Principal Information Security Manager

🔥 6 minutes ago

🗣️🇩🇪 German Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Staffbase

Staffbase

501 - 1000 employees

Founded 2014

👥 HR Tech

☁️ SaaS

🏢 Enterprise

💰 $115M Series E - Staffbase on 2022-03

HR Tech • SaaS • Enterprise

Staffbase is an AI-powered employee experience platform that helps organizations reach, inform, and support every employee — from frontline workers to office-based staff. The platform includes an intranet/employee hub, mobile employee app, targeted internal email campaigns, headless CMS, AI assistant (Navigator) for instant answers, digital signage, audio briefings, and integrations with Microsoft 365, ServiceNow, Cornerstone, Google, and others. Staffbase emphasizes content governance, personalization, and frontline engagement, and is used by over 1,500 enterprise customers to centralize communications, knowledge, and service delivery across channels.

📋 Description

• Act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence. • Report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers. • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation. • Own the control framework and ensure it stays current as the business evolves. • Prepare the InfoSec program for investor and M&A due diligence scrutiny. • Own the response to enterprise customer security questionnaires and RFPs. • Represent Staffbase credibly in customer security reviews, calls, and audits. • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality. • Maintain the risk register and drive risk treatment decisions with relevant stakeholders. • Own vendor security assessments for critical and high-risk suppliers. • Own the internal security policy framework, keep it current, understandable, and enforced. • Design and run security awareness programs that change behaviour, not just tick boxes. • Own the incident response plan and lead execution when incidents occur. • Coordinate with Engineering, Legal, and leadership during incidents. • Drive post-incident reviews and close findings with owners.

🎯 Requirements

• 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company • Proven ownership of ISO 27001 and/or SOC 2 programs • Track record of representing InfoSec to enterprise customers, including security reviews and escalations • Must be fluent in German and English • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations

🏖️ Benefits

• Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan) • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560 • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August • Support - we’re offering a company pension scheme • Volunteers Day - you’ll get one day off per year for supporting a social project

Apply Now

Similar Jobs

🕒 3 days ago

EWOR

201 - 500

💼 Consulting

📣 Marketing

📚 Education

Co-Founder / Head of Sales for a Cybersecurity startup under EWOR GmbH, supporting ambitious entrepreneurs with funding and mentorship.

Cyber Security

🕒 July 15

Mesalvo GmbH

201 - 500

Head of Security developing information security and data protection strategies for healthcare technology company Mesalvo. Leading projects and advising management on secure solutions with a focus on health and care.

🗣️🇩🇪 German Required

Cloud

Cyber Security

🕒 June 17

Eye Security

51 - 200

📦 Logistics

🏭 Manufacturing

🏥 Healthcare

Staff Cybersecurity Evangelist representing Eye Security's expertise in cybersecurity across DACH region. Engaging in conferences and partnerships to elevate the company's market standing.

🗣️🇩🇪 German Required

Cyber Security

🕒 June 12

Cloud Software Group

10,000+ employees

Technical Sales Specialist at Citrix driving product adoption for security solutions in enterprise environments. Collaborating with customers to integrate and optimize security within their existing frameworks.

Citrix

Cloud

DNS

TCP/IP

🕒 June 9

Avnet

10,000+ employees

📦 Logistics

💼 Consulting

🏭 Manufacturing

Business Information Security Officer serving as a strategic partner and managing cybersecurity at Avnet. Advising business units on risk management, compliance, and security measures.

Cloud

Cyber Security