Similar Jobs
See allInformation Security Consultant
SITS Group
Germany
ISO 27001
Risk Analysis
IT Security
Information Security Analyst
Didomi
Europe
ISO 27001
GRC
Vulnerability Management
Senior Manager, Infosec, IT & Compliance
Practice Better
Canada
HIPAA
GDPR
SOC 2
ISO 27001 Internal Auditor
Partner Company
Europe
ISO 27001
Internal Audit
Security Compliance
Senior GRC Analyst
Garner
US
GRC
IT Audit
SOC 2
Your mission:
- Take full ownership of information security, compliance, and IT governance at Cosuno.
- Build and run the ISMS, lead ISO 27001 certification, and become the face of security to enterprise customers.
- Act as a senior individual contributor with end-to-end ownership, backed by Engineering and the CTO.
What you'll own:
- ISMS and ISO 27001: Lead certification from gap analysis through audit, manage risk, policies, and controls.
- Customer trust and audits: Own security questionnaires, RFIs, and represent Cosuno in customer audits.
- Data protection (GDPR): Handle DPAs, subprocessor management, vendor reviews, and DSARs.
- IT governance and access management: Oversee identity and access management via JumpCloud, device hardening, and security awareness.
How we work:
- High autonomy, high impact: You own these domains end to end with direct sponsorship from the CTO.
- Compliance as a product: Security and compliance are treated as a genuine part of building trust, not a checkbox.
- AI-first by default: Use AI tools like Claude Code to draft policies, answer questionnaires, and automate tasks.
Cosuno
Cosuno is a fast-growing tech startup revolutionizing the construction industry through a digital platform for tenders and procurement, using AI to analyze price data and create efficient bids. They are a lean, 100-person team with a culture of high autonomy, pragmatism, and AI-first thinking, offering a remote-first work environment.