Auf einen Blick
- Aufgaben: Gestalte die Sicherheitsgovernance mit Automatisierung und KI für kontinuierliche Compliance.
- Unternehmen: Innovatives Unternehmen mit kreativer und inklusiver Kultur.
- Vorteile: 25 Tage Urlaub, flexible Arbeitszeiten, Weiterbildungsmöglichkeiten und Homeoffice-Budget.
- Weitere Informationen: Vibrante Teamkultur mit Slack-Kanälen für alle Interessen.
- Warum dieser Job: Werde Teil eines dynamischen Teams und forme die Zukunft der Sicherheit.
- Qualifikationen: 5+ Jahre Erfahrung in Informationssicherheit und GRC, idealerweise mit SOC 2 oder ISO 27001.
Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.
We're all about helping brands turn ideas into impact.
Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns.
Our people empower thousands of marketers and designers — including teams at Uber, Microsoft, Volkswagen, and Telefónica — to build engaging brands.
With headquarters in St.
Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy.
And we’re on the lookout for new team members to share our vision.
If you’re ready for a brand-new adventure, keep reading!
Your team
With the mission of creating a home where all brands (including our own) are safe, the Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders.
Security, pragmatism and user friendliness are our guiding principles.
Outside of work, we’re gamers, avid bookworms and kickboxers.
Your mission
Trust is what enables the world's leading brands to build on Frontify.
Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify.
Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.
A key focus of the role is driving the next stage of our security governance maturity.
Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits.
You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness.
This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value.
- Your responsibilities
- You'll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.
- You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.
- You'll serve as the subject matter expert during audits and ensure our control environment remains effective and audit‑ready.
- You'll help transform compliance from a point‑in‑time activity into a continuous process by introducing automation and AI into our Vanta‑based GRC program.
This includes improving evidence collection, control monitoring, and access review processes.
- You'll design and improve AI‑enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.
- You'll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher‑risk vendors receive appropriate human review.
- You'll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training.
- Your story
- You're comfortable working in a hybrid format, with the ability to come to our St. Gallen office once per week.
- You have 5+ years of experience in information security governance, GRC, or technology risk within a Saa S or cloud environment.
- You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors.
Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.
- You're hands‑on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.
- You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.
- You're genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.
- You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.
- A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.
- You speak English fluently. German is a plus.
We understand that every candidate’s experience is different. If you’re interested in this role but don’t tick all the boxes, we still encourage you to apply.
Why join us?
- Thrive with the tools and support to shape your future at Frontify.
- Be part of a product that connects brands and people with a human touch.
- Enjoy flexibility, opportunities to grow, and exposure to innovative technologies and ideas.
- Join a vibrant, social team—whether you love animals, yoga, or travel, we’ve got the Slack channels for you!
What we offer
- A minimum of 25 days annual leave per year
- Parental, family care, and bereavement leave
- Daily sickness benefits and accident insurance
- Paid educational and wellbeing days off Wellbeing, learning and development, and commuter allowance
- Home office setup budget
- Pension fund: contributions paid 60% by us and 40% by you
- Access to exclusive perks and discounts from hundreds of top brands
- Workation: Work from inspiring locations around the world for up to 45 days per year!
- Invite to our summer company meet‑up
- Important to us
Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future.
We’re committed to an inclusive hiring experience.
If you need any support or adjustments during the recruitment process, please let your Talent Partner know when scheduling.
Any information shared will be treated confidentially.
Next steps
If there’s a fit, you’ll meet our Talent Partner to discuss your experience and explore whether Frontify is the right place for you.
This description outlines the primary duties of the role, which may evolve in response to business needs and company growth.
We’re looking for someone comfortable with change and excited to contribute to a dynamic environment.
If this sounds like you, come join us and help shape what’s next.
We may conduct preliminary checks for successful candidates, depending on the role and in line with local laws. We’ll share all relevant details during the interview process.
#J-18808-Ljbffr
Information Security Governance Specialist Arbeitgeber: Frontify AG. “Frontify” is a registered trademark of Frontify AG
Frontify ist ein hervorragender Arbeitgeber, der eine kreative und inklusive Arbeitskultur fördert, in der Teamarbeit und persönliche Entfaltung im Mittelpunkt stehen. Mit einem flexiblen Arbeitsmodell und zahlreichen Entwicklungsmöglichkeiten bietet das Unternehmen seinen Mitarbeitern die Chance, innovative Technologien zu nutzen und an spannenden Projekten zu arbeiten. Zudem profitieren die Mitarbeiter von attraktiven Zusatzleistungen wie 25 Tagen Urlaub, einem Home-Office-Budget und der Möglichkeit, von inspirierenden Orten weltweit zu arbeiten.
Kontaktdaten:
Frontify AG. “Frontify” is a registered trademark of Frontify AG Recruiting-Team
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Information Security Governance Specialist erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Frontify AG. “Frontify” is a registered trademark of Frontify AG kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Frontify AG. “Frontify” is a registered trademark of Frontify AG zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Frontify AG. “Frontify” is a registered trademark of Frontify AG.
Wir glauben, dass du diese Fähigkeiten brauchst, um Information Security Governance Specialist mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Frontify AG. “Frontify” is a registered trademark of Frontify AG vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Frontify AG. “Frontify” is a registered trademark of Frontify AG könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Frontify AG. “Frontify” is a registered trademark of Frontify AG sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Frontify AG. “Frontify” is a registered trademark of Frontify AG auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!