
Tacton Systems AB · Stockholm
About the Role You will be the hands-on security specialist responsible for keeping our internal digital landscape secure — across systems, integrations, cloud...
About the Role
You will be the hands-on security specialist responsible for keeping our internal digital landscape secure — across systems,
integrations, cloud environments, data flows, and our vendor ecosystem. This role reports into the CISO office, directly to the
CISO & Compliance Manager.
You will combine security architecture thinking with practical execution: threat modeling, technical risk assessments, vendor due
diligence, and governance work. You will partner closely with IT, Engineering, and Legal, acting as the internal security expert
stakeholders turn to. You will also play a key role in how we secure our growing use of AI — an area that brings both significant
opportunity and significant risk.
This is a high-impact, cross-functional role for someone energized by the full breadth of security work — from technical
assessments to policy and standards.
What You Will Do
What Will Help You Thrive
Who We're Looking For
You combine technical rigour with genuine people skills — comfortable owning a threat model one day and a policy document the
next. You are pragmatic, hands-on, and motivated by outcomes. You communicate clearly across audiences, thrive with broad
responsibilities, and are proactive about improving both yourself and the way things are done.
What to Expect During the Recruitment Process
Why Tacton?
that’s central to how manufacturers sell
salary level.
consultations and treatments.
you focus on your family without financial stress
About Tacton
Tacton is a global leader in software for manufacturers of complex, highly configurable products. Tacton delivers the
Buyer-Centric Smart Factory, connecting buyer engagement with engineering and order fulfillment through a single source of truth.
By uniting Configure, Price and Quote, Configuration Lifecycle Management, and Configured Order Fulfillment, Tacton helps
manufacturers manage complexity, protect margins, and deliver with confidence across the lifecycle.
With more than 26 years of experience, Tacton supports manufacturers worldwide and is headquartered in Stockholm, Sweden and
Chicago, USA. Learn more at www.tacton.com.
JOIN US TO SHAPE THE FUTURE! Teamtailor is a global Employer Branding and ATS SaaS platform used by over 13,000 companies, 250,000 users, and available in 90 countries worldwide. 🌍 Working at Teamtailor means being part of a dynamic, fast-paced tech company that values impact and responsibility. Our workplace fosters an environment where everyone can contribute meaningfully to the growth of the company. 🎉🥳 Building a diverse team with a wide range of experiences, skills, and backgrounds has always been central to Teamtailor’s mission, and it remains a strength today. We welcome all individuals who share our vision and are committed to contributing to our collective success. Join us in helping companies and people communicate in more meaningful ways to make life-changing decisions together.👫 We are now looking for a Legal Counsel to join our team in Stockholm KEY RESPONSIBILITIES: * Contributing to our business goals by providing the business with proactive, clear, and relevant legal advice. * Reviewing, drafting, and negotiating various types of agreements including SaaS, supplier/vendor, partnership, reseller, data processing and DORA agreements, including providing public procurement RFP support. * Managing the impact of GDPR, EU AI Act and other European and global regulatory frameworks, including impact on product features. * Researching into specific legal topics, for example multi-national regulatory regimes. * Monitoring updates in legislation or directives that may be relevant to our business * Establishing efficient and high-quality workflows (for KM and AI use) based on business needs. WHO ARE YOU? * Qualified lawyer with +3 years of post-qualification experience, ideally in-house or at a technology-focused firm/department. * Fluent in Swedish and English, bonus if you speak French (or other third language). * Eager to learn, researching and compiling information about legal topics. * Able to prioritise a high volume of parallel tasks, ranging from detailed to strategic, without losing quality or composure under commercial pressure. * Able to switch between detailed focus and business overview. * Clear, direct communicator who can explain complex legal issues clearly and relevantly across different parts of the organization (Sales, Marketing, CSM, Product etc). * A true team player, happy pull your weight in a small and supportive team, without constant supervision. WHAT WE OFFER: * Putting your legal skills to practical, impacting use with real responsibility from day one, spanning contract negotiations across 20+ jurisdictions, AI Act and data privacy work that directly shapes how the product is sold globally. * Being part of a close knit, highly appreciated and amazing legal team with real legal ownership. * Professional growth in a fast-growing environment. If this opportunity excites you, we look forward to receiving your application!
