Security & AI Governance Lead
Paligo is hiring a Security & AI Governance Lead to own two things: the security management system our enterprise customers rely on, and the governance of how AI gets built and used across our platform. Customers in 38 countries trust Paligo with their most critical content, and this role exists to keep that trust earned as we become the grounding layer enterprise AI runs on.
About Paligo
Paligo is an industry-leading SaaS company in the component content management system (CCMS) space. Global teams at Amazon, Allianz, Mitsubishi, and the European Commission use our platform to create, manage, publish, and translate technical content.
We built a documentation authoring tool that enterprises run on. Now those enterprises are trying to put AI on top of their content and finding they can't trust the answers. Our bet is that structured content is what fixes that, and we're building the grounding layer to prove it.
About the role
You'll own our Information Security Management System (ISMS) under ISO/IEC 27001:2022: audits and evidence, risk assessments, policies, awareness training, and the security questions our enterprise customers ask us every week.
The second half of the job is AI governance. We're building AI into the product and using it across the company, which brings the EU AI Act, ISO/IEC 42001, and detailed customer requirements about how their content is handled into your scope. You'll shape how we meet them.
Every role at Paligo is expected to automate the repetitive parts of its own job, and security has more of them than most. The expectation is that you build it down: work you do by hand this year should be running without you the next, with you on the judgment calls instead.
You'll report to our Head of Platform Engineering, who sets security strategy with you and backs you with the mandate to get things done. At a company of under 100 people, that means hands-on work and real visibility from day one. It also means room to grow — this role is built to expand as your experience does, and as Paligo does.
What you'll do
Keep our ISO 27001 ISMS running and improving: documentation, internal audits, evidence collection, and preparation for external audits.
Maintain the risk register and run risk assessments across our platform and AI infrastructure.
Own how Paligo governs AI: internal acceptable use, plus the controls, documentation, and customer commitments around AI in the product. Track the EU AI Act and ISO/IEC 42001 and translate them into controls we run.
Lead security reviews of our AI grounding infrastructure and data pipelines together with engineering.
Secure our external AI offerings, including MCPs and APIs for autonomous agents, with a focus on data exposure and access control.
Answer customer security questionnaires and due diligence requests and run vendor risk reviews, then get them off your desk: build the evidence pipelines and agent workflows that draft them, and keep yourself on judgment and sign-off.
Support GDPR and contractual compliance work alongside Legal and product teams.
Coordinate incident response and business continuity testing, and keep both plans current.
Run security awareness training and build a security culture people actually engage with.
Report on ISMS performance and open risks to engineering and company leadership.
What we're looking for
Required
2+ years of experience in information security, risk, or compliance, preferably at a SaaS or technology company.
Hands-on experience working inside an ISO 27001 ISMS: audits, evidence, risk assessments, and policy maintenance.
Working knowledge of cloud security in AWS, Azure, or GCP.
A bias for automating your own work. You should already reach for scripts, APIs, and AI tools before doing something by hand for the tenth time.
The ability to translate security requirements for engineers and non-technical colleagues alike, and the confidence to hold the line when it matters.
A degree in computer science, information technology, information security, or a related field — or equivalent practical experience.
Professional fluency in English.
Nice to have
Exposure to compliance frameworks such as SOC 2, NIST CSF, PCI DSS, CCPA, or HIPAA.
Experience with GDPR, and familiarity with the EU AI Act, ISO/IEC 42001, or the NIST AI Risk Management Framework.
Experience building automation into a GRC function: evidence pipelines, questionnaire tooling, or agent workflows.
Experience handling enterprise customer security questionnaires and vendor risk reviews.
Familiarity with securing AI integrations via MCP and APIs.
Prior exposure to a CCMS or similar content- and data-heavy platforms.
Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CompTIA Security+, or progress toward CISM or CISSP.
What we offer
Real ownership: you run the ISMS and own AI governance.
A mandate to automate your own job. We'd rather you build the tool than grind the task.
A front-row seat as we build the grounding layer, where security is part of what customers buy.
Competitive benefits and flexible working hours.
A culture that takes work seriously and the rest of life seriously too.
The practical details
This is a hybrid position based out of our Stockholm office. Candidates must currently reside in Sweden and hold the legal right to work there. We are unable to sponsor work visas or offer relocation for this role.
The final step of our recruitment process is a mandatory background check, including a financial and criminal check. Any offer of employment is contingent on its successful completion.
Ready to talk?
If you want to own security and AI governance at Paligo, we'd like to hear from you.
- Department
- Tech
- Locations
- Solna
- Remote status
- Hybrid
About Paligo
Paligo is an end-to-end Component Content Management System (CCMS) solution for technical documentation, policies and procedures, knowledge management, and more.