Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Berlin, Chemnitz
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you lead the InfoSec team in Finance, conduct ISO 27001 and SOC 2 audits, handle customer security inquiries, and develop security policies and awareness programs.
Your role in the team
- You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
- You report directly to the SVP of Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors, and enterprise customers.
- You will own;
- Leads ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation.
- Own the control framework and ensure it stays current as the business evolves.
- Prepare the InfoSec program for investor and M&A due diligence scrutiny.
- Verantwortung für die Beantwortung von Sicherheitsfragebögen und RFPs für Unternehmenskunden übernehmen.
- Represent Staffbase credibly in customer security reviews, calls, and audits.
- Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality.
- Maintain the risk register and drive risk treatment decisions with relevant stakeholders.
- Eigenständige Durchführung von Sicherheitsbewertungen für kritische und risikoreiche Lieferanten.
- Partner with Procurement and Legal on AI-assisted review workflows.
- Verantwortlich für das interne Sicherheitsrichtlinien-Framework, es aktuell, verständlich und durchgesetzt zu halten.
- Design and run security awareness programs that change behaviour, not just tick boxes.
- Verantwortlich für den Incident-Response-Plan sein und die Umsetzung bei Vorfällen leiten.
- Coordinate with Engineering, Legal, and leadership during incidents.
- Führen Sie Nachsitz-Reviews nach Vorfällen durch und schließen Sie die Erkenntnisse mit den Verantwortlichen ab.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Proven ownership of ISO 27001 and/or SOC 2 programs.
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations.
- Must be fluent in German and English.
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations.
- Background working alongside Legal, Procurement, and Engineering.
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate).
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built.
Experience
- 5+ Jahre praktische Erfahrung im Bereich Informationssicherheit in einem SaaS- oder B2B-Tech-Unternehmen.
- Experience supporting or preparing for M&A or investor due diligence processes.
This text has been machine translated. Show original
What we offer
- Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan).
- Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560.
- Recharge - with 31 vacation days annually (including one floating holiday), plus pro-rata fully paid Fridays off during August.
- Support - we're offering a company pension scheme.
- Volunteers Day - you'll get one day off per year for supporting a social project.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
Staffbase GmbH
Founded in 2014, Staffbase GmbH is an innovative company that develops internal communication solutions, helping organizations connect their employees.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication