Senior Information Security Specialist

Other Jobs To Apply

No other job posts for this day.

<section class="job-section" id="st-companyDescription"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Company Description</h2></div><div class="wysiwyg"><p>SmartRecruiters is the Recruiting AI Company that transforms hiring for the world’s leading enterprises. Built for global scale, SmartRecruiters, an SAP company, delivers an AI-powered hiring platform that automates and optimizes the entire talent acquisition process, ensuring faster and smarter hiring decisions. More than 4,000 companies, including Amazon, Visa, and McDonald's, rely on SmartRecruiters to build winning teams. In 2025, SmartRecruiters joined SAP, the global leader in enterprise applications. Together, SmartRecruiters and SAP are accelerating the reinvention of hiring by combining cutting-edge AI innovation with the scale, reach, and resources of SAP’s ecosystem.</p><p>At SmartRecruiters, we are a values-driven, globally focused tech company with strong financial backing and a bold vision for the future of work. We commit and dig deep, embracing challenges with grit, curiosity, and a drive for excellence. We foster a collaborative and inclusive work environment, where trust and determination bring us together. Because together, we will win.<br> <br> Recognized by Fosway Industry Analysts as a strategic leader in recruitment technology for three consecutive years, and awarded by Comparably as a top company for Women, Perks and Benefits, Work-Life Balance, Happiness, Compensation, Diversity, and Culture - we take pride in creating a place where everyone can thrive. Our remote-friendly culture, competitive salaries, and strong internal mobility ensure that high performers have meaningful growth opportunities in an environment built on respect and empowerment.</p></div></section><section class="job-section" id="st-jobDescription"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Job Description</h2></div><div class="wysiwyg" itemprop="responsibilities"><p>SmartRecruiters is looking for a <strong>Senior Information Security Specialist</strong> to join the Governance, Risk & Compliance (GRC) team. This role is critical to ensuring that SmartRecruiters' applications, systems, and processes remain compliant with industry standards and regulatory requirements, including ISO 27001, ISO 22301, ISO 42001, SOC 2 Type II, Cyber Essentials, GDPR, and the EU AI Act.</p><p>The successful candidate will combine strong GRC expertise with a technical, engineering mindset - someone who can drive compliance programmes across multiple frameworks while also stepping into complex technical topics such as business continuity, AI security, and cloud compliance. Critically, this is not a purely audit-focused role; we need someone who can dig into technical details, assess security architectures, support forensic investigations, build automation to replace manual processes, and provide hands-on guidance to engineering and security teams. A core part of this role is identifying opportunities to engineer scalable, repeatable solutions, from compliance evidence collection to policy enforcement, rather than relying on manual effort.</p><p><br> <strong>Responsibilities</strong></p><p><strong>Governance, Risk & Compliance</strong></p><ul><li>Identify manual, repetitive GRC processes and design automation blueprints to streamline them, including evidence collection, control monitoring, access reviews, policy enforcement checks, and compliance reporting</li><li>Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit-readiness</li><li>Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities (e.g., vendor assessments, internal audits, risk reviews) to ensure consistency and scalability.</li><li>Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable</li><li>Continuously evaluate and improve GRC tooling, data flows, and reporting to drive operational efficiency across the team</li><li>Manage stakeholder expectations and partner with internal teams to ensure effective management of IT risks and compliance obligations</li><li>Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports.</li><li>Support the maintenance of the SOC 2 Type II framework, including evidence collection, control testing coordination, and audit support</li><li>Effectively manage ISO 27001 and ISO 22301 audit lifecycles and coordinate with stakeholders on ISMS and BCMS improvements</li><li>Support the maintenance and continuous improvement of the ISO 42001 (AI Management System) framework in alignment with the EU AI Act</li><li>Support vendor risk management activities, including third-party security assessments and due diligence reviews</li></ul><p><strong>Business Continuity & ISO 22301</strong></p><ul><li>Serve as a subject matter expert or key contributor for the Business Continuity Management System (BCMS), supporting the strategy, framework, and audit programme under ISO 22301</li><li>Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity metrics management</li></ul><p><strong>AI Security & Compliance</strong></p><ul><li>Support AI security and compliance activities, including the assessment of AI-related risks, alignment with ISO 42001 controls, and regulatory readiness under the EU AI Act</li><li>Collaborate with product and engineering teams to evaluate security controls for AI/ML features and services</li></ul></div></section><section class="job-section" id="st-qualifications"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Qualifications</h2></div><div class="wysiwyg" itemprop="qualifications"><ul><li>5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation</li><li>Demonstrated compliance or auditing experience with at least one major framework</li><li>Hands-on experience with incident response - including participation in security incident investigations, containment, and post-mortem processes</li><li>Solid understanding of controls auditing principles and evidence management</li><li>Technical understanding of cloud infrastructure (AWS preferred), networking fundamentals, identity management, and SaaS security architectures</li><li>Knowledge of risk management methodologies and experience conducting or supporting risk assessments</li><li>Ability to manage and deliver on multiple complex projects simultaneously, with minimal supervision</li><li>The ability to investigate, question, and interpret internal and external IT security and compliance issues at both a governance and technical level</li><li>A strong understanding of technology, cloud-based products, and SaaS environments</li><li>Experience working across business units and geographical boundaries to engage engineering, business, and operational teams</li><li>Experience with ISO 27001</li><li>Excellent written and verbal communication skills in English</li></ul><p><strong>Nice to have</strong></p><ul><li>Professional certifications such as CISA, CRISC, CISM, CISSP, CCSK, CCSP, or equivalent</li><li>Experience with ISO 9001, 27017, and 27018 </li><li>Experience with ISO 22301 (Business Continuity), including BIA, BCP/DRP, and recovery testing</li><li>Experience with BSI C5 (Cloud Computing Compliance Criteria Catalogue) or similar cloud-specific compliance frameworks</li><li>Knowledge of AI security principles, experience with ISO 42001, or familiarity with the EU AI Act and its technical requirements</li><li>Experience with enterprise risk management frameworks and tools</li><li>Understanding of threat modelling methodologies and secure development lifecycle (SDLC) principles</li></ul></div></section><section class="job-section" id="st-additionalInformation"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Additional Information</h2></div><div class="wysiwyg" itemprop="incentives"><p>SmartRecruiters is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.</p></div></section>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...