Rodeo
Get started

GRAITEC Italy

Information Security Leader

Leeds
Posted about 10 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Graitec Group

Graitec is a global leader in Building Information Modeling (BIM) solutions, designing and developing software that helps architects, engineers, and manufacturers design smarter and better. With over 30 years of innovation and an entrepreneurial spirit, we’ve tripled our revenue in just five years.

Our North Star is clear — accelerate the digital transformation of the AECO industry and model the future. We achieve this by growing our recurring revenue through innovative software and services that drive adoption, integration, and lasting value for our customers.

Our 800 experts across 30+ offices in 12 countries support more than 270,000 users worldwide. As a global Autodesk Platinum Partner, we combine world-class partnerships with our own cutting-edge software and services to drive performance and sustainability across the industry.

At Graitec, we move fast and think big. We collaborate across teams and borders, embrace diversity, and challenge ourselves to innovate every day. We believe in doing the right thing, breaking down silos, and making an impact together.

How we work: Growth, Agility, Innovation, Responsibility

How we behave: Ambition, Engagement, One Graitec, Positive Energy

Learn more about the Graitec Group: graitec-group.com/graitec-a-global-player

About The Team Hiring

The GRAITEC IT Department is a dynamic, multicultural environment bringing together skilled professionals across Europe and North America. With core expertise in IT infrastructure, cybersecurity, systems administration, cloud technologies, and enterprise applications, the team works closely with all business units to ensure stable, secure, and efficient operations that support the company’s strategic objectives.

At GRAITEC, the IT team plays a critical role in enabling business performance, minimizing security risks, and driving automation and digital transformation across the organization. We foster a culture of continuous improvement, collaboration, and operational excellence, encouraging initiative, supporting professional development, and empowering our IT professionals to implement solutions that create real, measurable impact across the global organization

Overview

Business Purpose & Value Contribution

This role owns information security, risk and compliance for Graitec: the certifications, the controls and the assurance that keep Graitec and our customers safe.

It is commercially consequential: information security managed as a product and turned into business won and retained. The role is hands-on, writing the policy, running the audit and answering the difficult customer questions, and it is designed to grow into a broader leadership remit as the capability matures.

Key Outcomes Expected

What success looks like in the first 12 months

  • ISO 27001 certification and SOC 2 Type II attestation achieved through one efficient control programme
  • An external trust centre live, with customer security questionnaires answered to an agreed SLA from a maintained and increasingly automated knowledge base
  • Security visibly enabling revenue, with named regulated and public sector opportunities won or retained on the strength of our security position
  • A prioritised information security risk register, owned by the business and reviewed at executive level
  • Detection and response matured: consolidated tooling, tested playbooks, and time to detect and respond trending down
  • External security ratings improved further
  • A published position on AI security and acceptable use, with the AI estate inventoried and a clear approval route to be an enabler for innovation

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Responsibilities

Certification & Compliance

  • Own delivery of SOC 2 Type II and ISO 27001 as a single efficient control programme
  • Build and run the information security management system: policies, controls, evidence, internal audit and management review, and own the relationship with auditors and certification bodies

Customer Assurance & Commercial Enablement

  • Run customer assurance: an external trust centre, a maintained questionnaire knowledge base, clear service levels back to Sales, and reporting on the commercial contribution of security
  • Represent Graitec on security with customers and prospects, including regulated and public sector accounts, and support contract negotiation with the Group Legal Director

Security Operations & Engineering

  • Own detection and response, and run vulnerability, exposure and patch management to agreed targets, with the external attack surface actively managed
  • Own identity and access security with IT Operations & Platforms: privileged access, service accounts, conditional access, and joiner, mover and leaver controls
  • Own the security tooling roadmap and budget, consolidating the estate as required

Cloud, Product & Web Security

  • Secure Graitec's public estate, platforms and hosted services, setting secure-by-design standards for cloud landing zones, integrations and customer-facing services
  • Extend remit to our intellectual property and product security, with a strong working interface into R&D
  • Embed secure development practice with R&D: secure SDLC, code and dependency scanning, secrets management, and penetration testing with tracked remediation

Risk, Resilience & Governance

  • Build and maintain the information security risk register, with business ownership, an agreed risk appetite and executive-level reporting
  • Own third party and vendor security assessment, including periodic reassessment and secure offboarding, and provide security due diligence for acquisitions
  • Drive security governance for corporate AI: inventory and approval of tools and agents, AI access to corporate data, AI vendor risk, and responsible use
  • Own incident response and business continuity: run exercises, lead responses, and work with other functions on disaster recovery design and testing
  • Build security awareness that changes behaviour, with targeted training, phishing simulation and a strong culture of prevention

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Responsibilities

  • Hands-on ownership of an information security programme in a software or SaaS business, with SOC 2 Type II and ISO 27001 carried end-to-end, and national schemes e.g., Cyber Essentials Plus or NIST CSF
  • Strong working knowledge of the Microsoft security stack (Defender, Entra ID, Purview, Sentinel) and of managing an outsourced or co-managed SOC
  • Cloud security, including landing zones, identity, securing internet-facing services, and penetration testing and vulnerability remediation with R&D teams
  • Security risk management, third party assurance and GDPR obligations, working alongside a Data Protection Officer
  • AI security and governance: securing AI agents that access corporate data, and setting the inventory, approval and acceptable use framework
  • Comfortable as the only dedicated security professional, pragmatic and proportionate in a mid-sized, fast-moving business
  • Commercially astute, credible in front of customers, and able to translate risk into business language
  • Self-directed and evidence-driven, taking work to completion, and able to develop junior talent and mature a small team

Also valued

  • CISSP, CISM, CISA, CRISC, CCSP, or ISO 27001 Lead Implementer or Lead Auditor
  • Experience in M&A due diligence and integration, in an acquisitive or private equity-backed group
  • Exposure to NIS2, DORA or the EU AI Act

Qualifications

  • Executive-level communication, with a track record of leading adoption and change across multinational, multidisciplinary teams
  • Results-oriented mindset with a high degree of ownership and accountability.
  • Ability to operate effectively in a global and multicultural environment.

Interview Process

At Graitec, we’re proud to foster a diverse and inclusive workplace.

We value our employees for who they are and the contributions they bring, encouraging everyone to be their authentic selves at work. This diversity helps us better serve the wide range of customers and markets we operate in. We welcome applications from all backgrounds and assess candidates solely on their skills and ability to succeed in the role.

Graitec uses AI to support and streamline internal processes; however, all application reviews, screening, and hiring decisions are made solely by our Talent Acquisition team and hiring managers.

HR Screening

  • An initial “get to know you” discussion.

Hiring Manager Interview

  • A role-specific discussion with the hiring manager.

Technical Interview

  • May include a presentation or a collaborative exercise.

Final Interview

  • Conversation with the Business Unit Leader.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Leeds, England, United Kingdom

Sign up to applySee more jobs like this