Information Security & Compliance Officer
Smallpdf
Compliance And Security Manager
PDF Tools AG is building its compliance and security capability from an early-stage foundation toward a structured, auditable framework. Today, compliance responsibilities are distributed across leadership — the CEO is formally accountable, the CTO drives execution — but there is no dedicated operational owner. As the company grows and the regulatory landscape intensifies (GDPR, Swiss FADP, AI Act, DORA, NIS2), we need a single person who owns this domain end-to-end and can move it from reactive gap-closing to a sustained, professional program.
This role was created to provide that dedicated ownership: someone who can take over the running compliance program, close remaining gaps, build repeatable processes, and represent the company's security and compliance posture toward customers, auditors, and partners.
Privacy Governance & Data Protection
- Own and maintain the Register of Processing Activities (ROPA) — currently established but requiring ongoing expansion and review.
- Ensure compliance with GDPR and Swiss FADP (revDSG) and CCPA requirements across all company operations.
- Manage data subject request (DSR) workflows and ensure timely, compliant responses.
- Own the retention and deletion policy — define, implement, and enforce data lifecycle rules.
- Maintain and improve the company's privacy policies (website, HR, product-level).
Vendor & Third-Party Risk Management
- Maintain the processor register and DPA repository.
- Ensure all active vendors/processors have reviewed DPAs with appropriate safeguards (SCCs, Swiss addenda).
- Establish and run an annual vendor review cadence.
- Map and document international data transfers and safeguards.
Security & Technical Measures
- Own the company's Technical and Organizational Measures (TOMs) documentation.
- Drive formalization and periodic testing of security controls.
- Coordinate penetration testing with external partners.
- Build toward a security monitoring and incident response capability.
- Own the risk register — maintain it, drive risk owners to close items, report to leadership.
- Evaluate and recommend security tooling (e.g., CVE scanning, static analysis integration, SIEM).
Regulatory & Certification Readiness
- Track emerging regulatory requirements (AI Act, DORA, NIS2) and assess applicability.
- Prepare the company for potential ISO 27001 or SOC 2 certification when strategically appropriate.
- Coordinate with external legal counsel (currently MLL) on regulatory assessments and policy drafting.
Customer & Business-Facing Compliance
- Respond to customer compliance questionnaires and security assessments.
- Support sales and pre-sales with compliance documentation, certifications overview, and security posture materials.
- Ensure product-level compliance considerations (e.g., OSS license management, SBOM generation) are integrated into engineering workflows.
What You Will Not Own (But Will Collaborate On)
- OSS license compliance in code : Engineering owns remediation and CI/CD integration — you provide the policy framework and audit.
- Product security features (encryption, access control, signatures): Engineering and Product own implementation — you define requirements and validate.
- Contract negotiation : Legal and Sales lead — you provide compliance input and review DPA terms.
- IT operations and infrastructure security : IT/DevOps owns day-to-day — you define policy and audit.
What This Looks Like Day-to-Day
In the first 6 months, you will spend most of your time closing existing gaps: completing the ROPA, getting DPAs in place, formalizing TOMs, and building the risk register into a living document. You will work closely with the CTO, who has been driving this work and will hand over operational ownership to you. You will also interface with external counsel and respond to customer questionnaires that come in through Sales.
Once the foundation is solid, the role shifts toward maintaining and improving the program: running periodic reviews, preparing for audits, tracking regulatory changes, and building internal awareness through training and guidelines.
What We Are Looking For
Must-Have
- 3–5+ years of experience in information security, data protection, or compliance roles — ideally in a B2B software or SaaS environment.
- Working knowledge of GDPR and Swiss FADP, including hands-on experience with ROPAs, DPAs, DSR handling, and data transfer mechanisms (SCCs, adequacy decisions).
- Familiarity with security frameworks and controls: ISO 27001, SOC 2, or similar — you don't need to have led a certification, but you should understand the requirements.
- Ability to build and maintain a risk register and drive risk mitigation across teams.
- Strong written and verbal communication in English (working language). German is a significant plus for Swiss regulatory context and local vendor interactions.
- Pragmatic and structured: you can prioritize what matters in a 50-person company, not gold-plate processes designed for 5,000.
- Comfortable working independently — this is a one-person function with leadership support, not a large team.
Nice-to-Have
- Experience with OSS license compliance (SBOM generation, license scanning tools like BlackDuck, FOSSA, or similar).
- Exposure to AI Act, DORA, or NIS2 requirements.
- Background in software development or engineering — enough to understand CI/CD pipelines, cloud infrastructure, and product architecture at a conceptual level.
- Experience in an M&A or due diligence context where compliance posture was a factor.
- Relevant certifications: CIPP/E, CIPM, CISM, ISO 27001 Lead Implementer, or similar.
Why you'll love working at Pdftools
Pdftools is a place where people genuinely care about doing things well.
We believe in precision, empathy, collaboration, and continuous improvement - and we live those values every day.
