BRAIN++ careers

Information Security and Risk Manager

Lead security, risk, compliance, and audit readiness for the BRAIN++ AI Factory. Applications close on 30 September 2026.

Full time On-site Sofia Tech Park, Sofia, Bulgaria Open until September 30, 2026

The role

BRAIN++ is looking for an Information Security and Risk Manager to build and manage the security, risk, and compliance framework of the AI Factory environment. The role focuses on ISO/IEC 27001, ISO 9001, incident management, and operational controls for AI services and shared infrastructure.

Responsibilities

  • Build and maintain an Information Security Management System aligned with ISO/IEC 27001.
  • Support the development of a Quality Management System aligned with ISO 9001.
  • Maintain policies, procedures, risk registers, incident registers, and governance documentation.
  • Coordinate risk management, incident response, internal audits, management reviews, evidence collection, and external-audit readiness.
  • Work with technical and operational teams on onboarding, access management, data handling, and service-delivery controls.
  • Maintain alignment with GDPR, the EU AI Act, and internal BRAIN++ governance requirements.

Requirements

  • University degree in a relevant field.
  • At least five years of relevant professional experience.
  • Hands-on ISO/IEC 27001 implementation, controls, documentation, and audit-preparation experience.
  • Understanding of ISO 9001, GDPR, access control, audit trails, and evidence retention.
  • Very good written and spoken English.
  • A valid CISM certification is mandatory.

Strong advantages

  • ISO/IEC 27001 Lead Implementer or Lead Auditor qualification.
  • Experience with ISO 9001, AI governance, HPC, cloud, data services, the EU AI Act, NIS2, or European projects.

What we offer

  • A role with practical influence over secure and governed AI services for Bulgaria and the EU.
  • A flexible working environment, competitive remuneration, and opportunities for professional development.

How to apply

Send your CV and a short motivation letter to office@sofiatech.bg. Briefly describe your experience with ISO/IEC 27001, risk management, and incident management, and confirm that you hold a valid CISM certification.