Logo Staffbase GmbH

Principal Information Security Manager

New

Job

  • Level
    Senior
  • Job Field
    IT, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Location
    Berlin, Chemnitz
  • Working Model
    Hybrid, Onsite
  • Job Summary

    In this role, you lead the InfoSec team in Finance, conduct ISO 27001 and SOC 2 audits, handle customer security inquiries, and develop security policies and awareness programs.

    Your role in the team

    • You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
    • You report directly to the SVP of Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors, and enterprise customers.
    • You will own;
    • Leads ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation.
    • Own the control framework and ensure it stays current as the business evolves.
    • Prepare the InfoSec program for investor and M&A due diligence scrutiny.
    • Verantwortung für die Beantwortung von Sicherheitsfragebögen und RFPs für Unternehmenskunden übernehmen.
    • Represent Staffbase credibly in customer security reviews, calls, and audits.
    • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality.
    • Maintain the risk register and drive risk treatment decisions with relevant stakeholders.
    • Eigenständige Durchführung von Sicherheitsbewertungen für kritische und risikoreiche Lieferanten.
    • Partner with Procurement and Legal on AI-assisted review workflows.
    • Verantwortlich für das interne Sicherheitsrichtlinien-Framework, es aktuell, verständlich und durchgesetzt zu halten.
    • Design and run security awareness programs that change behaviour, not just tick boxes.
    • Verantwortlich für den Incident-Response-Plan sein und die Umsetzung bei Vorfällen leiten.
    • Coordinate with Engineering, Legal, and leadership during incidents.
    • Führen Sie Nachsitz-Reviews nach Vorfällen durch und schließen Sie die Erkenntnisse mit den Verantwortlichen ab.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • Proven ownership of ISO 27001 and/or SOC 2 programs.
    • Track record of representing InfoSec to enterprise customers, including security reviews and escalations.
    • Must be fluent in German and English.
    • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations.
    • Background working alongside Legal, Procurement, and Engineering.
    • Practical understanding of cloud security architecture (enough to challenge and validate, not operate).
    • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built.

    Experience

    • 5+ Jahre praktische Erfahrung im Bereich Informationssicherheit in einem SaaS- oder B2B-Tech-Unternehmen.
    • Experience supporting or preparing for M&A or investor due diligence processes.

    This text has been machine translated. Show original

    What we offer

    • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan).
    • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560.
    • Recharge - with 31 vacation days annually (including one floating holiday), plus pro-rata fully paid Fridays off during August.
    • Support - we're offering a company pension scheme.
    • Volunteers Day - you'll get one day off per year for supporting a social project.

    This text has been machine translated. Show original

    Topics You Will Work On

    Job Locations

    • Location Chemnitz

      Sachsen

      Germany

    • Location Berlin

      Germany

    About Your Employer

    Staffbase GmbH

    Staffbase GmbH

    Founded in 2014, Staffbase GmbH is an innovative company that develops internal communication solutions, helping organizations connect their employees.

    Description

  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Internet, IT, Telecommunication
  • Logo Staffbase GmbH

    Principal Information Security Manager

    Location
    Berlin, Chemnitz
    Working Model
    Hybrid, Onsite
    Diversity
    Open for all genders

    More Jobs