You'll be supported by deep technical expertise, surrounded by kind people, and given the space to build something meaningful. With a strong, trusted product behind you and a team committed to solving real problems together, your work will matter far beyond marketing.
Because our technology touches essential workflows around the world, your impact will reach people and organizations who rely on us when trust and integrity matter most.
If you want to help shape the way the world shares information with trust and integrity - we'd love to meet you.
Our benefits
You get to impact how over 30 million people get work done monthly.
Push boundaries and dare to fail - that's how we learn!
30 vacation days - yep, you read that right - you can take them whenever you need them.
Flexibility: we have flexible working hours.
Need a long break? We offer sabbatical leave to employees who've been with us for over two years.
16 weeks parental leave - 100% of your salary - for all new parents.
Don't leave your four-legged friends at home; our Zurich office is pet-friendly.
A well-being budget of up to 2,000 CHF every year that can be used for training and development (plus days off for courses or training) and for physical and mental well-being purposes.
Possibility of a Phantom stock option plan - PSOP (Conditions apply).
Hack days to challenge you and your team, plus build amazing things.
How to Apply
Please apply using the form below and upload your CV - in English, as it's the standard working language at Pdftools. A PDF format is preferred.
Compensation philosophy
At Pdftools, we believe compensation should be fair, transparent, and thoughtfully aligned with the value each person brings to our team. Our approach balances several key factors - current market trends, role expectations, seniority, experience, and geographic location - to ensure every offer is both competitive and equitable.
We review our salary ranges regularly to stay in step
- ## Chief Information Security Officer & Product Regulatory Compliance Officer (m/w/d)Applylocations: Stuttgart Area: Backnangtime type: Full timeposted on: Posted Todayjob requisition id: JR10404377****Job Description:****## **Aufgaben und Verantwortlichkeiten:*** Operative...SuggestedPermanent employmentContract workFlexible hours
- ...Junior Compliance Manager / Information Security Officer (m/f/d) Starting immediately – Permanent – Full-time – Remote – Germany Welcome to Xiting’s Career Page! In this newly created position, you will support our CISO in building and continuously developing the company...SuggestedPermanent employmentFull timeImmediate startRemote work
$113k - $188k
...Guidehouseâ??s cyber practice, you will lead and execute core security compliance and RMF activities for classified federal systems.... ...the engagement. What You Will Do : The Information Systems Security Officer ( ISSO ) serves as the primary liaison between the...SuggestedTemporary workFlexible hours- ...Chief Information Security Officer (CISO) Our client is a leading provider specializing in laboratory testing services, dedicated to delivering... ...of sensitive healthcare and laboratory data, ensuring compliance with all relevant regulations (e.g., HIPAA, HITECH, and GDPR...SuggestedRemote work
- ...leader responsible for building, implementing, and overseeing the university's information security program. This role is critical to establishing robust security policies, ensuring compliance, and preparing for future audits. The ACIO/CISO will also play a key part in...SuggestedInterim roleRelocation
- ...Information Systems Security Manager And/Or Officer Lackland Air Force Base - JBSA-Lackland AFB, TX 78236 Overview Level Experienced Position Type... ...program activities, including risk management, compliance, and security operations. Provides guidance to leadership...Full timeContract workFor contractorsLocal areaWorldwide
- ...Koniag Government Services company , is seeking an Information System Security Manager/Officer (ISSM/O) with TS/SCI security clearance to support KTIS... ...timelines Ensure Continuous Monitoring (ConMon) compliance Facilitate smooth transition to sustainment ownership...Interim roleLocal areaRemote workFlexible hours
- ...Senior Information Security Officer We're looking for a skilled Senior Information Security Officer to join Definely at a pivotal stage of... ...implementing and maintaining our security standards, supporting compliance programs, and promoting secure practices across...Contract workPrivate practiceRemote work
- ...The Citizens Bank of Philadelphia is currently seeking an Information Security Officer, as follows: Position Information Security Officer Location/Travel Open/Some travel (MS) About the Position Oversee the establishment and maintenance of the enterprise...For contractors
$93.2k - $164.45k
...Systems (LM RMS), F-35 Cyber Security invites you to step up to... ...'ll safeguard the sensitive information and warfighting capabilities... ...Information System Security Officer (ISSO) position will support... ...procedures. Monitoring for non-compliance, anomalous activity (i.e.,...Full timeTemporary workWork experience placementWork at officeFlexible hoursShift workDay shift- ...transferable U.S. government issued security clearance is required prior to... ...interface and collaborate with the Information System Security Officers (ISSO) and Information Systems Security... ...You will be assisting with system compliance, auditing, security plan development...InternshipWork at officeRemote workRelocationRelocation package
$145k - $170k
...Chief Information Security Officer Remote The Chief Information Security Officer (CISO) is responsible for establishing, leading, and maintaining... ..., responsible for security strategy, risk management, compliance, incident response, and security operations. This role...Work experience placementRemote workFlexible hours- ...Chief Information Security Officer (CISO) About the Company Respected public research university Industry Higher Education Type Privately Held, VC-backed Founded 1863 Employees 5001-10,000 Funding Categories Education Social Entrepreneurship Universities Agriculture Animals...
