Information Security Officer

Super · All Locations · Engineering

Posted 2026-10-01

Apply for this role →

About the Role-

Super is creating a new Information Security Officer position within the Cybersecurity team to own our company-wide security governance, policy and compliance agenda. This is a governance and compliance role, not a technical one: it owns our security policies, drives security awareness and training, and ensures every team across the organisation knows what they must do to be compliant and follows through until it's done.

What the role involves

Policies & governance

Own and maintain the company-wide information security policy framework, ensuring it stays current, coherent and aligned with the business, and act as the internal authority on relevant standards and regulations (e.g. ISO 27001, GDPR)

Update and drive the security compliance strategy, including operation of the GRC platform, ensuring policies are clear and effectively communicated across the organisation

Training & awareness

Design and deliver security awareness and training programmes, tailored to different teams and tribes, so people understand their compliance obligations and how to meet them

Driving & verifying compliance

Drive compliance adoption across all business units, validating that teams understand and complete the steps required, and establish escalations so gaps are surfaced and closed proactively

Track and report on policy exceptions and remediation progress

Data protection & PII

Own the PII compliance plan, including the programme to deprecate unencrypted PII, and produce reporting escalated to the Board and Risk Committee where necessary

Audit & reporting

Coordinate with external auditors and manage evidence collection for audits and certifications

Provide regular compliance reporting to leadership, the Board and the Risk Committee

What we are looking for

Proven experience in information security governance, risk and compliance (GRC), ideally within a regulated, multi-market environment

Deep, practical knowledge of ISO 27001, GDPR and related security and data-protection standards

Experience owning security policy frameworks and running security awareness and training programmes

Hands-on experience operating a GRC platform and driving compliance across many teams

Track record of coordinating internal and external audits and managing audit evidence

Excellent stakeholder-management and communication skills, with the ability to influence and drive compliance without direct authority

Experience reporting to senior leadership, boards or risk committees

Nice to have

Relevant certifications (e.g. CISM, CISA, ISO 27001 Lead Implementer/Auditor, CISSP)

Experience with data-protection and PII programmes

Exposure to fast-scaling technology, gaming or fintech organisations

What we offer

Medical / Health Insurance

Open Annual Leave

Employee Assistance Programme

Training & Learning Development

Apply for this role →

← Back to all jobs