Logo Cosuno

Senior IT Security Manager

New

Job

  • Level
    Senior
  • Job Field
    IT, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Salary
    80.000 to 100.000€ Gross/Year
  • Location
    Berlin
  • Working Model
    Full Remote, Hybrid
  • Job Summary

    In this role, you will take ownership of information security and IT governance, lead the ISO 27001 certification process, and manage our ISMS while overseeing the technical implementations.

    Job Technologies

    Your role in the team

    • You'll take full ownership of information security, compliance, and IT governance at Cosuno.
    • You will build and operate our ISMS, guide us through ISO 27001 certification, and become the face of Cosuno's security posture towards enterprise customers and auditors.
    • This is a senior individual contributor role with genuine end-to-end ownership.
    • You won't be managing a team.
    • You will be the expert executing the work, supported by an Engineering team that implements the technical changes you specify, with direct sponsorship from the CTO.
    • Leiten Sie unsere ISO 27001-Zertifizierung von der Gap-Analyse bis zum Audit und führen Sie anschließend das ISMS durch: Risikomanagement, Statement of Applicability, interne Audits, Management-Reviews und den jährlichen Kontrollzyklus.
    • Write and maintain our security policies, making sure they describe how we actually work rather than how a template says we should.
    • Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster.
    • Represent Cosuno in supplier audits by enterprise customers: you'll face customer CISOs and auditors independently, in German or English as needed.
    • Own the operational side of GDPR: drafting and negotiating DPAs (AVVs), managing our subprocessor list and notifications, running vendor security reviews, and supporting DSARs.
    • Work with our external counsel and DPO where legal depth is required, while handling the day-to-day yourself.
    • Own our identity and access management via JumpCloud (MDM, SSO, device policies), including joiner/mover/leaver processes and periodic access reviews.
    • Define our IT security baseline: device hardening, SaaS tooling governance, security awareness training.
    • You own these domains end to end.
    • These responsibilities currently sit with our leadership team; the mandate is to take them over completely, not to assist.
    • We treat security and compliance as a genuine part of how we build trust with enterprise customers, not as a checkbox exercise.
    • When a policy requires technical changes (logging, backup configuration, access controls), you specify what's needed and our Engineering team builds it.
    • You need to understand our stack well enough to have that conversation credibly, but you don't need to write the code yourself.
    • We're 100 people, not 10,000.
    • We want lean, largely automated processes and modern compliance tooling, not committees.
    • We expect you to work heavily with AI tools such as Claude Code to draft policies, answer security questionnaires, analyze audit requirements, and build lightweight automations.
    • The goal is a compliance function that runs on smart processes and AI leverage, not headcount.
    • If your instinct when facing a 300-question security questionnaire is to build a system rather than start typing, you'll fit right in.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • You'll be a great fit if you have:
    • Full professional fluency in German and English.
    • A significant part of our compliance and customer-facing security work is conducted in German, and this is a firm requirement.
    • You've built or run an ISMS before, ideally leading a company through certification.
    • You are familiar with the Annex A controls and how companies actually implement them, and you can speak to an auditor without a script.
    • Operational GDPR expertise.
    • You can draft a DPA, you know your Art. 28 from your Art. 32, and you've handled subprocessor management, vendor reviews, and DSARs in practice.
    • Genuine technical literacy.
    • You understand how a modern SaaS product is built and run (cloud infrastructure, CI/CD, SaaS tooling).
    • You can read an architecture diagram, ask engineers the right questions, and write a System Development Policy that matches reality.
    • Fluency with AI tools in your daily work.
    • You already use tools like Claude, Claude Code, or similar as a core part of how you get things done, whether that's drafting a policy, working through a questionnaire, or automating a recurring task.
    • You see AI as a force multiplier for a one-person function, and you're eager to push it further.
    • Unabhängigkeit im Umgang mit Kunden.
    • You're comfortable being the sole security counterpart in an enterprise audit or a customer CISO call.
    • The organisational maturity to run multiple threads in parallel: a certification project, an audit, three questionnaires, and a DPA negotiation, without things slipping.
    • Bonus points for:
    • ISO 27001 Lead Implementer / Lead Auditor certification, or CIPP/E

    Experience

    • Deep, hands-on ISO 27001 experience.
    • Experience with compliance automation tooling (Kertos, Vanta, Drata, Secfix, or similar)
    • Experience building your own automations with AI (agents, scripts, or workflows for questionnaires, evidence collection, or vendor reviews)
    • Experience administering an MDM / IdP (JumpCloud, Okta, Jamf, or similar)
    • Experience with other frameworks relevant to our customers (SOC 2, TISAX, BSI C5, NIS2)
    • Prior experience at a B2B SaaS company selling to enterprise customers

    This text has been machine translated. Show original

    What we offer

    • Real ownership: You'll build the security and compliance function of a Series B company from a strong foundation, and shape it your way.
    • Competitive compensation: A salary above the market average, reflecting the seniority of the role.
    • Work-life balance: Work 100% remotely or from our modern office in Berlin, with flexible working hours.
    • Top-notch equipment: A new MacBook Pro to ensure you have the best tools for the job.
    • A great team: Regular company off-sites and team events that connect us as people, not just colleagues.
    • Job security: A permanent contract in a stable, well-funded company.

    This text has been machine translated. Show original

    Topics that you deal with on the job

    Job Locations

    • Location Berlin

      Germany

    This is your employer

    Cosuno

    Cosuno

    Cosuno Ventures GmbH is a dynamic startup that has developed an AI-powered platform for the construction industry. Focusing on tendering and procurement management, it enables users to efficiently manage their projects and interact with a variety of professionals.

    Description

  • Company Type
    Startup
  • Working Model
    Full Remote, Hybrid, Onsite
  • Industry
    Construction, Real Estate, Building Services
  • Logo Cosuno

    Senior IT Security Manager

    Salary
    80.000 to 100.000€ Gross/YearNet salary converted from the gross salary in the job ad using tax class I.48.049 to 58.031 € net/Year · Tax class I
    Location
    Berlin
    Working Model
    Full Remote, Hybrid
    Diversity
    Open for all genders

    More Jobs