Hiring.Camp

Information Security & Compliance Manager (all genders)

fiskaly

Location
Vienna, Vienna, Austria; Vienna, Vienna, Austria ยท Austria
Workplace
Hybrid, Onsite
Department
Legal
Seniority
Manager

Description

Job Details

  • Location: Vienna โ€” hybrid, with regular on-site presence (and full on-site presence during audits)
  • Languages: English (C1); German is a plus
  • Experience: 5+ years in Information Security, Compliance or GRC, incl. at least one ISO 27001 audit cycle owned end-to-end
  • Salary: Competitive, based on experience
  • Contract: Full-time, permanent

๐Ÿš€ Join fiskaly! Help Us Build Trust in Compliance & Security

Millions of people interact with fiskaly every day, even if they don't realize it. As a B2B company, we power the retail technology behind digital receipts and secure, legally compliant transactions.
By making receipts tamper-proof through digital signatures, we help fight tax fraud. And with our paperless receipt solution, we offer consumers a modern alternative while helping merchants streamline their operations.
Sure, our solutions sound complex but our mission is simple: make receipts easy for everyone.

๐Ÿ’ผ The Role

fiskaly is certified to ISO 27001, and our re-certification audit is scheduled for early 2027. We're looking for an Information Security & Compliance Manager to take end-to-end ownership of our ISMS: close the open nonconformities from our last audit, mature the management system, and lead us through re-certification โ€” then keep raising the bar as we scale across seven European markets.

This is an ownership role, not a coordination role. You set the direction โ€” what needs to happen, in which order and why โ€” and you deliver a good part of it yourself: improving processes, running internal audits, preparing evidence and sitting in the room with the auditors. Towards our management team you are the independent expert voice on security and compliance; towards Engineering, Product and Legal you are the hands-on partner who makes controls work in a cloud-native SaaS environment.

Beyond ISO 27001, you'll look after our ISO 9001 quality management system and our GDPR framework, and keep us ahead of NIS2 and the AI Act.

๐Ÿ› ๏ธ What You'll Do

  • Own our ISMS end-to-end โ€” scope, policies, controls, risk register, management review and continuous improvement โ€” and be accountable for its effectiveness, not just its documentation
  • Lead our re-certification in early 2027: assess the current state (previous findings, existing policies and processes, gaps), close the open nonconformities, plan and run internal audits, prepare the management review and the evidence, coordinate with the certification body and be present throughout the audit
  • Define and build ISMS processes tailored to fiskaly โ€” business continuity, change management, incident and vulnerability management, supplier management โ€” designed for how a cloud-native engineering team actually works, not copied from a template
  • Run the company-wide risk management programme, translating abstract risks into prioritised, actionable engineering and business tasks, and explaining business risk vs. technical risk to leadership
  • Be the independent expert voice towards management: report on the state of security and compliance, explain what our processes are for, and give concrete direction on what to improve and in which order
  • Partner with Engineering and Product to embed security-by-design into the SDLC, CI/CD and infrastructure-as-code, and move evidence collection from manual gathering to automated, continuous monitoring wherever possible
  • Support Legal and Sales on customer due diligence: security questionnaires, contract security reviews and enterprise customer audits
  • Oversee vendor risk management with lightweight, scalable assessments that surface third-party risk without stalling procurement
  • Maintain our ISO 9001 QMS and GDPR framework, monitor the regulatory landscape (NIS2, AI Act) and translate it into practical roadmaps for leadership
  • Drive a security-aware culture beyond mandatory training โ€” position compliance as a business enabler, not a blocker

โœจ What You Bring

  • 5+ years in Information Security, Compliance or Risk Management, with a track record of building or maturing an ISMS
  • You have owned at least one ISO 27001 certification, surveillance or re-certification audit end-to-end โ€” from gap assessment and closing nonconformities to sitting across from the auditor
  • Deep knowledge of ISO 27001 (2022) and its controls; working knowledge of ISO 9001 and GDPR; able to navigate NIS2 without hand-holding
  • Genuine fluency in SaaS and cloud environments: you understand GCP and/or Azure, CI/CD, infrastructure-as-code and modern change management well enough to audit them and to talk to engineers as a peer
  • A solid understanding of secure SDLC โ€” what good looks like and where the evidence lives
  • Strong risk management foundations (ISO 31000, COSO or comparable) and the ability to present risk to C-level stakeholders in business terms
  • A hands-on, delivery mindset: you define what needs to be done, then do it, scaling your effort to the deadline
  • Excellent communication and presentation skills in English (C1); German is a plus
  • Based in Vienna or willing to relocate, with regular on-site presence and full presence during audits
  • Relevant certifications (ISO 27001 Lead Implementer / Lead Auditor, CISM, CISSP, CISA) and experience with modern GRC platforms (e.g. Vanta, Drata) are strong pluses

๐Ÿ’ก What We Offer

  • A real ownership mandate: you'll be the person who takes fiskaly through re-certification and shapes how security, quality and compliance work at scale
  • A highly collaborative and international team that values trust, growth, and transparency
  • Competitive salary and benefits package
  • Hybrid setup with a modern office in Vienna, modern tools, and a strong culture of autonomy
  • Time and budget for continuous learning and certifications

๐ŸŒ Why fiskaly?

