Information Security Manager
Sleep.aiSalary Range: €49,200.00 To €55,200.00 Annually Position: Information Security Manager (part time employee) Reports to : Director of Engineering - DevOps, IT, Security and Privacy Location: Dublin, Ireland. Hybrid, must be able to make occasional trips to our Dublin office Status: Part-time employee, initially 20 hours a week with the potential for extension based on business needs and performance Salary Range: €4100 – €4600/month About the position: Manage our information security management system. Decide, propose, delegate, and keep us audit-ready without being asked. SleepScore is ISO 27001 certified and in the maintenance phase of the standard. The management system, policies and risk register are in place and working. The programmes underneath them are at varying stages of maturity, and that is where most of the interesting work is. We need someone to manage the operational reality: to see where the risk actually sits, decide what to do, and make it happen, either directly or by placing the work with the team that should carry it. You report to the Director of Engineering, who owns the ISMS day to day. It is not a clean handover. Engineering leadership stays involved and will keep carrying some of this work, so you need to be able to pick up any part of it, and the split will flex with what is in front of us. What you manage, you manage properly: bringing proposals rather than questions, forming a view we can agree, then running it. Ultimate responsibility to senior management stays with us, as the standard requires. A substantial part of this role is raising capability rather than sustaining it. Asset and endpoint management, access management, vulnerability management, business continuity and incident response, training and exercises, and the improvement programme itself are examples of areas that work today but are less mature than we want them, and they are not the only ones. You would assess where each stands, propose where it should get to, and then implement that: designing the process, building the tooling or configuration behind it, and embedding it with the team that runs it day to day. Join a fast-growing team on a mission to help millions around the world get a better night’s sleep by revolutionizing the health tech space through innovative sleep solutions. You’ll Get To: What You’d Manage: Audit readiness: internal audits and external surveillance. Finding the findings before the auditor does, and closing them with evidence. Risk register: honest, current and defensible, with treatment plans that actually move. Third-party and vendor security: assessments, the supplier register, and a real existing backlog to clear. Vulnerability follow-through: findings tracked to remediation against agreed SLAs, with the numbers reported honestly. Access and asset reviews: periodic, evidenced, across both sites, including portable media. Policies and procedures: current, reviewed on cycle, gaps drafted and proposed. Privacy and data protection: retention, processor inventories, and verifying deletion actually happens in connected systems. Continuity and incident response: keeping the plans real rather than notional, by running tabletop exercises, closing what they expose, and improving both. Training and awareness: managing the programme end to end, covering mandatory and role-specific training, completion tracking and follow-up, and the exercise calendar. The improvement programme: running the improvements register as a live pipeline of work, not a log. How Authority Works: Most of it becomes yours, but the split flexes: some areas will be clearly yours, some clearly theirs, and some will move depending on load and what an audit cycle throws up. We are not drawing a fixed boundary and pretending it will hold. Breadth over depth in one corner: because the split flexes, you need to be able to cover any of it, not to be the specialist in one area while the rest waits. Short escalation: the people who can decide are close by. You will not wait a fortnight for an answer. Autonomy grows with confidence: early on, expect to work decisions through us while a shared view of how you work settles. More moves to your own judgement as it does. Some things always come back to us: risk acceptance, policy changes, exceptions, anything with budget attached, and anything that commits another team’s capacity. That is where the standard puts them. You can assign remediation: placing work with the engineering team that owns a system, and holding it to a date, is part of the job rather than something you need permission for each time. What You’ll Bring: Five or more years in information security, with real ISO 27001 responsibility, not just participation in someone else’s audit. Judgement: you can look at a control gap, weigh it, and arrive with a recommendation. Track record of building or materially improving security programmes: asset, access, vulnerability, continuity, incident response or training, rather than only operating ones somebody else designed. Comfort assigning work to engineering teams you do not manage, and following it through. Genuine autonomy: two days a week leaves no room for close supervision. Be ready to describe decisions you made and carried, not tasks you completed. Writing that lands: proposals, register entries, management-review material. We’re Even More Excited If You Have: Experience through a full certification or recertification cycle. Azure, Microsoft Intune, Jira, Azure DevOps. GDPR and data protection practice. CISM, CISSP, or ISO 27001 Lead Implementer / Lead Auditor. Willingness to be named a Security Officer under our ISMS. What This Role Is Not: Not a CISO. Strategy, budget and board-facing reporting stay with engineering leadership. Not a people-management role. You would manage the system, not a team. Not advisory. You are expected to be in the tooling, closing items. Not an unsupported role. Engineering leadership stays close to the ISMS rather than handing it over and stepping away. Not a caretaker role. Keeping things as they are is not the brief; improving them is. Thrive at SleepScore Because You Are Joining: A technology-based company with a strong mission and vision for the future. We understand that bringing new ideas and innovative technology is mission critical. At SleepScore, we encourage our team to learn something new and expand their creativity that will accelerate their careers. A culture that is kind, open and accepting. It’s a place where people can embrace what makes them unique and the mix of cultural backgrounds and varying interests cultivates diverse thought and perspectives. A role treated as part of the team rather than as an outside supplier. You would be in the tooling, in the conversations, and trusted with real decisions. We offer competitive compensation, and for employed team members, health and wellness benefits programs that are comprehensive and meet the needs of our team. SleepScore recognizes that the ways we work and the workplace itself has shifted. We innovate in a workplace that optimizes a combination of virtual and in-person interactions to maximize collaboration and nurture our culture. This role is remote or hybrid, with the working days arranged to suit both sides. To apply: Click here to begin our online application. About SleepScore Inc: SleepScore Inc is a world-renowned leader in sleep science, research, and solutions, dedicated to helping people sleep better so they can live better. Through strategic partnerships with companies committed to providing the best for their customers, we deliver superior sleep solutions that are backed by unrivaled science and data. SleepScore Inc developed the most advanced sleep technology platform and leverages actionable and personalized sleep insights derived from 650M+ hours of sleep data to empower billions of people to achieve their best sleep, benefiting their physical, mental, and emotional well-being. Learn more at www.sleepscore.com . SleepScore Inc is proud to be an equal opportunity employer committed to a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, disability, veteran status, or any other basis protected by law.