
Principal Information Security Manager
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Germany.
• Serve as the principal deputy for InfoSec within our Finance & Operations division, managing daily operations, representing the function both internally and externally, and enhancing efficiency and intelligence.
• Directly report to the SVP of Business Operations & Transformation, collaborating closely with Legal, Procurement, Engineering, external auditors, and enterprise clients.
• Oversee the complete ISO 27001 and SOC 2 audit processes, including preparation, evidence collection, auditor management, and remediation of findings.
• Manage the control framework, ensuring it remains up-to-date as the business progresses.
• Equip the InfoSec program for scrutiny during investor and M&A due diligence.
• Handle responses to enterprise customer security questionnaires and RFPs.
• Represent Staffbase effectively during customer security reviews, calls, and audits.
• Develop scalable methods (automation, templates, knowledge base) to decrease response times while maintaining quality.
• Maintain the risk register and facilitate risk treatment decisions with appropriate stakeholders.
• Conduct vendor security assessments for critical and high-risk suppliers.
• Manage the internal security policy framework, ensuring it is current, comprehensible, and enforced.
• Design and implement security awareness programs that drive behavioral change rather than merely fulfilling requirements.
• Oversee the incident response plan and lead the execution during incidents.
• Coordinate with Engineering, Legal, and leadership during incidents.
• Lead post-incident reviews and ensure findings are closed with the respective owners.
• At least 5 years of practical InfoSec experience in a SaaS or B2B technology organization.
• Demonstrated ownership of ISO 27001 and/or SOC 2 programs.
• Proven experience representing InfoSec to enterprise clients, including during security reviews and escalations.
• Fluency in both German and English is required.
• Comfortable utilizing AI-driven tools and proactively seeking automation opportunities in compliance and operations.
• Competitive Compensation - we provide attractive salary packages, including LTIP (unit-based Long Term Incentive Plan).
• Flexibility - we offer flexible working hours and hybrid work options, supported by a yearly flex work allowance of €1560.
• Recharge - enjoy 31 vacation days annually (including one floating holiday), plus pro rata fully paid Fridays off during August.
• Support - we provide a company pension scheme.
• Volunteers Day - you’ll receive one day off each year to support a social project.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.