards, ongoing monitoring and offboarding.
-
Customer trust & commercial enablement: Represent Inriver externally on security, privacy and compliance topics in customer and prospect engagements. Partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence processes. Help customers and prospects understand and trust Inriverâs security posture, and ensure our Trust Center accurately reflects our controls, certifications and practices
-
Risk Management: responsible for the risk management program at Inriver, and escalating risks to the CFO and executive team as needed.
-
Budget Management: responsible for the Security and Compliance budgets.
Requirements
ď¸ 5+ years in information security or software engineering or similar, with at least 2 years in a senior leadership role (CISO, Head of Security or equivalent) in a mid-size SaaS / cloud / product company.
ď¸ Youâre not purely a governance leader. Demonstrated hands-on technical depth - youâve personally run incident response, reviewed code and IaC, and exploited or triaged real vulnerabilities.
ď¸Strong IT management experience across Microsoft services (e.g. Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle, procurement and IT cost management - ideally with the ability to operate across both Security and broader IT functions.
ď¸Track record of leading 24/7 SOC operations, or working very closely with an MSSP/SOC, including responding to alerts out-of-hours.
ď¸Deep, current knowledge of Microsoft Azure infrastructure and Azure security
ď¸Proven ownership of an ISO 27001, ISO 27701 SOC 2 Type II program end-to-end.
ď¸Strong, current knowledge of GDPR, NIS2, the EU Data Act and the EU AI Act.
ď¸Software engineering or platform/DevOps background - you can read and ideally write code (e.g. Python, C#) and engage with engineers as a peer.
ď¸Hands-on experience with a GRC platform, ideally Drata
ď¸Strong application security background: secure SDLC, SAST/SCA/DAST, threat modelling, vulnerability management, exploitability analysis and pen-testing.
ď¸Experience leading and developing small, technical teams within a constrained budget
ď¸Excellent written and spoken business English
Benefits & conditions
- A workplace where your voice matters and your work makes a real difference to a global SaaS business
Weâre serious about building a strong, secure business - and we also care about enjoying the ride.
In our MalmĂś office, youâll find things like:
-
Tuesday Fika
-
Friday breakfasts to start the day together
-
A running club and social activities for anyone who wants to join ď¸
-
A welcoming mix of focused work, collaboration and a few laughs along the way
We work in a hybrid setup, with flexibility and trust as a baseline.
About the company
At Inriver, we help brands deliver better product experiences - everywhere their customers are. From the first product detail to the final purchase decision, we make product information work smarter. When our platform is secure, our teams ship with confidence and it enhances customer trust. More than 1,600 global brands trust their product data with us., At Inriver, we are committed to upholding a set of core values that guide our actions and decisions every day. These values define who we are as an organization and shape our company culture. They serve as a foundation for building trust with our clients, partners, and within our teams.
These values are more than just words-they are the principles that guide our actions and help us build a positive and successful future together. We encourage everyone at Inriver to live by these values in their everyday work.
Itâs not individual values, but the combination of the three that makes us Inriver.
About Inriver
Inriver is the Product Information Management (PIM) solution that empowers brands, manufacturers, and retailers to take control of the product data current and turn complexity into competitive advantage. Its AI-powered, scalable platform connects seamlessly to upstream systems and downstream channels, enabling continuous optimization of product experiences across every touchpoint. Trusted by more than 1,600 global brands, Inriver accelerates time-to-market, enhances customer experience, and fuels profitable growth. For more information, visit www.inriver.com or follow us on LinkedIn.
Founded in 2007 Co-workers 300 Finance ¡ MalmÜ
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on inriver.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The 12 Best Jobs for Software Engineers
Fully Remote Software Engineer Jobs
What Are The Top Skills Required For Azure Developers?
The Most Popular IT Jobs on the Market