Your personal AI career agent
Principle Information Security Manager(m/w/x)
Leading ISO 27001 and SOC 2 audit cycles for a SaaS employee experience platform. Proven ownership of audit programs required. Flexible working hours, hybrid option, and yearly flex work allowance.
Requirements
- 5+ years InfoSec experience in SaaS/B2B tech
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Representing InfoSec to enterprise customers
- Fluent in German and English
- Comfortable with AI-driven tooling and automation
- Experience supporting M&A or investor due diligence
- Background working with Legal, Procurement, Engineering
- Practical understanding of cloud security architecture
- Relevant certification: CISM, CISSP, ISO 27001
Tasks
- Lead ISO 27001 and SOC 2 audit cycles
- Prepare and manage audit evidence collection
- Manage auditor relationships and findings remediation
- Maintain and update the control framework
- Prepare InfoSec program for investor and M&A due diligence
- Respond to enterprise customer security questionnaires and RFPs
- Represent Staffbase in customer security reviews and audits
- Develop scalable approaches for security responses
- Maintain the risk register and drive risk treatment
- Conduct vendor security assessments for critical suppliers
- Partner with Procurement and Legal on AI-assisted reviews
- Own and update the internal security policy framework
- Design and implement security awareness programs
- Lead the incident response plan execution
- Coordinate with Engineering, Legal, and leadership during incidents
- Conduct post-incident reviews and close findings
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Business Fluent
- English – Business Fluent
Tools & Technologies
- ISO 27001
- SOC 2
- AI-driven tooling
- cloud security architecture
- CISM
- CISSP
Benefits
Flexible Working
- Flexible working time models
- Hybrid work option
- Yearly flex work allowance
Competitive Pay
- Attractive salary packages
- LTIP
More Vacation Days
- 31 vacation days annually
- Floating holiday
- Pro rata fully paid Fridays off during August
Retirement Plans
- Company pension scheme
Purpose-Driven Work
- One day off per year for supporting a social project
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
Not a perfect match?
- StaffbaseFull-timeWith HomeofficeSeniorChemnitz, Berlin
- Shiftmove
(Senior) Information Security Officer(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - getolo GmbH
Information Security Lead - German Speaker(m/w/x)
Full-timeWith HomeofficeSeniorBerlin - Seven Education
Chief Information Security Officer (CISO)(m/w/x)
Full-timeWith HomeofficeSeniorHamburg, Berlin, Koblenz - Moss
Information Security GRC Lead(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin
Principle Information Security Manager(m/w/x)
Leading ISO 27001 and SOC 2 audit cycles for a SaaS employee experience platform. Proven ownership of audit programs required. Flexible working hours, hybrid option, and yearly flex work allowance.
Requirements
- 5+ years InfoSec experience in SaaS/B2B tech
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Representing InfoSec to enterprise customers
- Fluent in German and English
- Comfortable with AI-driven tooling and automation
- Experience supporting M&A or investor due diligence
- Background working with Legal, Procurement, Engineering
- Practical understanding of cloud security architecture
- Relevant certification: CISM, CISSP, ISO 27001
Tasks
- Lead ISO 27001 and SOC 2 audit cycles
- Prepare and manage audit evidence collection
- Manage auditor relationships and findings remediation
- Maintain and update the control framework
- Prepare InfoSec program for investor and M&A due diligence
- Respond to enterprise customer security questionnaires and RFPs
- Represent Staffbase in customer security reviews and audits
- Develop scalable approaches for security responses
- Maintain the risk register and drive risk treatment
- Conduct vendor security assessments for critical suppliers
- Partner with Procurement and Legal on AI-assisted reviews
- Own and update the internal security policy framework
- Design and implement security awareness programs
- Lead the incident response plan execution
- Coordinate with Engineering, Legal, and leadership during incidents
- Conduct post-incident reviews and close findings
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Business Fluent
- English – Business Fluent
Tools & Technologies
- ISO 27001
- SOC 2
- AI-driven tooling
- cloud security architecture
- CISM
- CISSP
Benefits
Flexible Working
- Flexible working time models
- Hybrid work option
- Yearly flex work allowance
Competitive Pay
- Attractive salary packages
- LTIP
More Vacation Days
- 31 vacation days annually
- Floating holiday
- Pro rata fully paid Fridays off during August
Retirement Plans
- Company pension scheme
Purpose-Driven Work
- One day off per year for supporting a social project
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
About the Company
Staffbase
Industry
IT
Description
The company helps organizations unlock the power of inspirational communication with an AI-native Employee Experience Platform.
Not a perfect match?
- Staffbase
Principal Information Security Manager(m/w/x)
Full-timeWith HomeofficeSeniorChemnitz, Berlin - Shiftmove
(Senior) Information Security Officer(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - getolo GmbH
Information Security Lead - German Speaker(m/w/x)
Full-timeWith HomeofficeSeniorBerlin - Seven Education
Chief Information Security Officer (CISO)(m/w/x)
Full-timeWith HomeofficeSeniorHamburg, Berlin, Koblenz - Moss
Information Security GRC Lead(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin