Information Security Officer
Super is creating a new Information Security Officer position within the Cybersecurity team to own the company-wide security governance, policy and compliance agenda. This is a governance and compliance role, not a technical one. It owns security policies, drives security awareness and training, and ensures every team across the organisation knows what they must do to be compliant and follows through until it is done.
- Own and maintain the company-wide information security policy framework, ensuring it stays current, coherent and aligned with the business.
- Act as the internal authority on relevant standards and regulations (e.g. ISO 27001, GDPR).
- Update and drive the security compliance strategy, including operation of the GRC platform, ensuring policies are clear and effectively communicated across the organisation.
- Design and deliver security awareness and training programmes, tailored to different teams and tribes, so people understand their compliance obligations and how to meet them.
- Drive compliance adoption across all business units, validating that teams understand and complete the steps required, and establish escalations so gaps are surfaced and closed proactively.
- Track and report on policy exceptions and remediation progress.
- Own the PII compliance plan, including the programme to deprecate unencrypted PII.
- Produce reporting escalated to the Board and Risk Committee where necessary.
- Coordinate with external auditors and manage evidence collection for audits and certifications.
- Provide regular compliance reporting to leadership, the Board and the Risk Committee.
- Proven experience in information security governance, risk and compliance (GRC), ideally within a regulated, multi-market environment (required).
- Deep, practical knowledge of ISO 27001, GDPR and related security and data-protection standards (required).
- Experience owning security policy frameworks and running security awareness and training programmes (required).
- Hands-on experience operating a GRC platform and driving compliance across many teams (required).
- Track record of coordinating internal and external audits and managing audit evidence (required).
- Excellent stakeholder-management and communication skills, with the ability to influence and drive compliance without direct authority (required).
- Experience reporting to senior leadership, boards or risk committees (required).
- Relevant certifications (e.g. CISM, CISA, ISO 27001 Lead Implementer/Auditor, CISSP) (nice-to-have).
- Experience with data-protection and PII programmes (nice-to-have).
- Exposure to fast-scaling technology, gaming or fintech organisations (nice-to-have).
- Medical / Health Insurance
- Open Annual Leave
- Employee Assistance Programme
- Training & Learning Development
Superbet, which operates under the Super Technologies banner, is a multinational sports betting and gaming group founded in 2008 in Romania by Sacha Dragic. Headquartered in Bucharest, it began with retail betting shops and has grown into one of the leading omni-channel betting operators in Central and Eastern Europe, with a strong focus on digital products. The group employs more than 5,000 people and operates across around a dozen European markets as well as Brazil. Its offices span Romania, Poland, Serbia, the UK, the Netherlands, Belgium, Spain, Croatia, Brazil, Malta and Gibraltar.
