Kiteworks logo

Senior Information Security Officer

Kiteworks

Full-time
5-10 years experience
Hybrid

€70,000 - €80,000 per year

Work Arrangement

Office Days per Week: 3 days

Key Skills

Information security
Compliance
ISO 27001
SOC 2
BSI C5
Risk analysis
Identity and access management
GDPR
Privacy legislation
Auditing
Threat analysis
Security incident handling
AI
Software development
Problem-solving
Collaboration

Job Description

As a Senior Information Security Officer, you will be part of the global security and compliance team. This team takes care of corporate security, including IT and cloud security, as well as the full compliance program of Kiteworks. As Kiteworks sells secure communication and collaboration products, security and compliance are top priorities for the company. Kiteworks has many security certifications and assurance reports, and as the business expands to new jurisdictions, it will need to obtain more certifications in the coming years.

As a senior member of the team, you will report directly to the Global IT CISO and are expected to work independently as well as take the lead on team projects. The role requires you to work on many things simultaneously, such as running audits, performing gap or threat analyses, and answering customer questions. We also count on you to champion security improvement initiatives, whether that's access management or software development. As part of these projects, you will be collaborating with other teams, such as IT and development.
Kiteworks moves fast, and it's our team's job to manage risk while helping the business grow just as fast. That balancing act matters more than ever as Kiteworks embraces AI, and we're the ones making sure that adoption happens securely.

We are specifically looking for a pragmatic problem solver who not only identifies risks but also proposes mitigations and gets things done.

We may be in compliance, but we are allergic to bureaucracy.

Note: this is a hybrid role with three days in our Amsterdam office. 

What You'll Do
  • Taking ownership of external security audits such as ISO 27001, BSI C5, and SOC 2
  • Performing gap analysis and implementing new security frameworks and standards
  • Keeping information security procedures up to date across departments
  • Acting as full domain owner for at least the identity and access management and supplier management domains
  • Executing control tasks, for example access checks, supplier reviews, and internal audits
  • Using AI to automate recurring tasks
  • Coordinating with control owners to support timely execution of their tasks
  • Implementing security improvement projects, for example in IT or software development
  • Handling security incidents
  • Taking part in the weekly security meeting and flagging new risks and opportunities
  • Answering questions on security and privacy from customers, prospects, and colleagues
  • Onboarding newly acquired companies to the global security and compliance program

What You'll Bring
  • At least 5 years' experience in information security and compliance
  • Experience with ISO 27001 and information security management systems
  • Experience with BSI C5 or SOC 2
  • Experience with audits
  • Experience with risk analysis
  • Experience with identity and access management
  • Knowledge of the GDPR and privacy legislation
  • Affinity with IT and software development
  • Affinity with AI
  • Experience in a tech company is highly preferred
  • Pragmatic problem-solving skills
  • Ability to work independently
  • Collaboration skills
  • Fluent in English

About Kiteworks
The Kiteworks single-tenant-by-design virtual appliance delivers full data sovereignty, governing employees’ and AI agents’ access to, use, and sharing of sensitive data under the same identity, policy, encryption, and audit controls. Compliance is built in, not bolted on.
 
The values that define us
  • Execution – We deliver results with focus, ownership, and consistency. Our teams take initiative, solve challenges proactively, and continuously optimize how we work to create meaningful impact for our customers.
  • Transparency – We communicate openly and clearly, ensuring stakeholders have the information they need to make informed decisions. We foster a culture of trust, welcome feedback, and embrace accountability in everything we do.
  • Integrity – We uphold the highest standards of honesty and responsibility. Our teams act ethically, consistently honor commitments, and build trust through principled, reliable actions.

Compensation range:
  • Salary Range: €70,000 - €80,000
  • Base pay depends on many factors, such as location, education, experience, and skills. Base pay is only one part of Kiteworks competitive Total Rewards package that can include benefits, perks, equity, and bonuses. The base pay range is subject to change and may be modified in the future.

Perks & benefits:
  • Stock options
  • Hybrid working model 
  • PTO: Unlimited (guided ~35 days/year including public holidays)
  • Pension Plan 
  • Temporary working from X

Commitment to equal opportunity & inclusion
Kiteworks is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.

Other requirements
Ability to meet Kiteworks, customer, and/or government security screening requirements for this role. These requirements include, but are not limited to, the following specialized security screenings.
Kiteworks Background Check
This position requires passing the Kiteworks background check upon hire/transfer and every two years thereafter.

Core Responsibilities

The Senior Information Security Officer will lead external security audits, perform gap analyses, and manage security and compliance frameworks. They will also act as a domain owner for identity and access management while collaborating with IT and development teams to implement security improvements.

Requirements

Candidates must have at least 5 years of experience in information security and compliance, including proficiency with ISO 27001, SOC 2, and risk analysis. Strong problem-solving skills, the ability to work independently, and familiarity with privacy legislation like GDPR are essential.

Benefits

  • Stock options
  • Hybrid working model
  • Unlimited PTO
  • Pension plan
  • Temporary working from abroad

About Kiteworks

Industry: Software Development

Company size: 501-1,000 employees

Kiteworks empowers organizations with a robust control plane for secure data exchange, ensuring secure and compliant data exchanges across all channels, including email, file sharing, and APIs. To this end, we created a platform that delivers data governance, compliance, and protection to customers. The platform controls, monitors, and protects every data interaction between people, machines, and systems across user collaboration, automated workflows, and enterprise AI. With on-premises, private cloud, hybrid, and FedRAMP deployment options, the Kiteworks platform provides the security and governance C-suite leaders need to protect their organizations, mitigate risk, and adhere to rigorous compliance regulations such as NIST CSF, HIPAA, SOX, GDPR, GLBA, FISMA, and the latest compliance standards, ensuring up-to-date data protection and governance.

Added Today