Platform Security & Compliance Lead
ТОРО ГРУПС ООД · Lead
Умения
Сертификати
Описание
Platform Security & Compliance Lead
For a client we are looking for:
Platform Security & Compliance Lead
Responsibilities:
• Decide who can access production systems in the EU and how — set it up so remote admin access from outside the EU is blocked by default, temporary access can be requested when genuinely needed, and every session is logged, without slowing the team down day to day.
• Take ownership of the company's compliance certifications (SOC 2 Type II and ISO 27001:2022) — be the main technical point of contact and keep the supporting evidence organized and current — while shaping the plan to eventually add ISO 27701.
• Make sure security checks happen automatically as code moves through development: catching vulnerabilities early, checking third-party libraries, keeping an inventory of what's in each release, changing system credentials on a regular schedule, and keeping cloud infrastructure configured safely.
• Build and maintain the technical systems that let the company delete or restrict someone's personal data properly — across every place that data is stored, starting the moment it's collected, aware of which country's privacy laws apply, and working correctly even during data restores.
• Partner with legal and the data protection to turn privacy requirements into things that are actually built and working, not just written down.
Requirements:
• 5+ years of hands-on experience doing this kind of engineering work directly — still writing infrastructure code and working in Kubernetes yourself day to day, not managing from a distance.
• Have personally led a company through at least one complete certification audit (SOC 2 Type II or similar), from start to finish.
• Comfortable building security checks directly into the development process, rather than reviewing things after the fact.
• Have previously run a compliance program at a company in a regulated industry.
• Comfortable using AI tools to speed up security and compliance-related work.
• Fluent professional English; based in Sofia or open to relocating.
• Nice to have, not required: certifications such as CISSP, CISM, CKS, or CIPP/E.
If you're interested in this opportunity please send us your CV. Only selected candidates will be invited for an interview.
License № 2418 from 18.12.2017
История на обявата
- 10 октомври 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.
Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.