hirly

Iceye

Staff GRC Engineer

Espoo

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Iceye first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Lead / management
Country
FI
Work mode
On-site / unstated
First seen by hirly
1 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Role highlights:

Staff GRC Engineer

Location: Espoo, Finland

Department: Product Security

Reports to: VP Product Security

Employment type: Permanent

Workplace model: Hybrid

Employment is subject to applicable security screening (incl. SUPO, where required)

Why this role matters:

As the Staff GRC Engineer, you'll own and mature ICEYE's Security Governance, Risk and Compliance program across a multi-country, multi-regulator footprint, including Finland, Germany, Spain, Poland, the UK and Greece amongst others. ICEYE operates at the intersection of commercial space technology and sovereign defence, so our compliance posture (ISO 27001, NIS2, NIST, and national frameworks) has to be credible to customers who include governments and defence agencies. You'll be the person who keeps that posture accurate, current and audit-ready, maps client and national requirements to internal ICEYE requirements, as a senior individual contributor. This role will be working closely with all the ICEYE Security team domains, ICEYE IT, ICEYE product management and the Program Management Office, Engineering and Sales.

Who We Are

ICEYE is the world leader in sovereign intelligence from space. We deliver persistent monitoring capabilities to detect and respond to changes in any location on Earth.

ICEYE owns the world's largest and most advanced SAR (synthetic aperture radar) satellite constellation. To our customers we provide intelligence with unmatched quality, latency and revisit times, in any weather, day or night. To governments who choose to operate their own constellation we provide this proven capability as a sovereign system.

ICEYE-built constellations serve customers in defence and intelligence, environmental monitoring, insurance and emergency management. We enable fast decisions that contribute to a safer future.

Founded and headquartered in Finland, ICEYE operates globally with over 1000 employees across Europe, North America, the Middle East, and Asia-Pacific.

Your day-to-day responsibilities

Ensure clients’ and their national security requirements are at all times clearly translated accurately to ICEYE internal requirements across product, IT, and other ICEYE functions, and we can clearly communicate those towards existing and new clients.

Ensure ICEYE has evidence of fulfilling and complying with the requirements, preferably as compliance-as-code whenever possible.

Support ICEYE’s Product, the Missions business line, PMO and Sales on client requirements. Produce material to support accreditation and acceptance requirements.

Own and continuously improve ICEYE's ISO 27001 ISMS, including risk assessments, the risk register, Statement of Applicability, internal audits and certification/surveillance audit cycles.

Track and operationalise NIS2, CRA and other EU product security obligations across ICEYE's in-scope entities, translating regulatory requirements into concrete policies, controls and evidence.

Run third-party and vendor security risk assessments.

Prepare clear, concise compliance and risk reporting for senior leadership, including status against certifications, audits and remediation plans.

Own and maintain information security policies, standards and supporting documentation, ensuring they stay practical and enforceable rather than shelfware.

Act as a day-to-day point of contact for external auditors, certification bodies and regulators on GRC matters.

What we’re looking for

Must haves:

Eligible for being cleared for a Personal Security Clearance as necessary as well as a citizenship or a permanent residency in the European Union.

Technical skills that allow you to interpret compliance requirements towards the product function; this includes being able to fluently discuss modern software architecture and development, deployment and release concepts.

Proven hands-on experience running ISO 27001 (implementation, internal audit, or certification maintenance) in a real organisation, not just theoretical knowledge or external auditing experience.

Working knowledge of NIS2, CRA, and how their obligations translate into practical controls and reporting.

Strong stakeholder management skills, with the ability to influence product management, engineering, IT, legal and leadership without formal authority.

Experience building or maintaining a risk register and running quantified risk assessments.

Comfortable operating independently across multiple countries and regulatory regimes.

Awareness of emerging AI governance frameworks (ISO 42001, NIST AI Risk Management Framework, EU AI Act) as well as NIST frameworks

Nice to haves:

Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor.

Experience in defence, space, aerospace or another regulated/sovereign-sensitive industry.

Exposure to classified information handling frameworks (EUCI, NATO equivalents, or national security clearance regimes).

A well-rounded skillset of using language models for automation.

Application Process

Initial screening call with Talent Acquisition

Technical/competency interview with the VP Product Security

Scenario-based exercise on requirements discovery, mapping and prioritisation

Final interview with senior stakeholders including a behavioural interview

Working at ICEYE

At ICEYE, you’ll join a diverse and highly engaged team united by the ambition to make the impossible possible. As a global scale-up, we combine speed and ambition with the opportunity to take real ownership from day one. Your growth, wellbeing, and success are a priority, with continuous professional development, training opportunities, and a culture where collaboration is how we win.

How We Work (Our Values)

Make the impossible possible : We set ambitious goals and stay calm under pressure. We bring grit, optimism, and ownership when things get hard, and we keep moving until we find a way.

Be curious : Go deep, ask questions, listen carefully, and think critically. Understand the “why” behind decisions.

See the big picture: Stay close to what’s happening across the company so you can make better decisions. Consider how your work affects others.

Drive effective teamwork: Create psychological safety, invite different perspectives, and build inclusive teams. There are no bad questions.

Act as one team: We win together. We match tasks to the right owner and stay agile as priorities shift.

Have fun : What we do matters—and it should be enjoyable. Celebrate progress, take pride in results, and share the wins.

Benefits

Our benefits are designed to support your health and wellbeing, at work and beyond. We keep improving them based on employee feedback, and offerings vary by location. Talent Acquisition will confirm what applies for this role and location during the process.

Our Commitment to Diversity, Equity, and Inclusion

We want ICEYE to be a place where people can be themselves and do great work. Different backgrounds and perspectives make us stronger, which is why we work to create an environment where people feel included, respected, and able to speak up. Whatever your background, we want you to bring your authentic self to the table.

We’re committed to fair, inclusive hiring and equal opportunity. Everyone is welcome to apply. If you need any adjustments or support during the recruitment process, tell us—we’ll do our best to help.

Apply now to start your ICEYE journey, and help us continue to make the impossible possible together. Read more about ICEYE and working with us at iceye.com .

Original posting on Iceye's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job