Frontify is the brand platform behind some of the world's leading organizations, including Microsoft, Telefónica, Bosch, Mercedes-Benz, and Kia. We help every team bring brands to life — with governance in one place, seamless workflows across the tools people already use, and a foundation that's ready for AI. We're driven by collaboration, curiosity, and the belief that great work can happen anywhere. What began in St. Gallen has grown to London, New York, and beyond. Wherever you join us, you'll take ownership from day one, shape work that reaches global brands, and help redefine how brands work in the age of AI. What you'll shape Trust is what enables the world's leading brands to build on Frontify. Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify. Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management. A key focus of the role is driving the next stage of our security governance maturity. Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits. You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness. This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value. What you'll do You'll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success. You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective and audit-ready. You'll help transform compliance from a point-in-time activity into a continuous process by introducing automation and AI into our Vanta-based GRC program. This includes improving evidence collection, control monitoring, and access review processes. You'll design and improve AI-enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight. You'll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher-risk vendors receive appropriate human review. You'll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training. Comfortable with a hybrid work model, spending 1 day per week in our London office. What you bring You have 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus. You're hands-on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort. You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements. You're genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters. You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work. A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus. You speak English fluently. German is a plus. What we offer Private health benefits and health cash plan Pension scheme: 5% matched A minimum of 25 days of annual leave per year Paid educational and wellbeing days off Wellbeing, learning and development, and commuter allowance Home office setup budget Weekly free office lunch Localized benefits Workation: Work from inspiring locations around the world (45 days annually) Invite to our summer company meet-up We understand that every candidate's experience is different. If you're interested in this role but don't tick all the boxes, we still encourage you to apply. A few things to know Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future. We're committed to providing a fair and accessible recruitment process. If you have a disability and require reasonable adjustments at any stage, please speak with your Talent Partner. Any information you share will remain confidential. This description outlines the primary duties of the role, which may evolve in response to business needs and company growth. We're looking for someone comfortable with change and excited to contribute to a dynamic environment. If this sounds like you, join us and help shape the future of branding. We may conduct preliminary checks for successful candidates, depending on the role and in line with local laws. We'll share all relevant details during the interview process. We use third-party artificial intelligence (AI) tools to record and transcribe interviews and to help our team review candidate profiles. These tools don’t replace human judgment, and all evaluations and final hiring decisions are made by our recruitment team. Please see our Privacy Notice for more information about how we process your data and how to exercise your privacy rights.
Information Security Governance Specialist
Frontify
Senior Data Governance Specialist
Lonza
Sales Reporting & Governance Specialist
Honda
Governance, Risk & Compliance Specialist
Soprasteria Uk
Data Protection Governance Specialist (FTC)
Collinson
Responsible AI Specialist (Governance, Ethics & Compliance)
Talan