- Company Name
- nLighten
- Job Title
- Security Compliance Senior Manager
- Job Description
-
**Job Title:** Security Compliance Senior Manager
**Role Summary:** Lead and continuously improve the Information Security Management System (ISMS) for a European data‑center portfolio, ensuring alignment with ISO/IEC 27001 and multiple regulatory frameworks (GDPR, NIS2, DORA, EU AI Act, etc.). Act as the primary security compliance subject‑matter expert, drive audit programs, manage certifications, and foster a strong compliance culture across operations, legal, IT, and executive leadership.
**Expectations:**
- 8+ years of relevant experience or equivalent expertise.
- Proven ability to lead regulatory audits, internal/external assessments, and customer audits.
- Strong communication skills in English; additional European languages a plus.
- Willingness to travel across Europe as required.
- Self‑motivated, detail‑oriented, and capable of independent execution in a fast‑growing environment.
**Key Responsibilities:**
- Design, implement, and continuously enhance the ISMS per ISO/IEC 27001 and corporate security strategy.
- Define and maintain the ISMS compliance roadmap, Statement of Applicability, risk‑treatment plans, and security policies.
- Own internal and external audit programs across Europe; conduct audits, manage evidence, and drive corrective actions.
- Generate audit KPIs and translate findings into actionable improvements.
- Oversee full lifecycle of information‑security risk assessments for data‑center operations, infrastructure, IT, and services; ensure mitigation plans are executed.
- Provide SME guidance on Business Continuity Management.
- Manage the portfolio of certifications (ISO 27001, PCI‑DSS, ISO 9001, ISAE 3402 SOC1, HDS, FINMA, BSI IT‑Grundschutz, EN 50600, etc.).
- Partner with Operations, EHS, Security, Legal, IT, and Network teams; deliver training and awareness programs.
- Present ISMS performance metrics, audit results, and risk posture to executive leadership.
- Lead compliance initiatives for GDPR, NIS2, DORA, EU AI Act; monitor regulatory changes and ensure proactive compliance.
**Required Skills:**
- Deep knowledge of ISO 27001/27002, GDPR, IT‑Grundschutz, SOC1/SOC2, PCI‑DSS.
- Strong understanding of information‑security risk management and data‑protection principles.
- Experience with GRC platforms and audit management tools.
- Excellent verbal and written communication; ability to influence cross‑functional stakeholders.
- Structured, detail‑focused working style; capable of independent decision‑making.
- Proactive, self‑driven attitude with ability to lead initiatives in a rapidly scaling organization.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field *or* 8+ years of directly relevant experience.
- Relevant certifications preferred (e.g., CISM, CISSP, ISO 27001 Lead Implementer, PCI‑DSS Qualified Security Assessor).