# Senior GRC Engineer at ICEYE

ICEYE is hiring a Senior GRC Engineer for a remote role open to applicants in Finland. Level rates it Little AI ●○○○; you can [apply on Level](https://jobsbylevel.com/go/f21c298c-336c-4513-a6cb-184d714600e8).

AI Level 1, AI centrality 37 out of 100. Remote (Espoo).

## Details

- Company: [ICEYE](https://jobsbylevel.com/companies/iceye)
- AI level: AI Level 1 (score 37 out of 100)
- Location: Remote (Espoo)
- Posted: August 6, 2026
- Apply: https://jobsbylevel.com/go/f21c298c-336c-4513-a6cb-184d714600e8

## Description

Role highlights: Senior GRC Engineer Location: Espoo, Finland Department: Product Security Reports to: VP Product Security Employment type: Permanent Workplace model: Hybrid Employment is subject to applicable security screening (incl. SUPO, where required) Why this role matters: As the Staff GRC Engineer, you'll own and mature ICEYE's Security Governance, Risk and Compliance program across a multi-country, multi-regulator footprint, including Finland, Germany, Spain, Poland, the UK and Greece amongst others. ICEYE operates at the intersection of commercial space technology and sovereign defence, so our compliance posture (ISO 27001, NIS2, NIST, and national frameworks) has to be credible to customers who include governments and defence agencies. You'll be the person who keeps that posture accurate, current and audit-ready, maps client and national requirements to internal ICEYE requirements, as a senior individual contributor. This role will be working closely with all the ICEYE Security team domains, ICEYE IT, ICEYE product management and the Program Management Office, Engineering and Sales. Who We Are ICEYE is the world leader in sovereign intelligence from space. We deliver persistent monitoring capabilities to detect and respond to changes in any location on Earth. ICEYE owns the world's largest and most advanced SAR (synthetic aperture radar) satellite constellation. To our customers we provide intelligence with unmatched quality, latency and revisit times, in any weather, day or night. To governments who choose to operate their own constellation we provide this proven capability as a sovereign system. ICEYE-built constellations serve customers in defence and intelligence, environmental monitoring, insurance and emergency management. We enable fast decisions that contribute to a safer future. Founded and headquartered in Finland, ICEYE operates globally with over 1000 employees across Europe, North America, the Middle East, and Asia-Pacific. Your day-to-day responsibilities Ensure clients’ and their national security requirements are at all times clearly translated accurately to ICEYE internal requirements across product, IT, and other ICEYE functions, and we can clearly communicate those towards existing and new clients. Ensure ICEYE has evidence of fulfilling and complying with the requirements, preferably as compliance-as-code whenever possible. Support ICEYE’s Product, the Missions business line, PMO and Sales on client requirements. Produce material to support accreditation and acceptance requirements. Own and continuously improve ICEYE's ISO 27001 ISMS, including risk assessments, the risk register, Statement of Applicability, internal audits and certification/surveillance audit cycles. Track and operationalise NIS2, CRA and other EU product security obligations across ICEYE's in-scope entities, translating regulatory requirements into concrete policies, controls and evidence. Run third-party and vendor security risk assessments. Prepare clear, concise compliance and risk reporting for senior leadership, including status against certifications, audits and remediation plans. Own and maintain information security policies, standards and supporting documentation, ensuring they stay practical and enforceable rather than shelfware. Act as a day-to-day point of contact for external auditors, certification bodies and regulators on GRC matters. What we’re looking for Must haves: Eligible for being cleared for a Personal Security Clearance as necessary as well as a citizenship or a permanent residency in the European Union. Technical skills that allow you to interpret compliance requirements towards the product function; this includes being able to fluently discuss modern software architecture and development, deployment and release concepts. Proven hands-on experience running ISO 27001 (implementation, internal audit, or certification maintenance) in a real organisation, not just theoretical knowledge or external auditing

The description is cut here. Read the full offer: https://jobsbylevel.com/jobs/senior-grc-engineer-at-iceye-823882

Source: https://jobsbylevel.com/jobs/senior-grc-engineer-at-iceye-823882

## Cite this page

Level. https://jobsbylevel.com/jobs/senior-grc-engineer-at-iceye-823882.

Get job alerts: https://jobsbylevel.com/newsletter
