Basware
Manager - Information Security (Compliance)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Manager - Information Security (Compliance)
At Basware, we deliver mission-critical cloud solutions that empower organizations to unlock their full potential. Our products are designed to bring clear and compelling value to our customers, and we’re looking for talented and forward-thinking professionals who can help us shape the future of our technology.
We are seeking a Manager - Information Security (Compliance), an experienced security compliance specialist who thrives at the intersection of governance, risk management, and stakeholder engagement. In this role, you will help ensure that Basware maintains a robust and effective security compliance program while supporting customers, auditors, suppliers, and internal teams with practical, risk-based guidance.
The Information Security Compliance team supports the organization in maintaining an effective, risk-based information security management system. The Manager - Information Security (Compliance) will coordinate key compliance, assurance, and risk management activities, working closely with business and solution owners to strengthen security governance, support audit readiness, and drive continual improvement.
Key Responsibilities
Customer and Stakeholder Assurance
- Manage the Security Advisory process, including completion of due diligence questionnaires, requests for information, and general information security queries from customers, prospects, partners, and customer-facing colleagues.
- Provide practical information security and compliance advice to colleagues, projects, solution owners, and business stakeholders, escalating material risks where appropriate.
Risk, Supplier Assurance, and Business Continuity
- Conduct and support third-party information security risk assessments and periodic supplier reviews, documenting findings, risks, recommendations, and follow-up actions.
- Maintain the information security risk register, coordinate periodic risk reviews, monitor treatment actions, and support the CISO and risk owners in recording clear, proportionate, and current risk information.
- Support business continuity activities, including assisting business owners with the completion and review of Business Impact Analyses and tracking related actions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Audit and Corrective Action Management
- Plan, coordinate, and perform internal information security audits, record audit evidence and findings, and monitor agreed corrective actions and opportunities for improvement.
- Support external audits and assurance activities by coordinating evidence, engaging relevant control owners, and responding to auditor queries.
- Agree appropriate corrective actions and implementation dates with control owners, and proactively support delivery to ensure agreed timelines are achieved.
Compliance Initiatives and Awareness
- Develop appropriate security training and communications that promote a positive information security culture.
- Manage assigned compliance initiatives and improvement activities, maintaining clear plans, priorities, dependencies, and stakeholder communications.
Experience and Technical Knowledge
- Minimum of two years’ experience working in information security or security compliance.
- Strong knowledge of recognized information security control frameworks and assurance standards, such as ISO/IEC 27002, PCI DSS, the NIST Cybersecurity Framework, and ISAE standards.
- Practical experience of information security risk management, including risk identification, assessment, treatment, monitoring, and reporting.
- Experience supporting internal or external audits, evidence collection, control testing, and remediation tracking.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Skills and Qualifications
Communication and Stakeholder Engagement
- Strong written and verbal communication skills, with the ability to explain security and compliance requirements clearly to technical and non-technical audiences.
- Strong influencing and stakeholder management skills, with the confidence to provide constructive challenge and secure commitment to agreed actions.
Planning, Organisation, and Working Style
- Effective project management and organizational skills, with the ability to manage competing priorities, actions, and stakeholders.
- A structured, detail-focused, and improvement-oriented approach, with sound judgement and the ability to work both independently and collaboratively.
Professional Qualifications
- Relevant professional certification or training in information security, audit, risk, or compliance is desirable.
- Experience with AI tools, frameworks, or applications is considered a strong asset. We highly value candidates who demonstrate curiosity, a proactive mindset, and a willingness to explore and incorporate AI-driven technologies into their work. We encourage growth in this area and provide opportunities for experimentation and learning.
Why Basware?
We’re a purpose-driven company with a global footprint and a collaborative culture. At Basware, you’ll work with passionate professionals, cutting-edge technology, and a shared commitment to innovation and excellence.
Ready to Make an Impact?
If you're excited by the challenge, apply now and help shape the future of Basware.
Please submit your resume and cover letter by clicking the ‘I’m interested’ link.
Our recruitment process will include pre-employment actions such as enhanced background screening and reference check.
Basware. Now it all just happens.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London