Security and compliance at TechWolf is a small, multidisciplinary team with an unusually central seat. We are not an isolated centre of expertise that the business consults occasionally: we sit inside day-to-day operations, and we pick up problems because they need solving, not because they fit neatly inside our remit. We are also on the critical path of the company's growth: every deal TechWolf signs clears a security review on our side, and for our largest customers that review is one of the harder parts of the sale. Our customers are large regulated enterprises, among them global banks and insurers, and their security teams assess us at the depth of a SOC 2 audit, on-site visits included. Today two people carry that work, against a business that has roughly doubled in a year. You are the third: a senior individual contributor who owns governance, risk and compliance programmes end to end, and who sits in front of those customers' security teams as the named owner. You decide when something escalates, and you are trusted to hold the room. You'll report to our Security Officer, who sets our security strategy and stays hands-on alongside you; your responsibility is to own and run the programmes that make that strategy real. On the hard calls, you define the solution rather than surface the problem, and the Security Officer signs off. How we work matters as much as what we own. This is a fast-paced, hands-on environment, and TechWolf is AI-first. AI tooling is a large part of how two people absorbed a doubling in deal volume without slowing deals down. We expect you to work the same way: hands on the work rather than directing it, self-sufficient, and building your own leverage. What you'll do Be the reason large deals clear security. You own security due diligence on our large enterprise deals end to end: the questionnaires, the custom due-diligence requests, the customer risk assessments, the evidence packages, the on-site visits, and every piece of follow-up between the first architecture call and signature. You negotiate the security schedules in contracts and data processing agreements yourself, finding positions that protect TechWolf without costing us the deal. This includes working with our internal AEs to align before sitting in front of the customer. Build the programme, not just work the queue. You decide how we tier what comes in, what response times we hold ourselves to, and what gets automated next. You design how we assess and tier our own vendors, and the criteria that decide when a third-party risk gets escalated. What you build here is what the function runs on as we scale. Run our certifications, including the ISO 42001 our AI Management System. In addition, you run ISO 27001 and SOC 2 end to end, working with the security and engineering teams. You own the auditor relationships at programme level, map controls across the three standards so we evidence something once rather than three separate times, and drive fixes from the root cause instead of closing findings one by one. Keep us ahead of regulation rather than behind it. You steer our GDPR posture, advise on the implementation of requirements for high-risk AI systems within the EU AI Act while most companies are still reading it, and advise the business on cross-border data transfers. Make risk a business conversation. You set the methodology, run risk workshops with senior stakeholders, and put risk to leadership in terms they can act on. When a risk acceptance drifts outside our appetite, you are the one who says so. Design governance that holds as we scale. You architect the ISMS documentation hierarchy, own the management-review cycle, and surface the governance gaps that quietly create operational risk before they surface themselves. Shape where security goes next. You contribute to the security and compliance roadmap, flag the regulation coming over the horizon, arm presales to answer security questions without you, and coach more junior colleagues on methodology. Own the follow-through when something goes wrong. You run the governance and coordination around incidents, the part that decides whether we actually learn from them. Not hands-on detection or response engineering. Who you are: You have owned enterprise security assurance for a client base with high expectations; running due-diligence responses, evidence packages and on-site assessments through to signed contracts, and you've negotiated security and data-protection terms that held up under scrutiny. At least four years of relevant experience, and senior in practice. You have carried ISO 27001 or SOC 2 through a full audit cycle as the owner, not as a contributor. You have dealt with auditors directly, and you know where an evidence trail breaks down before an auditor finds it. You are fluent in privacy and data protection, covering GDPR, the EU AI Act and cross-border transfer mechanisms. You can give the business a clear answer under time pressure, and you recognise when a question needs a lawyer rather than an opinion. You own risk and governance rather than administer them: you set methodology, put risk in terms leadership acts on, architect ISMS documentation that survives an audit, and hold the line when a risk acceptance drifts outside appetite, including when the person pushing is senior to you. You are an outstanding written and verbal communicator with external stakeholders, with the diplomacy to reach answers that work for both the customer and TechWolf, and you are comfortable operating amid ambiguity. You are comfortable being a generalist. Plenty of what lands on this team is not a neat fit for it, and you take it on anyway, working out what good looks like in a domain you did not start the week as an expert in. You are self-sufficient and you use AI as a matter of course, not as a novelty. You would rather automate a recurring problem than staff it. You are based in Belgium and can work from our Ghent office at least three days a week. What’s in it for you? 📊 Fair & competitive salaries – we benchmark our salaries yearly and pay above the market median in every role and location. 📈 Equity - everyone is an owner at TechWolf and can share in our success! 👨👩👧👦 Hybrid working and flexible hours - make your work schedule work for you 🚗 Mobility your way - choose between a company car or a mobility budget 🌱 Health insurance & retirement savings 🏝️ Work from abroad 3 weeks each year 🚅 Travel to London occasionally and work from our local office 💻 Learning and development opportunities 🚶♀️ Walking culture - who doesn’t love brainstorming or connecting with colleagues while taking a walk around the office? 🎉 Fun team buildings, social & sports activities Sounds like your cup of tea? There's more! TechWolf is on a mission to make work better and fairer for millions of people by powering the shift from jobs to skills as a framework to model talent. Our enterprise software uses AI to provide the skill data needed to power that transformation. We provide a unique opportunity to work with an all-star team and cutting-edge product, in a purpose-driven company that aims to empower people to thrive at work. TechWolf is growing fast and you’ll join a high-performing international team with a unicorn dream. Ready to help us build a rocket ship? Follow us to keep up with our latest updates on: LinkedIn | Instagram | Website
Senior Information Security Officer
Luminus
Chief Information Security Officer
Carrieres Fednot
Chief Information Security Officer
Careersnl Fednot
Chief Information Security Officer
Fednot
Deputy Project Officer (NATO Infrastructure Programme) for NATO with security clearance
WLG
Project Support Officer (Infrastructure Programme) for NATO with security clearance
WLG