
Principal Information Security Manager
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in Germany.
• Act as the senior deputy for Information Security within the Finance & Operations division.
• Oversee the daily operations of the InfoSec function and represent it both internally and externally.
• Report directly to the Senior Vice President of Business Operations & Transformation.
• Collaborate with Legal, Procurement, Engineering, external auditors, and enterprise clients.
• Lead the complete ISO 27001 and SOC 2 audit cycles, including preparation, evidence gathering, auditor coordination, and remediation of findings.
• Own and manage the control framework.
• Prepare the InfoSec program for investor and M&A due diligence processes.
• Handle responses to enterprise customer security questionnaires and Requests for Proposals (RFPs).
• Represent Staffbase in customer security reviews, calls, and audits.
• Develop scalable automation, templates, and knowledge bases to enhance response efficiency.
• Maintain the risk register and drive decisions related to risk treatment.
• Conduct vendor security assessments for critical and high-risk suppliers.
• Collaborate with Procurement and Legal on AI-assisted review workflows.
• Own and enforce the internal security policy framework.
• Design and implement behavior-changing security awareness initiatives.
• Own the incident response plan and lead its execution during incidents.
• Coordinate with Engineering, Legal, and leadership during incidents.
• Facilitate post-incident reviews and ensure findings are addressed with the responsible parties.
• A minimum of 5 years of hands-on InfoSec experience in a SaaS or B2B technology company.
• Demonstrated ownership of ISO 27001 and/or SOC 2 programs.
• Proven ability to represent InfoSec to enterprise clients, including handling security reviews and escalations.
• Proficiency in English is required.
• Comfortable utilizing AI-driven tools and actively seeking opportunities for automation in compliance and operations.
• Experience in supporting or preparing for M&A or investor due diligence processes is highly desirable.
• Background working closely with Legal, Procurement, and Engineering is highly desirable.
• Practical knowledge of cloud security architecture is highly desirable.
• Relevant certifications such as CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent are highly desirable.
• Competitive salary packages including Long Term Incentive Plans (LTIP) based on units.
• Flexible working time arrangements.
• Option for hybrid work.
• Annual flexible work allowance of €1560.
• 31 vacation days per year, including one floating holiday.
• Pro-rata fully paid Fridays off during August.
• Company pension scheme.
• One paid Volunteer Day per year for supporting a social project.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Comcast
Get handpicked remote jobs straight to your inbox weekly.