Information Security Governance Specialist

Posted 5 Days Ago
Be an Early Applicant
St. Gallen, CHE
Hybrid
Senior level
Enterprise Web • Marketing Tech • Software
Frontify is the all-in-one brand management platform for building powerful brand experiences.
The Role
Lead security governance by operating and improving compliance programs (ISO 27001, SOC 2, TISAX), owning customer security assurance, audit readiness, and vendor risk. Drive automation and AI adoption in the Vanta-based GRC program, design AI-enabled GRC workflows, scale automated vendor assessments, and improve security awareness to make governance continuous and auditable.
Summary Generated by Built In
We're all about helping brands turn ideas into impact.

Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns. Our people empower thousands of marketers and designers — including teams at Uber, Microsoft, Volkswagen, and Telefónica — to build engaging brands.

With headquarters in St. Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy. And we’re on the lookout for new team members to share our vision. If you’re ready for a brand-new adventure, keep reading!

Your team
With the mission of creating a home where all brands (including our own) are safe, the Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders. Security, pragmatism and user friendliness are our guiding principles. Outside of work, we’re gamers, avid bookworms and kickboxers.

Your mission

Trust is what enables the world's leading brands to build on Frontify. Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify. Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.

A key focus of the role is driving the next stage of our security governance maturity. Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits. You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness. This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value.

Your responsibilities

  • You'll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.

  • You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.

  • You'll serve as the subject matter expert during audits and ensure our control environment remains effective and audit-ready.

  • You'll help transform compliance from a point-in-time activity into a continuous process by introducing automation and AI into our Vanta-based GRC program. This includes improving evidence collection, control monitoring, and access review processes.

  • You'll design and improve AI-enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.

  • You'll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher-risk vendors receive appropriate human review.

  • You'll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training.

Your story

  • You’re comfortable working in a hybrid format, with the ability to come to our St. Gallen office once per week.

  • You have 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.

  • You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.

  • You're hands-on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.

  • You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.
  • You're genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.

  • You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.

  • A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.

  • You speak English fluently. German is a plus.

We understand that every candidate’s experience is different. If you’re interested in this role but don’t tick all the boxes, we still encourage you to apply.
 
Why join us?
- Thrive with the tools and support to shape your future at Frontify.
- Be part of a product that connects brands and people with a human touch.
- Enjoy flexibility, opportunities to grow, and exposure to innovative technologies and ideas.
- Join a vibrant, social team—whether you love animals, yoga, or travel, we’ve got the Slack channels for you!
 
What we offer
- A minimum of 25 days annual leave per year 
- Parental, family care, and bereavement leave
- Daily sickness benefits and accident insurance
- Paid educational and wellbeing days off
- Wellbeing, learning and development, and commuter allowance 
- Home office setup budget
- Pension fund: contributions paid 60% by us and 40% by you
- Access to exclusive perks and discounts from hundreds of top brands
- Workation: Work from inspiring locations around the world for up to 45 days per year!
- Invite to our summer company meet-up
 
Important to us
Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future.
 
We’re committed to an inclusive hiring experience. If you need any support or adjustments during the recruitment process, please let your Talent Partner know when scheduling. Any information shared will be treated confidentially.
 
Next steps
If there’s a fit, you’ll meet our Talent Partner to discuss your experience and explore whether Frontify is the right place for you.
 
This description outlines the primary duties of the role, which may evolve in response to business needs and company growth. We’re looking for someone comfortable with change and excited to contribute to a dynamic environment. If this sounds like you, come join us and help shape what’s next.
 
We may conduct preliminary checks for successful candidates, depending on the role and in line with local laws. We’ll share all relevant details during the interview process.

Skills Required

  • 5+ years experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.
  • Direct subject matter experience working on SOC 2 and/or ISO 27001 controls and audits.
  • Hands-on experience with modern GRC platforms (Vanta and Conveyor).
  • Experience introducing automation and AI into GRC/compliance processes (continuous evidence collection, automated control monitoring).
  • Ability to work hybrid and attend the St. Gallen office approximately once per week.
  • Fluency in English.
  • Ability to communicate risk clearly to technical and business audiences.
  • Experience with TISAX or Microsoft SSPA.
  • Relevant certification (CISA, CISM, CISSP, CIPP, or similar).
  • German language skills.

Frontify Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Frontify and has not been reviewed or approved by Frontify.

  • Leave & Time Off Breadth Policies include a minimum of five weeks of paid vacation, flexible hours, and hybrid/remote options. Feedback suggests time away and flexibility are consistently highlighted as strengths.
  • Healthcare Strength U.S. employees receive comprehensive medical, dental, and vision coverage, and all employees have access to dedicated mental-health support. Location-specific medical offerings (e.g., UK private medical and cashback plans) reinforce core health coverage.
  • Parental & Family Support Paid parental leave, lactation accommodations, and family-friendly scheduling are explicitly provided. Childcare benefits and supportive leave structures indicate meaningful backing for parents and caregivers.

Frontify Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: St. Gall
310 Employees
Year Founded: 2013

What We Do

With our best-in-class brand management platform, Frontify is on a mission to create a home where all brands can thrive. We envision a world where all teams and workforces, big and small, are empowered and engaged to be a part of building beloved brands.

Why Work With Us

Our community is spread across the world but we are always brought together by our shared values. At Frontify, we aim to stay united, be authentic, improve ourselves, and thrive together as a team.

Gallery

Gallery

Similar Jobs

Deepgram Logo Deepgram

Sales Development Representative

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Datadog Logo Datadog

Account Manager

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
2 Locations
6500 Employees

Pfizer Logo Pfizer

Senior Director, Applied AI - US Commercial

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
28 Locations
121990 Employees
215K-358K Annually

Tulip Logo Tulip

Forward Deployed Engineer - EMEA

Enterprise Web • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
27 Locations
310 Employees
70K-105K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account