Head of Information Security and Compliance

Posted Yesterday
Be an Early Applicant
2 Locations
Hybrid
Senior level
Artificial Intelligence • Information Technology • Internet of Things • Software
The Role
Lead and build the group's information security and compliance programme across multiple countries and acquisitions. Own ISO27001/Cyber Essentials Plus, ISMS, GDPR, incident response, business continuity, security baselines, risk registers, customer assurance, external vendors, audits and reporting to executives. Operate with a small team and collaborate with IT Operations and Platform Engineering to set and verify standards.
Summary Generated by Built In

About SINGU

At SINGU, we’re redefining how the world’s most ambitious real estate companies run their operations. Our mission is to become Europe’s leading platform for managing warehouse, logistics, retail, and multi-site commercial real estate portfolios — empowering our Clients to protect revenue, boost efficiency, and unlock new value across every aspect of their business.

 

Our unified CAFM platform already powers the daily operations of over 250 million m² of real estate worldwide, supporting more than 500,000 professionals. Following our union with the UK’s Micad and Germany’s net-haus, we now help manage 100,000+ buildings across 35+ countries — and we’re just getting started.

 

Backed by a leading growth equity investor, we’re scaling rapidly and partnering with global leaders such as Prologis, ECE, CTP, Hillwood, Logicor, GLP, and Unibail-Rodamco-Westfield. As we continue to grow through strategic acquisitions and bold innovation, we stay true to our core values: adaptability, collaboration, and client focus.

 

If you’re ready to help build Europe’s leading platform for property operations — and make a tangible impact on how the real estate industry works — join SINGU and be part of this transformation.

The Role

This is the senior security role in the group, and it is yours to build. You will hold the certifications, front the audits, and be the person our customers, insurers and board ultimately rely on.

We have grown fast through acquisition. That means several entities in three countries, each at a different level of maturity, with overlapping but non-identical obligations. Your job is to bring them onto one coherent, credible programme, and keep it that way through the next acquisition. You will do it with a small team and a lot of autonomy, so pragmatism matters more here than process for its own sake.

What You'll Own

  • ISO 27001 and Cyber Essentials Plus across every entity: scope, evidence, audits, recertification, and pulling newly acquired businesses in. If SOC 2 becomes commercially necessary, you will make that call and lead it.

  • The ISMS and the policies behind it. Current, genuinely used, and credible to an auditor.

  • GDPR across three jurisdictions: processing records, DPIAs, transfers, subject requests, breach notification.

  • Customer security assurance. Questionnaires, due diligence packs, and the security terms in contracts and DPAs. You will join the calls where deals are won or stalled on security.

  • Incident response, end to end. You own the plan, you run the response, and you make sure the post-mortem actually changes something.

  • Business continuity and disaster recovery for group systems, tested at least annually, plus tabletop exercises with the leadership team.

  • The security baselines for endpoints and internal systems such as CRM, ERP, email and collaboration. IT Operations implements them. You set them, and you verify them.

  • Risk register, access reviews and control testing, reported straight to the executive team.

  • External partners: MSPs, penetration testers, security vendors, and the cyber insurance relationship.

  • Security awareness that people absorb rather than click through.

What This Role Is Not

Security of the SINGU product and the infrastructure hosting it belongs to Platform Engineering. Day-to-day administration of laptops and internal systems belongs to IT Operations. You set the standard and hold both to it. You are not the person reimaging a laptop.

What We're Looking For

  • You have led information security and compliance, ideally as the most senior security person in the business.

  • You have taken ISO 27001 through at least one full audit cycle and know where the bodies are buried.

  • You have applied GDPR in practice, in more than one country.

  • You have matured security across businesses at different stages, ideally in a group built by acquisition.

  • You build programmes pragmatically. You can tell the difference between real risk reduction and theatre, and you protect business velocity while cutting the latter.

  • You are credible in front of customers, auditors and the board, and can hold a technical line without becoming the reason a deal dies.

  • CISSP, CISM or equivalent.

  • Strong professional English. Polish is useful, not essential.

Why You'll Want This

  • Full ownership of security for an international SaaS group, with direct access to the executive team.

  • A programme you shape rather than inherit. Real problems, real budget, and the mandate to fix them properly.

  • Security here enables revenue. It is a visible commercial role, not a back-office one.

  • The group is still growing. What you build now becomes the standard for everything we acquire next.

  • Competitive salary, aligned to seniority of the role

  • Private medical care, sport card, life insurance, an annual training budget, a team integration budget, and more

Singu Group is an equal opportunity employer. We welcome applications from all backgrounds.

If this role sounds like a good fit, we’d love to hear from you. Apply and help us build technology that supports critical operations every day.

Skills Required

  • Led information security and compliance as the most senior security person in a business
  • Taken ISO 27001 through at least one full audit cycle
  • Applied GDPR in practice across more than one country
  • Experience maturing security across businesses at different stages, ideally in a group built by acquisition
  • Ability to build pragmatic security programmes that reduce real risk without blocking business velocity
  • Credible in front of customers, auditors and the board; able to represent security in deal discussions
  • Ownership of incident response, business continuity, disaster recovery, and running post-mortems
  • CISSP, CISM or equivalent certification
  • Strong professional English (Polish useful)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Kraków, Małopolskie
122 Employees
Year Founded: 2009

What We Do

SINGU is a unified platform that centralizes maintenance, assets, and ESG into one source of truth. By replacing scattered tools and manual processes, it gives you the visibility and control to manage operations with clarity, efficiency, and accountability. Instead of complexity and data fragmentation, SINGU enables simpler, smarter, and more sustainable property operations. Our mission is to empower operations teams, owners, and service partners across logistics hubs, retail networks, healthcare, higher education, government, and adjacent sectors. We do this through a unified CAFM platform that centralizes data and workflows – driving efficiency, ensuring compliance, and delivering long-term value. SINGU supports the daily operations of over 500,000 users worldwide. Our platform manages more than 250 million square meters of real estate and is used across 40+ global markets, reflecting SINGU’s strong international presence in real estate operations software.

Similar Jobs

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Superhuman Logo Superhuman

Digital Adoption Manager, Superhuman Docs

Artificial Intelligence • Information Technology • Machine Learning • Natural Language Processing • Productivity • Software • Generative AI
Remote or Hybrid
Poland
1500 Employees
152K-250K Annually

Ericsson Logo Ericsson

Implementation Manager

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Warszawa, Mazowieckie, POL
88000 Employees

JPMorganChase Logo JPMorganChase

Controller

Financial Services
Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account