Bambuser
Security & Compliance Officer
Stockholm, Nordics, SE · Posted 11h ago
Job Description
While we welcome applications from everywhere, please note that at this stage we are prioritizing candidates who are already based in Stockholm and eligible to work in Sweden without visa sponsorship.
We are Bambuser, and we are reshaping commerce
Video has quickly become one of the most powerful ways for brands to engage, inspire, and convert consumers.
At Bambuser, we’re helping some of the world’s most recognized brands transform how they sell online through live shopping, shoppable video, and interactive commerce experiences. Brands including LVMH, Audi, Sephora, Decathlon, and Sonos use our platform to create richer and more engaging customer experiences.
As a global B2B SaaS company working with enterprise customers, trust matters at every stage of our business. Customers need to know that their data is handled responsibly. Teams need clear and practical guidance. Auditors need evidence that our controls work. As technology and regulation evolve – particularly around AI – we intend to maintain our position at the forefront.
That’s where you come in.
About the role
Bambuser already has strong security and compliance foundations, including an ISO 27001-certified ISMS. Your challenge will be to build on them as our business, customer expectations, and the regulatory landscape continue to evolve.
You’ll own our ISMS, data privacy and compliance frameworks, and operational risk registers. Day to day, you’ll support the business in meeting its regulatory obligations, keep our policies relevant and current, and make sure we walk into every audit ready rather than scrambling.
We’re a fast-moving scale-up, so we need you to think the way we all try to think: what can be automated, templated, or scheduled instead of done by hand again? If you find yourself doing the same manual task twice, we want you to build a system that makes sure you never do it a third time—and ideally, nobody else has to either.
Main duties and responsibilities
ISMS Governance & Audit Readiness
Own and maintain the ISO 27001 governance framework, driving continuous improvement of the ISMS to sail through surveillance audits and recertification. Prepare for and run internal and external audits end to end: scoping, evidence collection, stakeholder coordination, and findings remediation. Build playbooks and control documentation that hold up under scrutiny, not just look good on paper.Keeping Policies Sharp, Not Just Compliant
Own the full ISMS library. Review what exists for relevance, overlap, and gaps, and right-size it to match the actual risk profile, not more, not less. Drive adoption across the org through clear communication and practical enablement so policies get followed in practice.The Face of Security to Customers and Vendors
Serve as the go-to contact for enterprise customer security reviews, owning the information security sections of RFPs and keeping the Trust Center current. Lead the rollout of the RFP AI tool. On the procurement side, act as the information security reviewer for new tools and vendors, assessing data handling, access, and integration risk before adoption, AI tools included.Staying Ahead of Regulation, Including AI
Track the regulatory landscape across all markets: GDPR and international privacy law, information security standards, sector-specific rules. Turn that into concrete controls and clear internal ownership. Keep an eye on where AI regulation (like the EU AI Act) is heading, and proactively start building the groundwork, risk classification and usage guidelines.Security Testing and Training That Sticks
Coordinate and support penetration testing engagements: scoping with vendors, arranging internal access, chasing findings through to remediation. Own the security training program end to end, designing and delivering onboarding and recurring awareness training, and keeping it fresh as threats and regulations shift.Systems, Not Just Processes
Lead adoption of Bambuser's new operating model, making sure people understand and own their part in it. Turn security workflows that currently live in someone's head into documented, scalable processes. Wherever there's a recurring task, evidence collection, training reminders, audit scheduling, the default should be to automate it rather than track it manually.Data Privacy and Risk
Oversee GDPR and international privacy compliance across every market, looping in external counsel when needed. Run the Senior Management risk assessment process, keeping the corporate Risk Register current and tied to what the business actually cares about.
Requirements
Experience: 5+ years in information security compliance, IT audit, or risk management, ideally in B2B SaaS or another fast-growing tech company.
ISO 27001: A track record of implementing or maintaining ISO/IEC 27001 certifications. Experience running or supporting penetration testing programs is a plus.
Privacy know-how: A strong, practical grasp of GDPR in multi-tenant SaaS environments.
Regulatory radar: Familiarity with where AI regulation (like the EU AI Act) is headed and what it means for a tech business.
Pragmatism: You can turn complex regulatory requirements into workflows that don't grind the business to a halt.
Communication: You're comfortable translating technical security risk into business terms, for executives, for enterprise customers, and for a room full of people at a training session.
An automation instinct: You default to building the system rather than repeating the task, comfortable with workflow automation, reminders, scheduling tools, and AI-assisted drafting to cut busywork, both your own and everyone else's, so time goes toward the work that actually needs a human.
Proactive and solutions-oriented: You identify risks, spot patterns, and anticipate future needs, rather than waiting for problems to surface.
Bonus: Experience working in or with publicly listed companies, including familiarity with their internal control requirements.
Why Bambuser?
You’ll join a focused, hungry team that genuinely enjoys working together and getting things done. We move quickly, help one another, and share the same goal – without the silos or distance that can make this kind of role feel thankless elsewhere.
Here, your contribution will be visible, valued, and felt across the company. You’ll help turn ambition into something real by giving teams the clarity and confidence to move forward.
Here, you'll find the pace and ownership of a scale-up, without the chaos. We have a solid product, an experienced team, and people who care deeply about the quality of what they build.