Information Security & Product Compliance Engineer
Shelly Group · Sofia City, Bulgaria · Mid
Умения
Сертификати
Регулации и стандарти
Описание
About
We make smart devices and push the boundaries of the IoT sector every single day. Shelly is a strong company with a startup mindset - no bureaucracy, just bold ideas, creative problem-solving, and a team that genuinely loves what they do.
We turn every spark of an idea into a real product - from first concept to full production - and bring smart automation to over 3 million households around the world. From heating, lighting, appliances, curtains, and more - if it runs on electricity, chances are we can automate it. We've built over 100 smart devices (and counting!), and everything happens right here at our headquarters in Sofia.
Sounds exciting? Keep reading...
Information Security & Compliance Officer
Your Role:
We are looking for an Information Security & Compliance Officer to lead our information security and regulatory compliance efforts across the entire organization.
This is a cross-functional, coordination-focused role - not a deeply technical one. You will be the person who connects the dots between departments (IT, Engineering, Product, Operations, HR, Legal, and Management), turning security and compliance requirements into clear policies, processes, and everyday practices that teams can actually follow.
Your main focus will be corporate information security and regulatory compliance with the EU landscape that shapes our industry - including the Cyber Resilience Act (CRA), NIS2, GDPR, and standards such as ISO/IEC 27001. You will drive the programs, coordinate their implementation across teams, monitor progress, and make sure Shelly stays secure, compliant, and audit-ready as we continue to grow.
What makes you a great fit:
- 3+ years of experience in information security, compliance, risk, or IT governance
- Good understanding of the EU regulatory landscape and the ability to translate it into practical, easy-to-follow processes:
- Cyber Resilience Act (CRA)
- NIS2 Directive
- GDPR
- ISO/IEC 27001
- Experience designing and rolling out security policies, procedures, and internal controls
- Experience coordinating cross-functional initiatives and driving them to completion across multiple departments
- Solid understanding of information security fundamentals and best practices (you don't need to be a hands-on engineer, but you should speak the language and understand the concepts)
- Experience with risk assessments, audit preparation, and working with external auditors or authorities
- Strong project and stakeholder management skills - able to align teams, set expectations, and follow through
- Excellent communication skills - able to explain security and compliance clearly to both technical teams and non-technical colleagues and management
- Proficiency in English
- Highly organized, structured, and proactive, with a strong sense of ownership
- Nice to have: relevant certifications (ISO 27001 Lead Implementer/Auditor, CISM, CISSP, CIPP/E, or similar)
Your Responsibilities
- Own and continuously improve the company's information security and compliance program, policies, and procedures
- Drive compliance with CRA, NIS2, GDPR, and ISO/IEC 27001 across the organization
- Act as the central point of contact for information security and compliance, and coordinate implementation across all departments (IT, Engineering, Product, Operations, HR, Legal, etc.)
- Translate regulatory and security requirements into clear, practical processes and internal controls that teams can adopt in their daily work
- Conduct and coordinate risk assessments, define remediation plans, and track them to completion
- Maintain the security and compliance documentation, registers, and evidence needed for audits and certifications
- Prepare for and support internal and external audits, assessments, and certifications
- Coordinate the response to security incidents and data-related matters - organizing the right people, documenting, and following up on improvements
- Monitor and report on the company's security and compliance status, risks, and progress to management
- Plan and deliver security awareness training and promote a strong security culture across the company
- Liaise with external vendors, auditors, consultants, and regulatory bodies as needed
- Stay up to date with evolving regulations and best practices, and proactively recommend improvements
What is in it for you
Work:
A welcoming, collaborative team
Meaningful products and services that people actually use and love.
Learning opportunities to sharpen your skills
Competitive salary + Performance bonuses
Modern office in a great location
Fun team buildings and company events
Lifestyle:
26 days of paid annual leave
Flexible working hours
Additional health insurance
Free access to all Shelly devices (yes, you can smarten up your whole home!)
Multisport Card
Fully sponsored yearly public transport card
Ready to join the Shelly Revolution?
Let’s build the future of smart living together.
Hit that Apply button — we can’t wait to meet you.
История на обявата
- 15 септември 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.
Само 2 обяви за тази роля и ниво публикуват заплата — твърде малко за средна стойност.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.