LinkedIn

Information Security & Product Compliance Engineer

Shelly Group · Sofia City, Bulgaria · Mid

14 септември 2026 г.
Публикувана
15 септември 2026 г.
Последно видяна
Активна
Статус
1 ден
Отворена от

Умения

Сертификати

Изискват се

Регулации и стандарти

Описание

About

We make smart devices and push the boundaries of the IoT sector every single day. Shelly is a strong company with a startup mindset - no bureaucracy, just bold ideas, creative problem-solving, and a team that genuinely loves what they do.

We turn every spark of an idea into a real product - from first concept to full production - and bring smart automation to over 3 million households around the world. From heating, lighting, appliances, curtains, and more - if it runs on electricity, chances are we can automate it. We've built over 100 smart devices (and counting!), and everything happens right here at our headquarters in Sofia.

Sounds exciting? Keep reading...

Information Security & Compliance Officer

Your Role:

We are looking for an Information Security & Compliance Officer to lead our information security and regulatory compliance efforts across the entire organization.

This is a cross-functional, coordination-focused role - not a deeply technical one. You will be the person who connects the dots between departments (IT, Engineering, Product, Operations, HR, Legal, and Management), turning security and compliance requirements into clear policies, processes, and everyday practices that teams can actually follow.

Your main focus will be corporate information security and regulatory compliance with the EU landscape that shapes our industry - including the Cyber Resilience Act (CRA), NIS2, GDPR, and standards such as ISO/IEC 27001. You will drive the programs, coordinate their implementation across teams, monitor progress, and make sure Shelly stays secure, compliant, and audit-ready as we continue to grow.

What makes you a great fit:

  • 3+ years of experience in information security, compliance, risk, or IT governance
  • Good understanding of the EU regulatory landscape and the ability to translate it into practical, easy-to-follow processes:
  • Cyber Resilience Act (CRA)
  • NIS2 Directive
  • GDPR
  • ISO/IEC 27001
  • Experience designing and rolling out security policies, procedures, and internal controls
  • Experience coordinating cross-functional initiatives and driving them to completion across multiple departments
  • Solid understanding of information security fundamentals and best practices (you don't need to be a hands-on engineer, but you should speak the language and understand the concepts)
  • Experience with risk assessments, audit preparation, and working with external auditors or authorities
  • Strong project and stakeholder management skills - able to align teams, set expectations, and follow through
  • Excellent communication skills - able to explain security and compliance clearly to both technical teams and non-technical colleagues and management
  • Proficiency in English
  • Highly organized, structured, and proactive, with a strong sense of ownership
  • Nice to have: relevant certifications (ISO 27001 Lead Implementer/Auditor, CISM, CISSP, CIPP/E, or similar)

Your Responsibilities

  • Own and continuously improve the company's information security and compliance program, policies, and procedures
  • Drive compliance with CRA, NIS2, GDPR, and ISO/IEC 27001 across the organization
  • Act as the central point of contact for information security and compliance, and coordinate implementation across all departments (IT, Engineering, Product, Operations, HR, Legal, etc.)
  • Translate regulatory and security requirements into clear, practical processes and internal controls that teams can adopt in their daily work
  • Conduct and coordinate risk assessments, define remediation plans, and track them to completion
  • Maintain the security and compliance documentation, registers, and evidence needed for audits and certifications
  • Prepare for and support internal and external audits, assessments, and certifications
  • Coordinate the response to security incidents and data-related matters - organizing the right people, documenting, and following up on improvements
  • Monitor and report on the company's security and compliance status, risks, and progress to management
  • Plan and deliver security awareness training and promote a strong security culture across the company
  • Liaise with external vendors, auditors, consultants, and regulatory bodies as needed
  • Stay up to date with evolving regulations and best practices, and proactively recommend improvements

What is in it for you

Work:

A welcoming, collaborative team

Meaningful products and services that people actually use and love.

Learning opportunities to sharpen your skills

Competitive salary + Performance bonuses

Modern office in a great location

Fun team buildings and company events

Lifestyle:

26 days of paid annual leave

Flexible working hours

Additional health insurance

Free access to all Shelly devices (yes, you can smarten up your whole home!)

Multisport Card

Fully sponsored yearly public transport card

Ready to join the Shelly Revolution?

Let’s build the future of smart living together.

Hit that Apply button — we can’t wait to meet you.

История на обявата

  • 15 септември 2026 г.Появи сеобхождане

Очаквано възнаграждение

Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.

€1,300€2,300нето/месец · 2 – 5 години опит
Средно търсене·Всички нива за ролята

Само 2 обяви за тази роля и ниво публикуват заплата — твърде малко за средна стойност.

Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.