Information Security & Compliance Manager
About Teton
Teton is building the foundational data layer for the point of care - using real-time, multimodal AI to generate a digital twin of the resident and care environment. Our proprietary computer vision system enables staff to automate documentation, proactively manage resident acuity, and streamline workflows across entire facilities. From assisted living communities to hospital wards, our system delivers unprecedented access to real-time data insights, empowering providers with actionable intelligence to enhance decision-making and elevate care delivery.
This is our first dedicated hire for information security and GRC, and a rare opportunity to build a scalable function from the ground up as Teton grows its footprint with care providers, hospital trusts, and enterprise partners across Denmark, the UK, and the US.
Role Overview
We're looking for an Information Security & Compliance Manager to take ownership of Teton's information security and GRC function - our ISMS, our certifications, our security assurance towards customers, and the tooling that holds it all together. Today this work sits with our compliance function alongside regulatory affairs, privacy, and AI governance. Your job is to take the security and GRC cluster, run it, and build it into a scalable function.
You will work closely with our compliance lead (who retains regulatory, privacy, and AI governance ownership), our engineering team, and directly with customers' security teams. This is not a role for someone who wants to produce spreadsheets by hand. We run our compliance program on modern tooling (Vanta and others) and expect you to operate AI-assisted workflows aggressively - automating evidence collection, using AI to draft questionnaire responses and policy updates, and reserving your own time for the judgment calls that tooling cannot make. The ideal candidate is excited about automating the routine parts of their own job.
What You'll Do
Own our ISMS and ISO 27001 program - drive us through initial certification and own the ongoing operation: risk assessments, control implementation, internal audits, management reviews, and the certification audit cycle.
Run our compliance platform - administer and continuously improve our Vanta implementation: integrations, automated tests, evidence collection, policy management, and its AI capabilities.
Own customer security assurance - manage security questionnaires, customer audits, and due diligence requests from care providers, hospital trusts, and enterprise partners in Denmark, the UK, and the US.
Build a trust center and reusable assurance package that scales.
Drive UK security certifications and evidence - own Cyber Essentials (and Cyber Essentials Plus readiness) and support the technical evidence base for NHS requirements such as DTAC and clinical safety documentation.
Coordinate IT security operations - work with engineering and IT on access management, endpoint security, vendor security reviews, incident response processes, and security awareness across the company.
Prepare us for what is coming - support readiness for NIS2, the Cyber Resilience Act, and the security expectations that follow from medical device and AI regulation, in partnership with the compliance lead.
Own security risk management - maintain the risk register, prepare risk acceptance decisions for leadership, and make sure security risk is understood and owned at the right level.
What You'll Need
3-6 years of experience in information security, GRC, or IT compliance, ideally including at least one ISO 27001 implementation or certification cycle from the inside.
Hands-on experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar) and a genuine interest in running a security program through tooling rather than around it.
Solid technical literacy: you can read an architecture diagram, discuss cloud security controls with engineers, and evaluate a vendor's security posture without needing a translator.
A real understanding of, and interest in, the digital compliance landscape: you know why GDPR Article 32 matters to an ISMS, what NIS2 and the CRA are about to change, and how security evidence feeds regulatory frameworks in healthcare.
Strong written English; you will produce customer-facing security documentation. Danish is a plus but not a requirement.
Comfort with ambiguity and ownership. You will be the person for this domain, supported but not supervised in the day-to-day.
What It's Like Working at Teton
We're a growing team of extremely hard-working and talented people. The learning curves are steep, and expanding your skill set is not just encouraged - it's expected. It's a hands-on environment where you'll be challenged, supported, and constantly learning.
We are looking for people who believe in our long-term vision and value ownership and entrepreneurship rather than just another 9-5 job. With us you will have an opportunity to truly make an impact on the world with the outcomes of your work. So, if you are looking for a ride and not just a job - jump on board

