Information Security & Compliance Manager

Salary Competitive

Information Security & Compliance Manager


About Teton

Teton is building the foundational data layer for the point of care - using real-time, multimodal AI to generate a digital twin of the resident and care environment. Our proprietary computer vision system enables staff to automate documentation, proactively manage resident acuity, and streamline workflows across entire facilities. From assisted living communities to hospital wards, our system delivers unprecedented access to real-time data insights, empowering providers with actionable intelligence to enhance decision-making and elevate care delivery.

This is our first dedicated hire for information security and GRC, and a rare opportunity to build a scalable function from the ground up as Teton grows its footprint with care providers, hospital trusts, and enterprise partners across Denmark, the UK, and the US.


Role Overview

We're looking for an Information Security & Compliance Manager to take ownership of Teton's information security and GRC function - our ISMS, our certifications, our security assurance towards customers, and the tooling that holds it all together. Today this work sits with our compliance function alongside regulatory affairs, privacy, and AI governance. Your job is to take the security and GRC cluster, run it, and build it into a scalable function.

You will work closely with our compliance lead (who retains regulatory, privacy, and AI governance ownership), our engineering team, and directly with customers' security teams. This is not a role for someone who wants to produce spreadsheets by hand. We run our compliance program on modern tooling (Vanta and others) and expect you to operate AI-assisted workflows aggressively - automating evidence collection, using AI to draft questionnaire responses and policy updates, and reserving your own time for the judgment calls that tooling cannot make. The ideal candidate is excited about automating the routine parts of their own job.


What You'll Do

  • Own our ISMS and ISO 27001 program - drive us through initial certification and own the ongoing operation: risk assessments, control implementation, internal audits, management reviews, and the certification audit cycle.

  • Run our compliance platform - administer and continuously improve our Vanta implementation: integrations, automated tests, evidence collection, policy management, and its AI capabilities.

  • Own customer security assurance - manage security questionnaires, customer audits, and due diligence requests from care providers, hospital trusts, and enterprise partners in Denmark, the UK, and the US.

  • Build a trust center and reusable assurance package that scales.

  • Drive UK security certifications and evidence - own Cyber Essentials (and Cyber Essentials Plus readiness) and support the technical evidence base for NHS requirements such as DTAC and clinical safety documentation.

  • Coordinate IT security operations - work with engineering and IT on access management, endpoint security, vendor security reviews, incident response processes, and security awareness across the company.

  • Prepare us for what is coming - support readiness for NIS2, the Cyber Resilience Act, and the security expectations that follow from medical device and AI regulation, in partnership with the compliance lead.

  • Own security risk management - maintain the risk register, prepare risk acceptance decisions for leadership, and make sure security risk is understood and owned at the right level.


What You'll Need

  • 3-6 years of experience in information security, GRC, or IT compliance, ideally including at least one ISO 27001 implementation or certification cycle from the inside.

  • Hands-on experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar) and a genuine interest in running a security program through tooling rather than around it.

  • Solid technical literacy: you can read an architecture diagram, discuss cloud security controls with engineers, and evaluate a vendor's security posture without needing a translator.

  • A real understanding of, and interest in, the digital compliance landscape: you know why GDPR Article 32 matters to an ISMS, what NIS2 and the CRA are about to change, and how security evidence feeds regulatory frameworks in healthcare.

  • Strong written English; you will produce customer-facing security documentation. Danish is a plus but not a requirement.

Comfort with ambiguity and ownership. You will be the person for this domain, supported but not supervised in the day-to-day.


What It's Like Working at Teton

We're a growing team of extremely hard-working and talented people. The learning curves are steep, and expanding your skill set is not just encouraged - it's expected. It's a hands-on environment where you'll be challenged, supported, and constantly learning.

We are looking for people who believe in our long-term vision and value ownership and entrepreneurship rather than just another 9-5 job. With us you will have an opportunity to truly make an impact on the world with the outcomes of your work. So, if you are looking for a ride and not just a job - jump on board 😊

Perks and benefits

This job comes with several perks and benefits

Free lunch
Free lunch

Free coffee / tea
Free coffee / tea

Free office snacks
Free office snacks

Social gatherings
Social gatherings

Near public transit
Near public transit

Skill development
Skill development

See all 10 benefits

Working at
Teton

Teton is a fast-growing and well-funded healthcare startup, with a mission to introduce an intelligent assistant to health professionals around the world. We are assembling an ambitious and hardworking team with one goal in mind - to empower Health professionals and elevate patient care using cutting-edge deep learning and computer vision.

Read more about Teton

company gallery image