Senior Information Security Specialist

🔥 29 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Secfix

Secfix

11 - 50 employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Secfix is a company that specializes in automating compliance processes for businesses to help them achieve and maintain security standards such as ISO 27001, TISAX, and GDPR. By utilizing integrations with cloud providers, SSO, HR systems, and ticketing tools, Secfix streamlines the compliance workflow, reducing manual effort by up to 90%. The platform offers features like automated checklists, risk management, vendor management, and policy management, making it easier for startups and SMEs to stay secure and compliant. Secfix is particularly beneficial for small companies seeking ISO 27001 certification, offering support to ensure a smooth and fast compliance journey. The company is based in Europe and prioritizes data protection with GDPR compliance and strict data encryption policies.

📋 Description

• Own and drive the compliance roadmap inside the Secfix platform across multiple compliance frameworks • Implement ISO 27001 and adjacent frameworks end-to-end for customers • Mentor and upskill junior compliance specialists and review their work • Conduct internal audits for strategic and complex customers • Review junior team members’ internal audits to improve quality and consistency • Support CSMs and sales representatives with customer compliance questions and calls • Own and improve compliance content, including policies, evidence templates, playbooks, and security awareness training • Close framework gaps and incorporate auditor feedback into team practices and platform improvements • Partner with product and engineering to translate compliance gaps into structured product work • Collaborate with Customer Success, Product, and Founders on priorities • Build relationships with certification partners and train auditors on the Secfix platform

🎯 Requirements

• Fluent English (C1 or C2 English essential) • 7+ years of hands-on information security and GRC experience in B2B SaaS • Led 5+ successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company • Hands-on experience with Secfix or a similar GRC platform • Cloud infrastructure readiness across AWS, Azure, and GCP • Experience with posture analysis and remediation planning • Strong project management skills • Ability to break down ambiguous initiatives into concrete deliverables, prioritize ruthlessly, and ship • Excellent written communication, especially clear and precise compliance content for auditors, founders, and engineers • Ability to operate as a senior individual contributor with strong ownership • Experience implementing additional compliance frameworks is a bonus • Experience mentoring or coaching colleagues in compliance, audit, or GRC is a bonus • Startup experience is a plus

🏖️ Benefits

• 100% remote work with a virtual office in Gather • Competitive local salaries at or above market rates • Generous equity package • Direct access to world-class mentors • €1,000 annual personal development budget • Home office budget • Access to co-working spaces • 26 days holiday plus local public holidays • Comprehensive health coverage • Annual retreat • Company-wide events • Latest tech equipment, including MacBook, monitors, and headphones

Apply Now

Similar Jobs

🔥 15 hours ago

VOLENTUM Group Deutschland

1 - 10

💼 Consulting

📦 Logistics

🏥 Healthcare

Cyber-Security Specialist securing IT, cloud, and hybrid infrastructures for German clients. Managing SIEM, EDR, XDR, detection rules, incident response, and compliance initiatives.

🗣️🇩🇪 German Required

Cloud

DNS

Linux

TCP/IP

🔥 18 hours ago

Qdrant

51 - 200

🤖 Artificial Intelligence

☁️ SaaS

Security Engineer securing Qdrant’s open-source vector search engine for AI applications. Managing vulnerabilities, bug bounty operations, cloud security, automation, and incident response.

AWS

Cloud

Kubernetes

Python

Rust

Go

🔥 22 hours ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Senior Security Researcher developing scalable cybersecurity collection tools and investigating vulnerabilities for CrowdStrike Intelligence. Publishing actionable research on adversary activity, emerging vulnerabilities, and information security.

Android

iOS

Linux

Python

Rust

Go

🕒 Yesterday

GAMBIT Consulting

201 - 500

💼 Consulting

🏭 Manufacturing

🚘 Automotive

SAP-Beratung GAMBIT entwickelt SAP-Berechtigungs- und Security-Konzepte für Unternehmenskunden. Beratung, Audits, Workshops und Presales für On-Premise- und Cloud-Umgebungen.

🗣️🇩🇪 German Required

Cloud

🕒 Yesterday

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform, products, CI/CD, and production infrastructure. Leading threat modeling, vulnerability management, cloud hardening, and detection response.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go