Remote (+/- 2hrs from Germany GMT+1). C1 or C2 German Language is essential At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work. Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader. We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital. About the Role We're hiring a Senior Information Security Specialist to strengthen our compliance function as Secfix scales into more frameworks, mid-market customers, and a growing compliance team. This role sits at the intersection of compliance delivery, content, and team support. You'll own the compliance knowledge that lives inside our platform, mentor our junior compliance specialists, support our customer success team, and act as the senior compliance voice for customers, auditors, and product. You'll work closely with our co-founder & CISO and our CS Lead. This is a high-impact role with real influence on how Secfix delivers compliance: both as a service to customers and as content inside our app. What You'll Do: You will own one of the most important pillars of Secfix: the quality and breadth of our compliance offering. We don't (and can't afford to) micro-manage. We've built strong foundations and will give you full context on what works. You can test new approaches, but at the end of the day, you have full ownership of how you deliver results (with a strong support network from within and outside the company). You will: * Own and drive the compliance roadmap inside the Secfix platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand) * Implement ISO 27001 and adjacent frameworks end-to-end for customers * Mentor and upskill the compliance team: sharing expertise, reviewing work, and helping drive consistency in audits and customer deliverables * Conduct internal audits directly for strategic and complex customers, and review the internal audits performed by junior team members to drive quality and consistency * Act as a compliance partner to CSMs and sales reps: fast, reliable support for customer questions, and joining customer calls when deep expertise is needed * Own the quality of compliance content in the platform (including creating policies, evidence templates, Compliance enable playbooks for our CSMs, security awareness trainings and more) * Close framework gaps and incorporate auditor feedback into both team practice and platform improvements * Partner with product and engineering to translate compliance gaps into structured product work * Collaborate closely with CS, Product, and Founders to align compliance, customer, and roadmap priorities * Deepen relationships with our existing certification partners and train auditors on the Secfix platform so they can confidently use it during customer audits To be qualified for this role, you must have the following: * German (C1/C2) and English (fluent) is a must for this role * 5+ years of hands‑on information security and GRC experience in B2B SaaS * Led 3+ successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company * Hands on experience with a GRC platform like Secfix, or similar GRC platforms * Cloud infrastructure readiness across AWS, Azure, and GCP; experience with posture analysis and remediation planning * Strong project management skills with the ability to break down ambiguous initiatives into concrete deliverables, prioritizes ruthlessly, and ships * Excellent written communication, especially in producing clear, precise compliance content for diverse audiences (auditors, founders, engineers) * Strong ownership mindset: operates as a senior individual contributor without waiting for direction Bonus: * Experience implementing one or two additional compliance frameworks (e.g. SOC 2, GDPR, NIS 2, etc.) * Experience mentoring or coaching colleagues in a compliance, audit, or GRC context * Experience in a startup environment is a plus What we offer * Remote Work: 100% remote work with a virtual office in Gather. * Competitive Salary: Industry-competitive local salaries. We pay local rates that are at or above the market. We share this philosophy with GitLab. * Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success. * Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors. * Development Budget: €1,000 annual personal development budget. * Home office Budget: Home office budget and access to co-working spaces. * Holidays: 26 days holiday + local public holidays. * Health Insurance: Comprehensive health coverage. * Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Milan!). * Company Events: Company-wide events to build relationships and have some fun! * Tech Equipment: Latest tech equipment (MacBook, monitors, headphones). Interview Process: * 20-30 min - Intro call with Talent team * Take-home Assessment * 1.5hr Assessment review and interview with our CS Lead and CEO * 45 min - Final Founder Interview with Co-Founders (CTO & CISO) Please note: We are an equal-opportunity employer and remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here.
