Head of Information Security and Compliance
We're looking for a pragmatic, Director-level security leader to unify and mature information security and compliance across a fast-growing, international group of businesses. You'll step in as the most senior security voice in the organization, bringing coherence to security practices that have grown up independently across several acquired entities. This is a highly autonomous role: you'll own the ISMS end to end, steer ISO 27001 through its audit cycles, and make sure GDPR is applied consistently across every jurisdiction the group operates in. Beyond the technical and regulatory work, you'll be a commercial partner to the business, joining customer calls to defend the company's security posture and help close deals. The role reports directly to the executive team and carries real influence over how security decisions get made. We're looking for someone who reduces risk pragmatically, not someone who adds process for its own sake.
Details:
Schedule: Full time
Location: Krakow, Poland or Warsaw, Poland (Hybrid)
Start: ASAP
Duration: Long-term
English: Fluent
Type of collaboration: B2B
About the project: The organization is a fast-growing, international B2B SaaS group offering a unified platform for the real estate industry. It has scaled rapidly through a series of strategic acquisitions across multiple countries, bringing together teams and systems that previously operated independently. As the group has grown, so has the need for a single, coherent security and compliance standard that all entities can work to, rather than a patchwork of local approaches. The business operates in a regulated, data-sensitive space, working with enterprise customers who expect a mature, demonstrable security posture as part of any commercial relationship. Security here is treated as a business enabler: the goal is to move fast and close deals while keeping risk genuinely under control, not to build a heavyweight compliance function that slows the business down.
You have:
- Experience leading information security and compliance as the most senior security person in a business
- A proven track record of taking ISO 27001 through at least one full audit cycle
- Practical experience applying GDPR across multiple countries or jurisdictions
- An active CISSP, CISM, or equivalent certification
- Ideally, experience maturing security in a group built through strategic acquisitions (M&A integration)
- Ideally, a background in B2B SaaS technology
- A plus: professional proficiency in Polish
- The ability to work hybrid from Krakow or Warsaw, Poland
What to do:
- Own the information security and compliance program as the most senior security leader in the business
- Lead ISO 27001 certification and audit cycles across the group's entities
- Ensure consistent, practical application of GDPR across all jurisdictions the group operates in
- Unify and standardize security practices across newly and previously acquired entities
- Manage and mature the organization's Information Security Management System (ISMS)
- Own incident response planning and execution
- Lead risk management activities across the group
- Work toward and maintain alignment with frameworks such as Cyber Essentials Plus and SOC 2
- Join customer-facing and commercial calls to represent and defend the company's security posture
- Balance pragmatic risk reduction with the group's commercial velocity, avoiding unnecessary bureaucracy