Skip to main content

Information Security Officer

€4.1–4.6K / monthHybridPart timeSenior

Leinster, Ireland · Posted 6 hr. ago

Position: Information Security Officer (part-time employee)

Reports to: Director of Engineering - DevOps, IT, Security and Privacy

Location: Dublin, Ireland. Hybrid, must be able to make occasional trips to our Dublin office

Employee Status:Part-time employee/20 hours a week with the potential for extension based on business needs and performance.

Salary Range: €4100 – €4600/month

About the position:

Hold a designated Security Officer role for an ISO 27001 certified company, and use the standing it gives you to keep the management system honest.

SleepScore is ISO 27001 certified and in the maintenance phase of the standard. The management system, policies and risk register are in place and working. The programmes underneath them sit at varying maturity, and that is where most of the interesting work is.

We are looking for an Information Security Officer to be formally named in our ISMS and to take on most of the day-to-day running of the management system. The designation is deliberate. It gives you standing to make calls in your own right rather than borrowing someone else’s authority every time, which matters at two days a week, when you cannot wait for a meeting to move something forward.

You report to the Director of Engineering, who owns the ISMS day to day.

It is not a clean handover. Engineering leadership stays involved and will keep carrying some of this work, so you need to be able to pick up any part of it, and the split will flex with what is in front of us. What you manage, you manage properly: bringing proposals rather than questions, forming a view we can agree, then running it. Ultimate responsibility to senior management stays with us, as the standard requires.

A substantial part of this role is raising capability rather than sustaining it. Asset and endpoint management, access management, vulnerability management, business continuity and incident response, training and exercises, and the improvement programme itself are examples of areas that work today but are less mature than we want them, and they are not the only ones. You would assess where each stands, propose where it should get to, and then implement that: designing the process, building the tooling or configuration behind it, and embedding it with the team that runs it day to day.

Join a fast-growing team on a mission to help millions around the world get a better night’s sleep by revolutionizing the health tech space through innovative sleep solutions.

You’ll Get To:

What You’d Manage:

  • Audit readiness:internal audits and external surveillance. Finding the findings before the auditor does, and closing them with evidence.
  • ISMS governance:the operating rhythm, covering internal audit scheduling, management review inputs, the roles register, and keeping the Statement of Applicability truthful.
  • Risk register:honest, current and defensible, with treatment plans that actually move.
  • Third-party and vendor security:assessments, the supplier register, and a real existing backlog to clear.
  • Vulnerability follow-through:findings tracked to remediation against agreed SLAs, with the numbers reported honestly.
  • Access and asset reviews:periodic, evidenced, across both sites, including portable media.
  • Policies and procedures:current, reviewed on cycle, gaps drafted and proposed.
  • Privacy and data protection:retention, processor inventories, and verifying deletion actually happens in connected systems.
  • Continuity and incident response:keeping the plans real rather than notional, by running tabletop exercises, closing what they expose, and improving both.
  • Training and awareness:managing the programme end to end, covering mandatory and role-specific training, completion tracking and follow-up, and the exercise calendar.
  • The improvement programme:running the improvements register as a live pipeline of work, not a log.

How Authority Works:

  • You are named in the documentation:the ISMS roles register, the RACI and management review records. An auditor will read those and expect them to match what you actually do, so the designation comes with visibility, not just a title.
  • You get a direct line to leadership:clause 5.3 requires that someone be assigned responsibility for reporting on ISMS performance to top management. That responsibility would be yours. It means you can escalate a finding over the head of anyone who would rather it stayed quiet.
  • What it does not mean:accountability under clause 5.1 sits with top management and is not delegable. Risk acceptance stays with risk owners and leadership. The designation buys you day-to-day authority, not the final signature.
  • Most of it becomes yours, but the split flexes:some areas will be clearly yours, some clearly theirs, and some will move depending on load and what an audit cycle throws up. We are not drawing a fixed boundary and pretending it will hold.
  • Breadth over depth in one corner:because the split flexes, you need to be able to cover any of it, not to be the specialist in one area while the rest waits.
  • Autonomy grows with confidence:early on, expect to work decisions through us while a shared view of how you work settles. More moves to your own judgement as it does.
  • Some things always come back to us:risk acceptance, policy changes, exceptions, anything with budget attached, and anything that commits another team’s capacity. That is where the standard puts them.
  • You can assign remediation:placing work with the engineering team that owns a system, and holding it to a date, is part of the job rather than something you need permission for each time.

