Job
- Level
- Lead
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will develop a comprehensive security program, oversee infrastructure decisions, manage vulnerabilities, handle incident response, and communicate with customers regarding security practices.
Job Technologies
Your role in the team
- You'll be our first dedicated security engineer: a senior IC with no team at the start. You join as Deputy CISO, report to our Director of Technology (currently acting CISO), and build security engineering from scratch. The baseline is already in place - ISO 27001, C5 Type II, regular penetration tests, and encryption in the product. AI is adding new surfaces: voice documentation, document generation, and agentic workflows. You build and own the security program, the tooling, and the security story we tell customers.
- Vulnerability management - scanners and dependency updates across repos, plus the process that gets findings closed.
- Partner to Platform - review security-sensitive infrastructure decisions and explore options like customer-managed keys or HSMs. Platform still owns architecture.
- Certifications, technical side - control design and assessments for our ISO 27001 and C5 setup, the security case for a potential upcoming Class IIa medical device (MDR), and pentest scoping and follow-up, with regulation like the EU Cyber Resilience Act on the horizon. This is roughly a quarter to a third of the role, and we say it openly: for the right person in healthcare security, it's a draw, not a chore.
- Customer security - reusable docs, evidence, and AI-assisted questionnaires, so the tenth enterprise deal costs a fraction of the first. You join the call when a hospital CISO asks something new about our AI architecture.
- Incident response - process, runbooks, and escalation, and you lead when it's real. We're too small for a SOC, so you design on-call that fits a company our size. Product incidents and platform bugs have their own owners in engineering.
- Unternehmensweite Sicherheit – beobachten Sie die Bedrohungslandschaft, verwandeln Sie das Lieferketten-Chaos dieser Woche in konkrete Maßnahmen und legen Sie die Baselines fest, die IT auf Geräte und Konten anwendet.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- You've been the technical counterpart through at least one ISO 27001, C5, or SOC 2 certification cycle: you've designed controls, faced an auditor, and written the technical side of a Statement of Applicability. This is a hard requirement.
- You've run vulnerability management somewhere real: scanners, dependency bots, triage, and the follow-through that gets things fixed.
- You follow the security scene closely (podcasts, advisories, incident write-ups) and usually have an opinion on this week's incident before it reaches the news.
- You're genuinely curious about AI security - both securing AI systems (agents, sandboxing, data flows) and using AI tooling to work at leverage.
- You can talk to engineers, auditors, and hospital security teams in English without a slide deck translating for you.
Experience
- You're a hands-on security engineer with 6+ years across software and security engineering, and you can point to a security program (or a big part of one) you've owned.
This text has been machine translated. Show original
What we offer
- Purposeful work - your role will have a positive impact on patients, their families, and healthcare professionals.
- Company culture - we believe in flat hierarchies that promote high performance and strong team dynamics. We foster an environment characterized by mutual respect, loyalty, and recognition. Together, we strive for our goals - and expect the same from you.
- Flexibility - want to pick up your child from daycare? Like to exercise during lunch? We'll support you. We are a remote-friendly company offering flexible working hours. Workations are also possible by arrangement.
- Edenred card - which you can use according to your needs.
- Extra vacation day - so you can celebrate your birthday with your loved ones, you'll have the day off.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Topics You Will Work On
Job Locations
About Your Employer
Recare Deutschland GmbH
Recare Deutschland GmbH is a modern health tech startup based in Berlin that offers a digital platform for connecting hospitals, nursing, and rehabilitation facilities. The company optimizes administrative processes and enhances collaboration along the care chain through AI-supported workflows, particularly in discharge management. With a platform that integrates many acute hospitals and rehabilitation clinics, Recare contributes to increasing efficiency in healthcare.
Description
- Company Type
- Startup
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Healthcare, Social Sector