Principal Information Security Manager
New
S
StaffbaseSaaS / Employee Experience
Remote working within GermanyFull-TimePrincipal
SalaryCompetitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
Apply NowOpens the employer's application page
Job Details
- Languages
- English
- Experience
- 5+ years
- Required Skills
- ComplianceRisk Management
Requirements
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture
- Relevant certification such as CISM, CISSP, or ISO 27001 Lead Auditor/Implementer (highly desirable)
Responsibilities
- Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
- Own the control framework and ensure it stays current as the business evolves
- Prepare the InfoSec program for investor and M&A due diligence scrutiny
- Own the response to enterprise customer security questionnaires and RFPs
- Represent Staffbase credibly in customer security reviews, calls, and audits
- Maintain the risk register and drive risk treatment decisions with relevant stakeholders
- Own vendor security assessments for critical and high-risk suppliers
- Own the internal security policy framework, keep it current, understandable, and enforced
- Design and run security awareness programs
- Own the incident response plan and lead execution when incidents occur
View Full Description & ApplyYou'll be redirected to the employer's site