While we welcome applications from everywhere, please note that at this stage we are prioritizing candidates who are already based
in Stockholm and eligible to work in Sweden without visa sponsorship.
Video has quickly become one of the most powerful ways for brands to engage, inspire, and convert consumers.
At Bambuser, we’re helping some of the world’s most recognized brands transform how they sell online through live shopping,
shoppable video, and interactive commerce experiences. Brands including LVMH, Audi, Sephora, Decathlon, and Sonos use our platform
to create richer and more engaging customer experiences.
As a global B2B SaaS company working with enterprise customers, trust matters at every stage of our business. Customers need to
know that their data is handled responsibly. Teams need clear and practical guidance. Auditors need evidence that our controls
work. As technology and regulation evolve – particularly around AI – we intend to maintain our position at the forefront.
That’s where you come in.
Bambuser already has strong security and compliance foundations, including an ISO 27001-certified ISMS. Your challenge will be to
build on them as our business, customer expectations, and the regulatory landscape continue to evolve.
You’ll own our ISMS, data privacy and compliance frameworks, and operational risk registers. Day to day, you’ll support the
business in meeting its regulatory obligations, keep our policies relevant and current, and make sure we walk into every audit
ready rather than scrambling.
We’re a fast-moving scale-up, so we need you to think the way we all try to think: what can be automated, templated, or scheduled
instead of done by hand again? If you find yourself doing the same manual task twice, we want you to build a system that makes
sure you never do it a third time—and ideally, nobody else has to either.
Own and maintain the ISO 27001 governance framework, driving continuous improvement of the ISMS to sail through surveillance
audits and recertification. Prepare for and run internal and external audits end to end: scoping, evidence collection,
stakeholder coordination, and findings remediation. Build playbooks and control documentation that hold up under scrutiny, not
just look good on paper.
Own the full ISMS library. Review what exists for relevance, overlap, and gaps, and right-size it to match the actual risk
profile, not more, not less. Drive adoption across the org through clear communication and practical enablement so policies get
followed in practice.
Serve as the go-to contact for enterprise customer security reviews, owning the information security sections of RFPs and
keeping the Trust Center current. Lead the rollout of the RFP AI tool. On the procurement side, act as the information security
reviewer for new tools and vendors, assessing data handling, access, and integration risk before adoption, AI tools included.
Track the regulatory landscape across all markets: GDPR and international privacy law, information security standards,
sector-specific rules. Turn that into concrete controls and clear internal ownership. Keep an eye on where AI regulation (like
the EU AI Act) is heading, and proactively start building the groundwork, risk classification and usage guidelines.
Coordinate and support penetration testing engagements: scoping with vendors, arranging internal access, chasing findings
through to remediation. Own the security training program end to end, designing and delivering onboarding and recurring
awareness training, and keeping it fresh as threats and regulations shift.
Lead adoption of Bambuser's new operating model, making sure people understand and own their part in it. Turn security
workflows that currently live in someone's head into documented, scalable processes. Wherever there's a recurring task,
evidence collection, training reminders, audit scheduling, the default should be to automate it rather than track it manually.
Oversee GDPR and international privacy compliance across every market, looping in external counsel when needed. Run the Senior
Management risk assessment process, keeping the corporate Risk Register current and tied to what the business actually cares
about.
fast-growing tech company.
penetration testing programs is a plus.
customers, and for a room full of people at a training session.
automation, reminders, scheduling tools, and AI-assisted drafting to cut busywork, both your own and everyone else's, so time
goes toward the work that actually needs a human.
problems to surface.
You’ll join a focused, hungry team that genuinely enjoys working together and getting things done. We move quickly, help one
another, and share the same goal – without the silos or distance that can make this kind of role feel thankless elsewhere.
Here, your contribution will be visible, valued, and felt across the company. You’ll help turn ambition into something real by
giving teams the clarity and confidence to move forward.
Here, you'll find the pace and ownership of a scale-up, without the chaos. We have a solid product, an experienced team, and
people who care deeply about the quality of what they build.
Fler lediga tjänster som liknar denna i och runt Stockholm