Skip to main content

Senior Information Security Officer

Security and compliance at TechWolf is a small, multidisciplinary team with an unusually central seat. We are not an isolated centre of expertise that the business consults occasionally: we sit inside day-to-day operations, and we pick up problems because they need solving, not because they fit neatly inside our remit. We are also on the critical path of the company's growth: every deal TechWolf signs clears a security review on our side, and for our largest customers that review is one of the harder parts of the sale.

Our customers are large regulated enterprises, among them global banks and insurers, and their security teams assess us at the depth of a SOC 2 audit, on-site visits included. Today two people carry that work, against a business that has roughly doubled in a year. You are the third: a senior individual contributor who owns governance, risk and compliance programmes end to end, and who sits in front of those customers' security teams as the named owner. You decide when something escalates, and you are trusted to hold the room. You'll report to our Security Officer, who sets our security strategy and stays hands-on alongside you; your responsibility is to own and run the programmes that make that strategy real. On the hard calls, you define the solution rather than surface the problem, and the Security Officer signs off.

How we work matters as much as what we own. This is a fast-paced, hands-on environment, and TechWolf is AI-first. AI tooling is a large part of how two people absorbed a doubling in deal volume without slowing deals down. We expect you to work the same way: hands on the work rather than directing it, self-sufficient, and building your own leverage.

**What you'll do**

* Be the reason large deals clear security. You own security due diligence on our large enterprise deals end to end: the questionnaires, the custom due-diligence requests, the customer risk assessments, the evidence packages, the on-site visits, and every piece of follow-up between the first architecture call and signature. You negotiate the security schedules in contracts and data processing agreements yourself, finding positions that protect TechWolf without costing us the deal. This includes working with our internal AEs to align before sitting in front of the customer.

* Build the programme, not just work the queue. You decide how we tier what comes in, what response times we hold ourselves to, and what gets automated next. You design how we assess and tier our own vendors, and the criteria that decide when a third-party risk gets escalated. What you build here is what the function runs on as we scale.

* Run our certifications, including the ISO 42001 our AI Management System. In addition, you run ISO 27001 and SOC 2 end to end, working with the security and engineering teams. You own the auditor relationships at programme level, map controls across the three standards so we evidence something once rather than three separate times, and drive fixes from the root cause instead of closing findings one by one.

* Keep us ahead of regulation rather than behind it. You steer our GDPR posture, advise on the implementation of requirements for high-risk AI systems within the EU AI Act while most companies are still reading it, and advise the business on cross-border data transfers.

* Make risk a business conversation. You set the methodology, run risk workshops with senior stakeholders, and put risk to leadership in terms they can act on. When a risk acceptance drifts outside our appetite, you are the one who says so.

* Design governance that holds as we scale. You architect the ISMS documentation hierarchy, own the management-review cycle, and surface the governance gaps that quietly create operational risk before they surface themselves.

* Shape where security goes next. You contribute to the security and compliance roadmap, flag the regulation coming over the horizon, arm presales to answer security questions without you, and coach more junior colleagues on methodology.

* Own the follow-through when something goes wrong. You run the governance and coordination around incidents, the part that decides whether we actually learn from them. Not hands-on detection or response engineering.

Others also viewed

Senior Information Security Officer

Company:
TechWolf
City:
Gent
Employment type: 
Full-time, Permanent
Job categories: 
Security Engineer, IT, System, Presales Engineer, Financial Analyst
Seniority level: 
Senior
Published:
12.08.2026
Share now: