Security Officer
Scrive
We Care, We Challenge, We Commit, We Collaborate Join Scrive and be part of an international, fast-growing company headquartered in Stockholm, Sweden. Collaborate with smart, caring, and driven colleagues across Europe as we shape the Scrive story. 🚀 The opportunity We are currently looking for a Security Officer to join our team and play a key role in supporting the implementation and maintenance of Scrive's Information Security Management System (ISMS) and ensuring compliance with ISO 27001, SOC 2 Type 2 and other security standards and regulatory frameworks. This role is an exciting opportunity to act as a liaison between the Security Office and operational teams, helping to translate security policies into practical controls while monitoring compliance across the organization. 📍The role will preferably be based in Stockholm, but we're also open for candidates working from one of our Hubs (Copenhagen, Oslo, Berlin, Amsterdam or Brno). You will report to the CISO (Chief Information Security Officer) who is working remotely from Latvia. As a Security Officer you will:
- Implement and monitor controls – Build automations to verify that security controls are continuously implemented and operational according to security best practices.
- Collaborate with engineering teams to build tooling for control monitoring and security review automations.
- Support policy and compliance – Assist in maintaining and updating security policies, procedures, and guidelines, while supporting internal and external audits.
- Manage risks and incidents – Support the risk assessment process, help maintain the risk register, and assist in incident response coordination and documentation.
- Drive awareness and communication – Support security awareness training programs and create clear security guidance documentation for our employees.
- Relevant Experience within information security, compliance, or an operational security role where you have worked independently within an established framework. Technical capabilities to work with log analysis and handling tools, AI based automations and similar technologies. Technical capabilities in configuring and managing infrastructure and assure its security configurations.
- Proven knowledge of SOC 2 Type 2, ISO 27001 clauses, Annex A controls (focus on more technical controls here), and ISMS structures, especially on technical implementation and monitoring of this.
- Stakeholder Communication – The ability to explain complex security requirements in plain language and provide helpful guidance without causing friction.
- Analytical Thinking & Technical Aptitude – A mindset for identifying gaps in documentation or control design, combined with a high-level understanding of system architecture.
- Regulatory Awareness – Familiarity with eIDAS / TSP (Trust Service Provider) requirements, GDPR, CRA and other regulatory requirements within EU and their technical implementations.
- Project Coordination – Experience coordinating small workstreams and tracking action items using tools like Jira.