$72.18k - $100k
...Salary Range: $72,181.00 - $100,000.00 Security Clearance: TS/SCI Level of... ...short video: Job Description As the Information Systems Security Officer (ISSO) the individual works closely... ...strategies to achieve and sustain RMF compliance. Job Duties Include: Performing vulnerability...Full timeWork experience placementWork at officeLocal areaWorldwide$131.3k - $237.35k
...Leidos has a new and exciting opportunity for a Senior Information System Security Officer in our National Security Sector's (NSS) Cyber &... ...firmware. Develop system security policy and ensure compliance. Administer the user identification and authentication...Local areaImmediate startFlexible hours$131.3k - $237.35k
...Leidos has a new and exciting opportunity for a Senior Information Systems Security Officer (ISSO) in our Intelligence Sector, Cyber & Analytics... ...systems through robust security measures and compliance frameworks. This multi-year, high-impact program supports...Contract workLocal areaImmediate startRelocation packageFlexible hours- ...Information Security Employee (F/M/D) The local information security officer (LISO) is responsible for establishing, implementing, and maintaining effective information security governance, policies, and procedures within the Porsche Holding Group in Ukraine (Porsche...Local areaRemote work
- ...to focus on improving the quality and safety of patient care. Security Clearance Requirements US Citizenship or documented proof of eligibility... ...and Milestones) that developers can understand. Cloud-Native Compliance: Understanding of how to document security controls for AWS-...Temporary workWork at officeRemote workWork from homeFlexible hours
- ...Information Technology Security Officer (m/w/d) To support the "Data Center Technologies" department, Airbus Secure Land Communications GmbH is looking for an Information Technology Security Officer (m/w/d) in Ulm or Berlin. Help us to expand and secure critical...Local areaRemote work
$210k - $220k
...Chief Information Security Officer (CISO) Are you interested in working with the World's leading AI-powered Quality Engineering Company? Ready... ...recovery and business continuity plans Ensure compliance with industry standards and regulations (ISO 27001, NIST,...Casual workLocal areaFlexible hours$175k
...professional development assistance. YSIis seeking an Information System Security Officer (ISSO) . The ideal candidate will be responsible for the... ...selection, implementation, assessment, and authorization in compliance with NIST 800-37 and federal requirements. Develops,...Temporary workImmediate startRemote work- ...Providing strategic leadership in a remote, full-time capacity, the Chief Information Security Officer will manage information governance, cybersecurity, and AI initiatives while ensuring compliance and operational excellence across the organization. Key Responsibilities...Full timeRemote work
$87.1k - $157.45k
...Description Information System Security Officer (ISSO) White Sands Missile Range, NM Leidos has an exciting opportunity for an Information... ...readiness, security processes and develop briefings, and compliance with evolving DoD cybersecurity directives. Provide...Work at officeLocal areaImmediate start- ...Chief Information Security Officer (CISO) About the Company Accomplished executive search firm Industry Staffing and Recruiting Type... ...risks, responding to security incidents, and ensuring compliance with relevant regulations and industry standards. Applicants...
$105k - $135k
...Information System Security Officer Dark Wolf is looking for an Information System Security Officer to join a collaborative, dynamic team in a... ...development, security engineering, risk management, and compliance. The successful candidate will have strong written and...For contractorsRemote work- ...Senior Information Security Officer Hawk is the leading provider of AI-supported anti-money laundering and fraud detection technology. Banks... ...explainable AI to improve the effectiveness of their AML compliance and fraud prevention by identifying more crime while maximizing...Remote work
- ...certification and SOC 2 Type II attestation. Security and compliance are not afterthoughts at UniUni; they... ...to: Chief Technology & Product Officer (CTPO) Location: North... ...The Role We are hiring an Information Security Officer to lead UniUni's security...Contract workRemote workWorldwide
- ...Chief Information Security Officer (CISO) Organization: Nymbus Location: Fully remote; occasional travel may be required for client meetings and team gatherings. Description: About the job ABOUT NYMBUS: Nymbus is a modern fintech company delivering...Contract workRemote workNight shift
- ...Virtual Cybersecurity Or Compliance Expert Soum is on a mission to revolutionize e-commerce in the MENA region and beyond by building... ...for a virtual cybersecurity or compliance expert to guide our security posture, particularly as we move into regulated spaces like...Remote work
$190k - $220k
...divh2Chief Information Security Officer/h2pPosition at Zones LLC. Company Overview: When it comes to IT solution providers, there are a lot of... ...currently offers paid time off and personal sick leave in compliance to individual state requirements. At Zones, work is more...Work at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security & Compliance Officer. Be the first to apply!
- chief information security officer ciso United States
- business information security officer biso United States
- business information security officer United States
- information systems security officer United States
- remote ciso United States
- chief information security officer United States
- information security officer United States
- information security officer iso United States
- ciso United States
- financial compliance analyst United States