About the team At Doordash, Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our multi-sided marketplace of consumers, merchants, Dashers, and partners. Security, privacy, and compliance are foundational to earning and maintaining trust as we expand globally. The Governance, Risk, and Compliance team partners across Security, Engineering, Legal, Privacy, Product, IT, Procurement, Internal Audit, and business teams to help DoorDash understand its compliance obligations, manage security and privacy risk, and build durable programs that scale with the company. About the role We’re looking for a Senior Information Security Specialist to help mature DoorDash’s global security and privacy compliance risk program. You will create and operationalise a global compliance change process framework that helps DoorDash detect changes in our compliance landscape, assess impact, identify gaps, and drive accountable remediation across teams. This is a senior individual contributor role for someone who has managed global compliance frameworks and security/privacy compliance programs in a technology company. You will bring structure to ambiguous compliance changes, translate requirements into actionable control expectations, facilitate risk workshops, and help leadership understand compliance risk in clear business terms. What you'll be doing * Design and operate a global compliance change management framework to identify new or changing security, privacy, regulatory, contractual and framework obligations across DoorDash’s markets and products. * Maintain a structured view of DoorDash’s compliance landscape, including obligation inventories, control mappings, ownership models, risk decisions and remediation status. * Lead compliance-impact assessments for new regulations, framework updates, product launches, market expansions, vendor changes and major technology initiatives. * Facilitate compliance risk workshops with Engineering, Legal, Privacy, Product, Procurement, IT, Internal Audit and business stakeholders. * Translate complex regulatory, security, and privacy requirements into practical control expectations and specifications that technical and non-technical teams can implement. * Identify control gaps, assess residual risk, define remediation plans and track progress through closure with clear accountability. * Partner with control owners to improve evidence quality, audit readiness, and sustainable operation of controls across global compliance frameworks. * Help mature DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications. * Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements. * Promote a risk-based, pragmatic compliance culture that enables DoorDash teams to move quickly while protecting customers, partners, employees and the business. Requirements * You have 6+ years of experience in GRC, security compliance, technology risk, privacy compliance, IT audit, or a related field, preferably in a global technology, marketplace, SaaS, fintech or payments environment. * You have managed or materially contributed to a global compliance framework or security/privacy compliance management program. * You have built, operated or significantly improved a compliance change management, obligations management, control mapping or regulatory-change process. * You have hands-on experience facilitating risk assessments, compliance risk workshops, control self-assessments and remediation planning with cross-functional stakeholders. * You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements. * You understand how security and privacy controls operate in modern technology environments, including cloud infrastructure, identity and access management, SDLC, incident response, vendor risk, data governance and business continuity. * You can translate legal, regulatory and framework requirements into clear, tangible control specifications to engineers and explain technical risk in business terms. * You communicate clearly, write with precision and can create high-quality policies, procedures, risk memos, control narratives, executive updates, and decision records. * You are comfortable navigating ambiguity, balancing multiple priorities and driving outcomes without relying on constant direction. * You build trust with technical and non-technical stakeholders and can facilitate conversations rather than dictate outcomes. Why Doordash, Deliveroo and Wolt Our mission is to transform the way you shop and eat, bringing the neighbourhood to your door by connecting consumers, restaurants, shops and riders. We are transforming the way the world eats and shops by making access to food and products more convenient and enjoyable. We give people the opportunity to buy what they want, as they want it, when and where they want it. We are a technology-driven company at the forefront of the most rapidly expanding industry in the world. We are still a small team, making a very large impact, looking to answer some of the most interesting questions out there. We move fast, value autonomy and ownership, and we are always looking for new ideas. Workplace & Benefits At Doordash we know that people are the heart of the business and we prioritise their welfare. Benefits differ by country, but we offer many benefits in areas including healthcare, well-being, parental leave, pensions, and generous annual leave allowances, including time off to support a charitable cause of your choice. Benefits are country-specific, please ask your recruiter for more information. Diversity At Doordash, we believe a great workplace is one that represents the world we live in and how beautifully diverse it can be. That means we have no judgement when it comes to any one of the things that make you who you are - your gender, race, sexuality, religion or a secret aversion to coriander. All you need is a passion for (most) food and a desire to be part of one of the fastest-growing businesses in a rapidly growing industry. We are committed to diversity, equity and inclusion in all aspects of our hiring process. We recognise that some candidates may require adjustments to apply for a position or fairly participate in the interview process. If you require any adjustments, please don't hesitate to let us know. We will make every effort to provide the necessary adjustments to ensure you have an equitable opportunity to succeed.