Information Security Lead
S
SecfixSecurity Compliance
Remote (+/- 2hrs from Germany GMT+1), +/- 2 hours from Germany GMT+1Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- English (C1 or C2 level required)
- Experience
- 7+ years
- Required Skills
- AWSProject ManagementGCPPeople ManagementAzure
Requirements
- 7+ years of hands-on information security and GRC experience in B2B SaaS.
- Led 5+ successful ISO 27001 certification projects as an implementer or auditor.
- 2+ years of people or team management experience.
- Fluent English (C1 or C2 level) is mandatory.
- Hands-on experience with GRC platforms (e.g., Secfix).
- Strong knowledge of cloud infrastructure security (AWS, Azure, GCP), posture analysis, and remediation planning.
- Strong project management skills, including the ability to break down ambiguous initiatives into concrete deliverables.
- Excellent written communication skills with the ability to create clear, precise compliance content for diverse audiences.
- Strong ownership mindset and ability to operate as a senior individual contributor.
Responsibilities
- Own and drive the compliance roadmap inside the Secfix platform across multiple frameworks including ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, and ISO 42001.
- Implement ISO 27001 and adjacent frameworks end-to-end for customers.
- Mentor and upskill the compliance team, conducting audits and reviewing junior team deliverables to ensure consistency.
- Act as a primary compliance partner for CSMs and sales, providing expert support and joining customer calls.
- Develop and maintain high-quality compliance content including policies, evidence templates, playbooks, and security awareness training.
- Partner with product and engineering teams to translate compliance gaps into actionable product improvements.
- Manage relationships with certification partners and train auditors on the Secfix platform.
View Full Description & ApplyYou'll be redirected to the employer's site