Principal Information Security Manager

Posted 11 hours ago

This is a fully remote position, open to applicants in Germany.

📋 Description

• Act as the senior deputy for Information Security within the Finance & Operations division.

• Oversee the daily operations of the InfoSec function and represent it both internally and externally.

• Report directly to the Senior Vice President of Business Operations & Transformation.

• Collaborate with Legal, Procurement, Engineering, external auditors, and enterprise clients.

• Lead the complete ISO 27001 and SOC 2 audit cycles, including preparation, evidence gathering, auditor coordination, and remediation of findings.

• Own and manage the control framework.

• Prepare the InfoSec program for investor and M&A due diligence processes.

• Handle responses to enterprise customer security questionnaires and Requests for Proposals (RFPs).

• Represent Staffbase in customer security reviews, calls, and audits.

• Develop scalable automation, templates, and knowledge bases to enhance response efficiency.

• Maintain the risk register and drive decisions related to risk treatment.

• Conduct vendor security assessments for critical and high-risk suppliers.

• Collaborate with Procurement and Legal on AI-assisted review workflows.

• Own and enforce the internal security policy framework.

• Design and implement behavior-changing security awareness initiatives.

• Own the incident response plan and lead its execution during incidents.

• Coordinate with Engineering, Legal, and leadership during incidents.

• Facilitate post-incident reviews and ensure findings are addressed with the responsible parties.


⛳️ Requirements

• A minimum of 5 years of hands-on InfoSec experience in a SaaS or B2B technology company.

• Demonstrated ownership of ISO 27001 and/or SOC 2 programs.

• Proven ability to represent InfoSec to enterprise clients, including handling security reviews and escalations.

• Proficiency in English is required.

• Comfortable utilizing AI-driven tools and actively seeking opportunities for automation in compliance and operations.

• Experience in supporting or preparing for M&A or investor due diligence processes is highly desirable.

• Background working closely with Legal, Procurement, and Engineering is highly desirable.

• Practical knowledge of cloud security architecture is highly desirable.

• Relevant certifications such as CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent are highly desirable.


🏝️ Benefits

• Competitive salary packages including Long Term Incentive Plans (LTIP) based on units.

• Flexible working time arrangements.

• Option for hybrid work.

• Annual flexible work allowance of €1560.

• 31 vacation days per year, including one floating holiday.

• Pro-rata fully paid Fridays off during August.

• Company pension scheme.

• One paid Volunteer Day per year for supporting a social project.

People also viewed

CrowdStrike9 hours ago

Regional Sales Director, Cloud Security

AU flagAustralia, +1 more countryFull-timeCybersecurity / Security Engineer
ApplyView job
Triumph Enterprises, Inc.9 hours ago

Configuration Management and Documentation Specialist – Federal Cybersecurity

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
LaunchDarkly11 hours ago

Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$116k – $159.5k/year
ApplyView job
Comcast11 hours ago

DevSecOps Engineer, Security Compliance

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
AECOM11 hours ago

Transit Safety Security Specialist

US flagNew Mexico OnlyFull-timeCybersecurity / Security Engineer$100k – $150k/year
ApplyView job
AECOM11 hours ago

Transit Safety Security Specialist V

US flagNew Mexico OnlyFull-timeCybersecurity / Security Engineer$110k – $160k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers