Information Security Officer
About this role
Paligo is hiring an Information Security Officer to run and strengthen our information security work day to day. Enterprise customers in 38 countries trust Paligo with their most critical content, and this role exists to keep that trust earned — from our ISO 27001-certified ISMS to the security foundations of our evolution into the AI Content Infrastructure for businesses.
This is a hybrid position based out of our Stockholm office. Candidates must currently reside in Sweden and hold the legal right to work there. We are unable to sponsor work visas or offer relocation for this role.
About Paligo
Paligo is an industry-leading SaaS company in the component content management system (CCMS) space. Global teams at Amazon, Allianz, Mitsubishi, and the European Commission use our platform to create, manage, publish, and translate technical content.
After having built a successful documentation authoring tool, Paligo is transforming into a foundational AI Content Infrastructure, ensuring enterprise AI is safe, compliant, and accurate by grounding it in the rich context distributed across diverse business sources.
About the role
You'll own the day-to-day operation of our Information Security Management System (ISMS) under ISO/IEC 27001:2022: audits and evidence, risk assessments, policies, awareness training, and the security questions our enterprise customers ask us every week.
You'll report to the CTO, who sets security strategy with you and backs you with the mandate to get things done. At a company of under 100 people, that means hands-on work and real visibility from day one. It also means room to grow — this role is built to expand as your experience does, and as Paligo does.
What you'll do
Keep our ISO 27001:2022 ISMS running and improving: documentation, internal audits, evidence collection, and preparation for external audits.
Maintain the risk register and run risk assessments across Paligo CCMS.
Support security reviews of our AI grounding infrastructure and data pipelines together with engineering.
Help secure our external AI offerings, including MCP and APIs for autonomous agents, with a focus on data exposure and access control.
Own customer security questionnaires, due diligence requests, and vendor risk reviews.
Support GDPR and contractual compliance work alongside Legal and product teams.
Coordinate incident response and business continuity testing, and keep both plans current.
Run security awareness training and build a security culture people actually engage with.
Report on ISMS performance and open risks to the CTO and leadership team.
What we're looking for
Required
2–5 years of experience in information security, risk, or compliance, preferably at a SaaS or technology company.
Hands-on experience working inside an ISO 27001 ISMS: audits, evidence, risk assessments, and policy maintenance.
Working knowledge of cloud security in AWS, Azure, or GCP.
The ability to translate security requirements for engineers and non-technical colleagues alike, and the confidence to hold the line when it matters.
A degree in computer science, information technology, information security, or a related field — or equivalent practical experience.
Professional fluency in English.
Nice to have
Exposure to compliance frameworks such as SOC 2, NIST CSF, PCI-DSS, CCPA, or HIPAA.
Experience with GDPR and the EU AI Act
Experience handling enterprise customer security questionnaires and vendor assessments.
Familiarity with securing AI integrations via MCP and APIs.
Prior exposure to component content management systems or similar content- and data-heavy platforms.
Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CompTIA Security+, or progress toward CISM or CISSP.
What we offer
Real ownership early in your career: you run the ISMS at a profitable, growing company that enterprises depend on.
A CTO who acts as your sponsor and sounding board, with direct access to leadership.
A role designed to grow. This is our first dedicated security seat, and it expands as you and Paligo do.
A front-row seat as we build AI grounding infrastructure for enterprises, where security is a core part of the product story.
Competitive benefits, flexible working hours, and a hybrid setup based in Stockholm.
A culture that takes work seriously and the rest of life seriously too.
Ready to talk?
If you want to own security at a platform enterprises worldwide depend on, and grow into the person who leads it, we'd like to hear from you.
(The final step of our recruitment process is a mandatory background check, including a financial and criminal check. Any offer of employment is contingent on its successful completion.)
Company at a glance
Paligo supports teams working with complex technical documentation that must grow, adapt, and remain consistent over time. Built for structured content at scale, Paligo helps organizations treat documentation as a long-term business asset through reuse, automation, and strong content governance.
At the core of Paligo is a cloud-based CCMS designed around modular content. Teams can author once, reuse components across multiple outputs, and keep documentation aligned across products, formats, and languages. This reduces manual work, accelerates updates, lowers translation costs, and helps teams publish faster with fewer errors.
Paligo combines advanced structured authoring with a modern, approachable interface. This makes it effective for experienced documentation specialists while remaining accessible to contributors across the organization. From creation and collaboration to translation and multichannel delivery, Paligo brings the full documentation workflow into one controlled environment.
Paligo’s purpose is to help organizations move beyond static, fragmented documentation and build content operations that support continuous growth. With Paligo, teams stay in control of complexity and deliver documentation that evolves alongside their business.
Top Benefits
- Flexible working hours
- Hybrid work setup
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?