Principal Information Security Manager

🔥 0 minutes ago

🇩🇪 Germany – Remote

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Staffbase

Staffbase

501 - 1000 employees

Founded 2014

👥 HR Tech

☁️ SaaS

🏢 Enterprise

💰 $115M Series E - Staffbase on 2022-03

HR Tech • SaaS • Enterprise

Staffbase is an AI-powered employee experience platform that helps organizations reach, inform, and support every employee — from frontline workers to office-based staff. The platform includes an intranet/employee hub, mobile employee app, targeted internal email campaigns, headless CMS, AI assistant (Navigator) for instant answers, digital signage, audio briefings, and integrations with Microsoft 365, ServiceNow, Cornerstone, Google, and others. Staffbase emphasizes content governance, personalization, and frontline engagement, and is used by over 1,500 enterprise customers to centralize communications, knowledge, and service delivery across channels.

📋 Description

• Serve as the senior deputy for InfoSec within the Finance & Operations department • Own the InfoSec function day-to-day and represent it internally and externally • Report directly to the SVP Business Operations & Transformation • Coordinate with Legal, Procurement, Engineering, external auditors, and enterprise customers • Lead ISO 27001 and SOC 2 audit cycles end-to-end, including preparation, evidence collection, auditor management, and findings remediation • Own and maintain the control framework • Prepare the InfoSec program for investor and M&A due diligence • Own responses to enterprise customer security questionnaires and RFPs • Represent Staffbase in customer security reviews, calls, and audits • Build scalable automation, templates, and knowledge bases to reduce response times • Maintain the risk register and drive risk treatment decisions • Own vendor security assessments for critical and high-risk suppliers • Partner with Procurement and Legal on AI-assisted review workflows • Own and enforce the internal security policy framework • Design and run behaviour-changing security awareness programs • Own the incident response plan and lead execution during incidents • Coordinate with Engineering, Legal, and leadership during incidents • Drive post-incident reviews and close findings with owners

🎯 Requirements

• 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company • Proven ownership of ISO 27001 and/or SOC 2 programs • Track record of representing InfoSec to enterprise customers, including security reviews and escalations • Must be fluent in English • Comfortable with AI-driven tooling and actively looks for automation opportunities in compliance and operations • Experience supporting or preparing for M&A or investor due diligence processes is highly desirable • Background working alongside Legal, Procurement, and Engineering is highly desirable • Practical understanding of cloud security architecture is highly desirable • Relevant certification such as CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent is highly desirable

🏖️ Benefits

• Attractive salary packages including LTIP (unit-based Long Term Incentive Plan) • Flexible working time models • Option of hybrid work • Yearly flex work allowance of €1560 • 31 vacation days annually, including one floating holiday • Pro rata fully paid Fridays off during August • Company pension scheme • One paid Volunteers Day per year for supporting a social project

Apply Now

Similar Jobs

🕒 September 10

1KOMMA5°

1001 - 5000

💼 Consulting

📦 Logistics

🏗️ Construction

Head of Security leading Trust for 1KOMMA5°’s renewable-energy software and connected home systems. Building cloud, IoT, compliance, and identity security.

🗣️🇩🇪 German Required

Cloud

Cyber Security

Google Cloud Platform

🕒 August 21

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform. Leading threat modeling, cloud security, vulnerability management, and detection response.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 August 12

Eraneos Germany

1001 - 5000

🏥 Healthcare

🏭 Manufacturing

📦 Logistics

Principal Cybersecurity consultant driving Eraneos Germany’s cybersecurity consulting growth. Developing enterprise accounts, complex proposals, partnerships, and integrated security offerings.

🗣️🇩🇪 German Required

Cyber Security

🕒 August 11

Mozilla

501 - 1000

👥 B2C

🔒 Cybersecurity

Mozilla Staff Security Engineer maintaining ISMS and supporting ISO 27001 and SOC 2 compliance programs. Leading audits, policies, remediation, and cross-functional security governance.

🕒 August 7

Orcrist Technologies GmbH

11 - 50

💼 Consulting

🎖️ Defense

📦 Logistics

Director building physical and organizational security for Orcrist’s petabyte-scale B2B data intelligence platform. Managing classified-work protection, sites, personnel security, crisis response, vendors, and regulatory compliance.

🗣️🇩🇪 German Required