What You’ll Bring:

  • Five or more years in information security with direct ISMS responsibility, not just participation in someone else’s audit.
  • Fluency in the standard:clauses, controls, and what evidence actually satisfies them. You should be comfortable being the person in the room who knows.
  • Willingness to be formally designated in our ISMS, and to be present and answerable during audits.
  • Judgement:you can look at a control gap, weigh it, and arrive with a recommendation.
  • Track record of building or materially improving security programmes: asset, access, vulnerability, continuity, incident response or training, rather than only operating ones somebody else designed.
  • Comfort assigning work to engineering teams you do not manage, and following it through.
  • Genuine autonomy:two days a week leaves no room for close supervision. Be ready to describe decisions you made and carried, not tasks you completed.
  • Writing that lands:proposals, register entries, management-review material.

We’re Even More Excited If You Have:

  • ISO 27001 Lead Auditor or Lead Implementer:a natural fit for a designated role.
  • Experience through a full certification or recertification cycle.
  • Azure, Microsoft Intune, Jira, Azure DevOps.
  • GDPR and data protection practice.
  • CISM or CISSP.

What This Role Is Not:

  • Not a Data Protection Officer. That is a distinct statutory role under GDPR with its own legal protections, and it is not what we are filling.
  • Not a CISO. Strategy, budget and board-facing reporting stay with engineering leadership.
  • Not a people-management role. You would manage the system, not a team.
  • Not advisory. You are expected to be in the tooling, closing items.
  • Not an unsupported role. Engineering leadership stays close to the ISMS rather than handing it over and stepping away.
  • Not a caretaker role. Keeping things as they are is not the brief; improving them is.

Thrive at SleepScore Because You Are Joining:

  • A technology-based company with a strong mission and vision for the future.
  • We understand that bringing new ideas and innovative technology is mission critical. At SleepScore, we encourage our team to learn something new and expand their creativity that will accelerate their careers.
  • A culture that is kind, open and accepting. It’s a place where people can embrace what makes them unique and the mix of cultural backgrounds and varying interests cultivates diverse thought and perspectives.
  • A role treated as part of the team rather than as an outside supplier. You would be in the tooling, in the conversations, and trusted with real decisions. We offer competitive compensation, and for employed team members, health and wellness benefits programs that are comprehensive and meet the needs of our team.
  • SleepScore recognizes that the ways we work and the workplace itself has shifted. We innovate in a workplace that optimizes a combination of virtual and in-person interactions to maximize collaboration and nurture our culture. This role is remote or hybrid, with the working days arranged to suit both sides.

To apply: Click here to begin our online application.

About SleepScore Inc:

SleepScore Inc is a world-renowned leader in sleep science, research, and solutions, dedicated to helping people sleep better so they can live better. Through strategic partnerships with companies committed to providing the best for their customers, we deliver superior sleep solutions that are backed by unrivaled science and data.

SleepScore Inc developed the most advanced sleep technology platform and leverages actionable and personalized sleep insights derived from 650M+ hours of sleep data to empower billions of people to achieve their best sleep, benefiting their physical, mental, and emotional well-being. Learn more at www.sleepscore.com.

SleepScore Inc is proud to be an equal opportunity employer committed to a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, disability, veteran status, or any other basis protected by law.

Locations
Leinster, Ireland
Timezones
Ireland
Experience
5+ years

Categories

Skills