We're not just building tech, we're shaping the future of digital compliance. At fiskaly, we believe in trust, shared vision, and celebrating success together. If you want to make an impact where security meets innovation, we'd love to hear from you.

Skills

AzureGCPCI/CDRisk ManagementComplianceProcurementChange ManagementGDPRISO 27001CISSP

Similar Jobs

30

Senior Information Security Analyst - IPD - SAS

Wells Fargo ยท 110380-IND-BENGALURU-INTL BLR Twr-1&2 CARNATION, India

Today

Senior Information Security Analyst, Incident Management

Td ยท One Temasek Avenue, Singapore City, Singapore ยท Hybrid

Today

Information Security Engineer

Intuitive Surgical ยท Peachtree Corners, GA, United States

Today

Senior Information Security Specialist

Dev Technology ยท Ashburn, VA (Hybrid) +1 ยท Hybrid

Today

Information security governance Expert

GRUPPO BCC ICCREA ยท MILANO, LOMBARDIA, Italy

Today

Information security governance Junior

GRUPPO BCC ICCREA ยท MILANO, LOMBARDIA, Italy

Today

Information Security Specialist

KOS International Holdings ยท Hong Kong

Yesterday

Information Security & Cyber Lead

Origina ยท Sandyford, Dublin, Ireland

Yesterday

Information Security Risk Analyst

Fisher ยท Camas, WA, US

Yesterday

Information Security Risk Analyst

Fisher ยท Tampa, FL, US

Yesterday

Information Security Risk Analyst

Fisher ยท Plano, TX, US

Yesterday

(USA) Senior Software Engineer, Information Security

Walmart ยท (USA) ISD Office - DGTC AR BENTONVILLE Home Office, United States of America

Yesterday

Sr Analyst III Information Security

DXC Technology ยท IN314 - Quadrant Business park- Pune (IN314), India

Yesterday

Assistant Vice President / Vice President, Cloud Security Analyst, Global Information Security, Sydney, Australia

Ghr ยท Sydney, Australia ยท Onsite

Yesterday

Assistant Vice President / Vice President, Cloud Security Analyst, Global Information Security, Sydney, Australia

Ghr ยท Sydney, Australia ยท Onsite

Yesterday

Information Security Systems Administrator

Work At Vassar Benefits ยท Vassar Main Campus, United States of America

Yesterday

Information Security Analyst II

Mimecast ยท IND - Bengaluru, India ยท Hybrid

Yesterday

Werkstudent (m/w/d) โ€“ Information Security Operations

Vacancies ยท Hamburg - Am Strandkai, Germany

Yesterday

Information Security Systems Officer (ISSO)

I2Xisys ยท Boulder, CO, US ยท Hybrid, Onsite

Yesterday

Senior Information Security Engineer

Globalizationpartners ยท Ireland (Remote-First) ยท Remote

Yesterday

Senior Information Security Engineer

IFS ยท Colombo, Western Province, Sri Lanka

2 days ago

Technical Information Security Officer

Standard Bank Group ยท Douglas, Douglas, Isle of Man

2 days ago

Information Security Expert (m/w/d)

CREALOGIX ยท Stuttgart, Baden-Wurttemberg, Germany ยท Remote

2 days ago

Senior Specialist, Information Security Analyst

0101022-GIA PROD US LOS ANGELES ยท MH, India

2 days ago

Senior Manager Information Security

ASRC Federal ยท Aberdeen Proving Ground, MD 21005, USA

2 days ago

Executive Director, Chief of Staff to the Deputy Chief Information Security Officer

CVS Health ยท Work At Home-Massachusetts, United States of America ยท Remote

2 days ago

Information Security Assurance Analyst I

Global Payments ยท Windward Campus, United States of America +2 ยท Hybrid

2 days ago

Sr Mgr Information Security (US)

Td ยท Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel, New Jersey, United States of America +1 ยท Hybrid

2 days ago

Information Security Professional IV

Ucf ยท UCF Main Campus, United States of America

2 days ago

Lead Engineer, Information Security (Application Security)

Rxo ยท USNC-Charlot15 (2476), United States of America ยท Onsite

2 days ago