Doodle logo
DoodlePosted 1 month ago

Lead, IT Operations, Cyber Security and Compliance - All Genders

HybridBerlin, State of Berlin, Germany

Full TimeSenior Level

Job Summary

Design and own Doodle's AI governance framework, covering agentic AI security controls, EU AI Act assessments, and risk management for external contributors. Author board-level cybersecurity posture presentations using the NIST CSF 2.0 framework and translate technical risk into business language for the CEO and CFO. Own and drive SOC 2 Type II, HIPAA, ISO 27001, and ISO 42001 programmes while serving as Privacy Officer for GDPR and Swiss FADP obligations. Operate the full security toolset including SentinelOne, CrowdStrike, Okta, and Netskope, and lead a lean IT team supporting 100+ headcount across Berlin and remote EU locations. Manage the full employee lifecycle, access provisioning, device management, and service desk operations. Run a structured vendor due diligence programme and maintain a live risk register in Linear across 10+ active items.

Required Qualifications

  • Proven experience owning multi framework compliance programmes such as SOC 2, ISO 27001, ISO 42001, or HIPAA
  • Experience serving as a Privacy Officer or managing GDPR/FADP obligations directly
  • Strong understanding of EDR, MDM, IAM/SSO, and CASB/SSE tooling in a live production environment
  • Experience building AI governance frameworks, including emerging regulation such as the EU AI Act
  • Comfortable running a live risk register and structured vendor due diligence process
  • Able to assess and manage risk from external contributors and third party tools
  • Experience leading a lean IT team supporting 100+ employees across multiple locations
  • Hands on with the full employee lifecycle: onboarding, offboarding, access provisioning, device management, and service desk
  • Comfortable owning a SaaS portfolio and driving tooling decisions such as CLM platform selection
  • Able to translate technical risk into business language for CEO and CFO audiences
  • Comfortable presenting security posture at board level
  • Strong cross functional partner to PeopleOps, Legal, and external DPO relationships
  • Based and have the right to work in Germany
  • Must be available for weekend shifts

Desired Qualifications

  • Experience supporting enterprise customers in regulated verticals such as government, energy, or healthcare
  • Experience with Netskope or similar SSE platforms
  • Experience automating IT workflows using tools such as Linear
  • Background in a high growth B2B SaaS environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce