Unlock Full Resume Report

New offer - be the first one to apply!

September 20, 2026

Information Security Lead (OT Security, Video Data Privacy & SOC 2)

Senior • Remote

Warsaw, Poland

Quick Facts

  • Role: Information Security Lead (OT Security, Video Data Privacy & SOC 2)

Description

You will be the hands-on security owner for an AI machine-vision platform operating inside customer industrial networks. The role covers OT/camera connectivity security design, customer security engagements, SOC 2 readiness (mapped to Trust Services Criteria), and end-to-end privacy for video/image data used for AI training. You will also own the security risk register, vendor risk, and incident-response plan, advising engineering on the controls SOC 2 requires.

Responsibilities

  • Define secure connectivity from cameras/on-site devices to customer OT networks, including segmentation, firewall rules, outbound-only cloud connectivity, secure remote access, and secure hardening/patching.

  • Act as the security voice with customers’ IT, OT, and security teams (questionnaires, architecture reviews, network requirement documents, and calls).

  • Lead SOC 2 work: gap assessments, mapping controls to Trust Services Criteria, evidence collection, and coordination with the auditor and compliance tooling.

  • Own video/image privacy: DPIAs, data-flow maps, retention/deletion rules, access control, governance for footage used to train AI models, and evidence that anonymisation of people holds up; deliver customer-facing documentation (DPA, sub-processor list, and technical/organizational measures).

  • Support customers with workplace-camera rules, including works councils and national employee-monitoring law.

  • Own security risk management: security risk register, vendor risk, and incident-response plan; advise engineering on SOC 2 control requirements for cloud and development.

Requirements

  • 6+ years in information security with hands-on implementation experience building and running controls.

  • SOC 2 audit experience in a hands-on role (Type I or II), ideally extending an ISO 27001-aligned program.

  • Hands-on ISO 27001 implementation and strong understanding of what SOC 2 adds.

  • OT/industrial network security expertise (segmentation via zones & conduits, Purdue model and/or IEC 62443, secure remote access, and securing third-party systems that can signal/command PLCs and line equipment).

  • Data privacy experience applying GDPR in practice (DPIAs and privacy by design), ideally for video/CCTV or sensor data, including anonymisation and governance for personal data used to train AI models.

  • English at C1 level for policies and customer-facing security documentation.

  • Pragmatic, independent approach and comfort delivering results quickly in a young company.

Benefits

  • Participation in interesting and demanding projects.

  • Flexible working hours.

  • A great, non-corporate atmosphere.

  • Possibility to work remote or hybrid (2 days per week from the office).

  • Opportunities for development and promotion.

  • Attractive package of benefits.

Similar jobs you might like