Principal Information Security Manager
HybridChemnitz, Saxony, Germany
Job Summary
Lead ISO 27001 and SOC 2 audit cycles end-to-end, managing evidence collection, auditor interactions, and findings remediation while maintaining a current control framework. Own the response to enterprise customer security questionnaires and RFPs, representing Staffbase credibly in reviews and audits to build scalable, automated approaches that reduce response time. Drive risk treatment decisions through the risk register, oversee vendor security assessments for critical suppliers, and partner with Legal and Procurement on AI-assisted review workflows. Own the internal security policy framework, enforce behavior-changing awareness programs, and lead incident response execution and post-incident reviews. Act as senior deputy for InfoSec within Finance & Operations, coordinating across teams to prepare the function for investor and M&A due diligence. Fluently speak German and English; report directly to the SVP Business Operations & Transformation.
Required Qualifications
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in German and English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Desired Qualifications
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.