> Markdown version of [/jobs/ext/2983704-head-of-security-compliance-it](https://www.wearedevelopers.com/jobs/ext/2983704-head-of-security-compliance-it). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Security, Compliance & IT - **Company:** Inriver Inc. - **Location:** Malmo, NE, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, IT Management, Information Systems Security Architecture Professional, Procurement Software, Systems Development Life Cycle, Role-Based Access Control, Software Engineering, Software Vulnerability Management, Web Applications, Software Security, Generative AI, Microsoft InTune, Information Technology, Key Vault, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://career.inriver.com/jobs/8403829-head-of-security-compliance-it ## About the Role ️ Proven track record of developing and implementing security strategies and roadmaps with real business impact - not a control framework on paper. ️ 5+ years in information security, software engineering or similar, with at least 2 years in a senior leadership role (Head of Security, CISO or equivalent) in a mid-size SaaS, cloud or product company. ️ Excellent stakeholder management and communication skills - you can explain security posture and risk to management so they can act on it. ️ Leadership and coordination of major security incidents. You've run the response, not just been in the room. ️ Leadership of compliance audits (ISO 27001 and/or SOC 2 Type 2), end-to-end. ️ Experience presenting the company to customers - security reviews, RFXs and enterprise due diligence. ️ Development and implementation of application security and cloud security programs. ️ Deep, current knowledge of Microsoft Azure infrastructure and Azure security, plus strong IT management experience across Microsoft services (Entra ID, Intune/MDM, M365), SaaS administration, identity lifecycle and IT cost management. ️ Strong, current knowledge of GDPR, NIS2, the EU Data Act and the EU AI Act. ️ Experience leading and developing small, technical teams within a constrained budget - and the willingness to do operational, hands-on work alongside them. ️ Excellent written and spoken business English, eligibility to work in the EU, and based within commuting distance of our Malmö office for hybrid on-site work. ## Description You'll own our security strategy and roadmap - and you'll deliver it. You'll lead a small, sharp team across Security and IT, work through a 24/7 managed detection and response partner, and partner with engineering teams that own the security of the code they write. You'll be the person our customers, our leadership team and our auditors talk to about security. You'll work from our HQ office in Malmö, supporting our remote locations in Stockholm, Amsterdam, Davao and Manila. Internal IT sits in this role too - the Microsoft 365 and Entra ID estate, device management, identity lifecycle, our SaaS portfolio and IT cost. That's deliberate. Most of what makes a company secure - identity, access, endpoints, joiner-mover-leaver, patching - is IT work, so one owner means those foundations get built properly rather than negotiated between two functions. This is a high-impact role reporting to the CFO, working closely with the wider leadership team, Legal and HR. You'll be close enough to the work to be credible with engineers, and hands-on when it counts - but you won't be triaging every alert, and we've built the operating model so that you don't have to. Why you'll love this role * Own Enterprise Security, Product Security, Privacy, Compliance and internal IT end-to-end, across a global, PE-backed mid-size SaaS company * A mandate that's already agreed. Our gate-and-block operating model - security gates that can hold a release - is signed off by the CEO, CTO and CPO. Not a best-effort understanding. * 24/7 monitoring is funded. We're onboarding a managed SOC/MDR partner. Non-major incidents are handled by them, not by you at 3am. * Engineering owns its own findings, remediated against SLAs you agree together. You build the gates and the capability; you don't chase tickets. * You're not the risk owner of last resort. Material cyber risk is accepted by the business leaders whose decisions create it, and your escalation path doesn't stop at your manager. * Run a modern Microsoft Azure security stack, a real product-security program embedded in our SaaS SDLC, and compliance across SOC 2, ISO 27001, ISO 27701, GDPR, NIS2, the EU Data Act and the EU AI Act What you'll do * Set the security strategy and roadmap - and deliver it. Build a multi-year plan grounded in business risk, get it funded, and lead the initiatives in it to completion. * Be the security partner to Engineering. Embed secure SDLC, threat modelling and SAST/SCA/DAST in our pipelines, set the quality gates, and agree the remediation SLAs product teams work to. * Lead vulnerability management and penetration testing. Scope and commission internal and third-party testing across web application, API and cloud, manage the specialists who run it, and drive findings to closure. * Own the security posture of our Azure environment. Harden our infrastructure (Entra ID, Defender for Cloud, Sentinel, Conditional Access, PIM, Key Vault, Purview, Azure RBAC) and lead our Cloud Security Engineer so our product runs on secure architecture. * Run internal IT as a foundation, not a help desk. Own the M365 and Entra ID estate, device management, identity and access lifecycle, and the IT experience of our people across five locations - including the joiner-mover-leaver and access review processes our certifications depend on. * Own the SaaS estate, IT procurement and IT cost. Rationalise what we run, negotiate what we buy, and keep spend defensible. * Lead major security incidents as a core member of the Security Incident Response Team - coordinating our response, our partner, Legal and the leadership team, through to the lessons learned that stop it happening twice. Our managed SOC handles everything below that threshold, including out of hours. * Run our compliance program end-to-end across ISO 27001, ISO 27701, SOC 2 Type 2 and GDPR, plus NIS2, the EU Data Act and the EU AI Act. Take ISO and SOC 2 audits to the finish line. * Own enterprise risk, third-party risk, BCP/DR and security awareness, with vendor due diligence and contractual safeguards run in close collaboration with Legal. * Be our voice on security with customers. Represent Inriver in customer and prospect engagements, and partner with Sales, Legal and Customer Success on RFPs, security reviews, contractual discussions and enterprise due diligence - keeping our Trust Center an accurate reflection of what we actually do. * Own the Security, Compliance and IT budgets, including staffing - and make sure material cyber risk reaches the CFO, the executive team and the board when it needs to., ️ Working with an outsourced SOC/MDR and with external pen testers ️ Vetting and leading the implementation of SAST/SCA/DAST tooling ️ Privacy and data protection ️ Third-party risk, BCP/DR or security awareness programs ️ Generative and agentic AI security ️ Operating across multiple geographies, including the US and the Philippines ️ Recognised certifications such as CISSP or CISM ## Related Videos - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [External Secrets Operator: the secrets management toolbox for self-sufficient teams](https://www.wearedevelopers.com/videos/811-external-secrets-operator-the-secrets-management-toolbox-for-self-sufficient-teams) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)