Remote Source

    Senior Information Security Specialist

    Poland
    Full-Time
    Senior (7+ yrs)
    IT & Security
    Posted on June 10, 2026

    SmartRecruiters is looking for a Senior Information Security Specialist to join the Governance, Risk & Compliance (GRC) team. This role is critical to ensuring that SmartRecruiters' applications, systems, and processes remain compliant with industry standards and regulatory requirements, including ISO 27001, ISO 22301, ISO 42001, SOC 2 Type II, Cyber Essentials, GDPR, and the EU AI Act.

    The successful candidate will combine strong GRC expertise with a technical, engineering mindset - someone who can drive compliance programmes across multiple frameworks while also stepping into complex technical topics such as business continuity, AI security, and cloud compliance. Critically, this is not a purely audit-focused role; we need someone who can dig into technical details, assess security architectures, support forensic investigations, build automation to replace manual processes, and provide hands-on guidance to engineering and security teams. A core part of this role is identifying opportunities to engineer scalable, repeatable solutions, from compliance evidence collection to policy enforcement, rather than relying on manual effort.


    Responsibilities

    Governance, Risk & Compliance

    • Identify manual, repetitive GRC processes and design automation blueprints to streamline them, including evidence collection, control monitoring, access reviews, policy enforcement checks, and compliance reporting
    • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit-readiness
    • Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities (e.g., vendor assessments, internal audits, risk reviews) to ensure consistency and scalability.
    • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable
    • Continuously evaluate and improve GRC tooling, data flows, and reporting to drive operational efficiency across the team
    • Manage stakeholder expectations and partner with internal teams to ensure effective management of IT risks and compliance obligations
    • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports.
    • Support the maintenance of the SOC 2 Type II framework, including evidence collection, control testing coordination, and audit support
    • Effectively manage ISO 27001 and ISO 22301 audit lifecycles and coordinate with stakeholders on ISMS and BCMS improvements
    • Support the maintenance and continuous improvement of the ISO 42001 (AI Management System) framework in alignment with the EU AI Act
    • Support vendor risk management activities, including third-party security assessments and due diligence reviews

    Business Continuity & ISO 22301

    • Serve as a subject matter expert or key contributor for the Business Continuity Management System (BCMS), supporting the strategy, framework, and audit programme under ISO 22301
    • Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity metrics management

    AI Security & Compliance

    • Support AI security and compliance activities, including the assessment of AI-related risks, alignment with ISO 42001 controls, and regulatory readiness under the EU AI Act
    • Collaborate with product and engineering teams to evaluate security controls for AI/ML features and services

    Company:  SmartRecruiters

    Provides enterprise-grade hiring platform designed for HR and recruiting talent with all-in-one solution for tracking applicants.
    501-1000 employees
    Human Resources & Recruiting
    HQ: United States