The role
BRAIN++ is looking for an Information Security and Risk Manager to build and manage the security, risk, and compliance framework of the AI Factory environment. The role focuses on ISO/IEC 27001, ISO 9001, incident management, and operational controls for AI services and shared infrastructure.
Responsibilities
- Build and maintain an Information Security Management System aligned with ISO/IEC 27001.
- Support the development of a Quality Management System aligned with ISO 9001.
- Maintain policies, procedures, risk registers, incident registers, and governance documentation.
- Coordinate risk management, incident response, internal audits, management reviews, evidence collection, and external-audit readiness.
- Work with technical and operational teams on onboarding, access management, data handling, and service-delivery controls.
- Maintain alignment with GDPR, the EU AI Act, and internal BRAIN++ governance requirements.
Requirements
- University degree in a relevant field.
- At least five years of relevant professional experience.
- Hands-on ISO/IEC 27001 implementation, controls, documentation, and audit-preparation experience.
- Understanding of ISO 9001, GDPR, access control, audit trails, and evidence retention.
- Very good written and spoken English.
- A valid CISM certification is mandatory.
Strong advantages
- ISO/IEC 27001 Lead Implementer or Lead Auditor qualification.
- Experience with ISO 9001, AI governance, HPC, cloud, data services, the EU AI Act, NIS2, or European projects.
What we offer
- A role with practical influence over secure and governed AI services for Bulgaria and the EU.
- A flexible working environment, competitive remuneration, and opportunities for professional development.
How to apply
Send your CV and a short motivation letter to office@sofiatech.bg. Briefly describe your experience with ISO/IEC 27001, risk management, and incident management, and confirm that you hold a valid CISM certification.