Skip to content

Information Security & Regulatory Compliance Manager – ISO 27001 & European E-Invoicing (part-time)

IMG_3632

Location

On-site in our new HQ in beautiful surroundings in Hellerup.

About the role

We're looking for a part-time Information Security & Regulatory Compliance Manager with solid practical experience in ISO/IEC 27001:2022.

The role will be responsible for maintaining and further developing iEDI's management of Information Security and supporting its continued ISO 27001 certification.

You'll work directly with policies, controls, risk assessments, audits, documentation, training, and continuous improvement. Alongside information security, the role will also involve navigating regulatory developments relevant to iEDI, including European e-invoicing requirements and, in particular, the French requirements concerning Plateforme Agréée (PA).

This is a hands-on role. We're not simply looking for an advisory position, but rather someone who is comfortable taking ownership and carrying out the work together with management, developers, colleagues, and external auditors.

What we're looking for

We're looking for someone who enjoys taking ownership and turning regulatory and security requirements into practical, well-structured processes. You're comfortable working independently, but also know when to involve colleagues and stakeholders to move projects forward.

Ideally, you:

  • Have practical experience working with ISO/IEC 27001:2022 and Information Security Management Systems (ISMS)
  • Are structured, detail-oriented, and enjoy keeping documentation organised and up to date
  • Can communicate complex security and compliance topics in a clear and practical way
  • Are comfortable planning and conducting audits, risk assessments, and employee training
  • Take initiative and are confident driving tasks from planning to implementation
  • Have an interest in European digital regulation, such as e-invoicing, GDPR, NIS2, DORA, and related compliance frameworks
  • Are fluent in English, both written and spoken

Don't tick every box? We know that great candidates don't always meet every single requirement. If you have a solid foundation in information security and enjoy learning new things, we'd still love to hear from you.

What you'll be doing

  • Maintaining and developing our ISMS in accordance with ISO/IEC 27001:2022
  • Keep security policies, risk assessments, controls, procedures, and supporting documentation up to date
  • Plan and conduct information security training for employees
  • Prepare and conduct internal audits and follow up on findings and non-conformities
  • Prepare the organization for external surveillance and certification audits
  • Maintain oversight of security incidents, corrective actions, and ways to improve them
  • Follow relevant regulatory requirements such as GDPR, NIS2, DORA etc. etc.
  • Monitor international developments within electronic invoicing and regulatory compliance
  • Work closely with management, developers, operational colleagues, and external auditors
  • Be comfortable working independently and taking ownership of compliance activities from beginning to end

What we offer

  • An entrepreneurial environment in which your ideas are heard and your solutions welcome
  • Significant ownership of an important area of the business
  • The opportunity to work directly with both information security and emerging European regulatory requirements
  • A close working relationship with management and our technical teams
  • A flexible part-time role in a stable and growing international field
  • The opportunity to shape how security and compliance are handled as the company continues to develop
  • Social gatherings a few times a year where international colleagues are invited