Our client is a Swiss AI scale-up. Its platform watches manufacturing lines through cameras; AI agents flag jams, breakages, quality defects and safety events in real time and can trigger actions on line equipment. It is live in plants across 18+ countries — glass, food and beverage, consumer goods, building materials and wood. The product sits inside customers’ industrial networks, connects to their machines and processes footage in which plant staff appear, so security and privacy come up in every sale. You will be the person who makes that answer solid — hands-on, from the first week.
Information Security Lead (OT Security, Video Data Privacy & SOC 2)
Your responsibilities:
- Define how cameras, on-site devices and equipment integrations connect into customer OT networks — including the paths that send commands to machines: segmentation, firewall rules, outbound-only cloud connectivity, secure remote access, hardening and patching.
- Be the security voice with customers’ IT, OT and security teams — questionnaires, architecture reviews, network requirement documents and calls.
- Lead SOC 2, building on the existing ISO 27001-aligned security programme: gap assessment, controls mapped to the Trust Services Criteria, policies, evidence collection, and the work with the auditor and compliance tooling.
- Own privacy for video and image data: DPIAs, data-flow maps, retention and deletion, access control, rules for footage used to train AI models, and evidence that the platform’s anonymisation of people holds up — plus customer-facing documents (DPA, sub-processor list, technical and organisational measures).
- Help customers through workplace-camera rules — works councils and national employee-monitoring law.
- Own the security risk register, vendor risk and incident-response plan; advise engineering on the controls SOC 2 needs in cloud and development practice.
We are looking for you, if you have:
We don’t expect equal depth in all three areas — strong in two and credible in the third is the profile.
- 6+ years in information security, including hands-on implementation: you have built and run controls, not only assessed them.
- SOC 2 — took a product or SaaS company through a SOC 2 audit (Type I or II) in a hands-on role, ideally extending an existing ISO 27001 programme. Hands-on ISO 27001 implementation plus a clear grasp of what SOC 2 adds is a close substitute.
- OT / industrial network security — segmentation of plant or utility networks, zones and conduits or the Purdue model, IEC 62443, secure remote access, and securing third-party systems that signal or command PLCs and line equipment.
- Data privacy — GDPR in practice: DPIAs and privacy by design on real systems, ideally video, CCTV or other sensor data — including anonymisation and the use of personal data to train AI models.
- English at C1 — you write policies and customer-facing security documentation and hold your own with enterprise security teams.
- Pragmatic and independent; comfortable in a young company that needs results quickly.
Nice to have
- German.
- Certifications: CISSP, CISM, CISA, GICSP, ISA/IEC 62443, ISO 27001 Lead Implementer or Lead Auditor, CIPP/E.
- Swiss revFADP, NIS2, EU AI Act.
- Vanta, Drata or Secureframe.
- Cloud security on AWS, GCP or Azure; containers and Kubernetes.
- Background in manufacturing, machine vision, IIoT or video-surveillance products.
We offer:
- Participation in interesting and demanding projects.
- Flexible working hours.
- A great, non-corporate atmosphere.
- Possibility to work remote or hybrid (2 days per week from the office).
- Opportunities for development and promotion.
- Attractive package of benefits.
We reserve the right to contact the selected candidates.