Information Security Project Manager

🏢 Linnworks
📍 Estonia
📅 Posted Sep 20, 2026 · via Himalayas
🏷 Infosec, Security Project Management, Compliance Management, It Audit, Security Governance, Information Security Project Manager +6 more
Apply on original site ↗

your mission

Job Title: Information Security Project Manager

Reports to: Director of Technical Operations
Location: UK / Estonia / US (remote-friendly within these regions)
Role purpose

The Information Security Project Manager is responsible for coordinating and driving the company’s information security activities in a pragmatic, commercially aware way.
This role exists to manage security-related projects, audits, and customer security interactions so that we stay compliant and credible without blocking sensible business decisions or over-engineering controls.
Scope and context

This role sits within the technology function and partners closely with Technical Operations, Engineering, Product, Legal, and Sales.
The focus is on governance, coordination, and communication, not on dictating policy in isolation or acting as the final decision-maker on security matters.
Final risk and tooling decisions sit with the Director of Technical Operations and the broader leadership team; the Information Security Project Manager’s job is to provide clear input, well-reasoned recommendations, and organised execution.

We are a growing SaaS business without PCI, PHI, or highly sensitive PII in scope, and we are not subject to HIPAA or classified/secret information regime – our security approach should be proportionate: strong, credible, and well-documented, but not theatrical or unnecessarily restrictive.
Key responsibilities
ISO 27001 and internal audits

-
Plan, coordinate, and execute internal audits and control reviews against ISO 27001 (and related frameworks where relevant).

-
Maintain audit schedules, evidence repositories, and action logs so that we are consistently “audit ready” rather than scrambling before assessments.

-
Work with control owners across the business to ensure that required processes are in place, understood, and operating in a pragmatic way.

-
Track findings and remediation actions, ensuring owners are clear on what needs to be done and by when, and following up to completion.

-
Support external ISO 27001 surveillance and recertification audits, including planning, evidence collation, and managing auditor queries.

Security projects and initiatives

-
Coordinate discrete security improvement projects (for example, rolling out new security tooling, tightening access controls, or updating key policies).

-
Break down security initiatives into clear tasks, owners, and timelines, and keep stakeholders informed on progress and risks.

-
Work with Technical Operations and Engineering to ensure technical changes are understood, documented, and reflected in our security posture.

-
Help prioritise security work by articulating risk, impact, and effort, while understanding the wider commercial and delivery context.

Customer security, RFPs and RFQs

-
Partner with Sales, Pre-Sales, and Customer Success to respond to customer security questionnaires, RFPs, RFQs, and due diligence requests.

-
Maintain and continuously improve a central library of standard security responses and artefacts (for example, summaries of our controls, certifications, and processes).

-
Coordinate input from Technical Operations, Engineering, and Legal where deeper technical or contractual responses are required.

-
Attend customer calls when needed to explain our security posture in clear, non-alarmist language and build confidence in our approach.

Security information and communication

-
Develop and maintain a clear, concise view of our security posture that can be communicated internally and to customers (for example, how we handle data, access, monitoring, and incident response at a high level).

-
Ensure that key facts (such as use of encryption at rest and in transit, SSO capabilities, backup approaches, and incident processes) are understood and kept up to date, even if technical details are owned by others.

-
Translate technical explanations from engineers into language suitable for non-technical audiences, in

Flights + hotels

This role requires you to be in Estonia. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Comparing Project Manager pay and openings — the live median is $92k?All remote Project Manager jobs →Project Manager salary data →
Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you