Principal Information Security Manager
HybridBerlin, State of Berlin, Germany
Job Summary
Lead ISO 27001 and SOC 2 audit cycles end-to-end, managing evidence collection, auditor coordination, and findings remediation while maintaining a current control framework. Own the response to enterprise customer security questionnaires and RFPs, representing Staffbase credibly in security reviews and audits to build scalable, automated approaches. Drive risk treatment decisions through the risk register, conduct vendor security assessments for critical suppliers, and partner with Legal and Procurement on AI-assisted review workflows. Own the internal security policy framework, design behavior-changing awareness programs, and lead incident response execution and post-incident reviews. Act as senior deputy for InfoSec within Finance & Operations, coordinating across Engineering, Legal, and external stakeholders to prepare the program for investor and M&A due diligence. Fluent in German and English with 5+ years in SaaS InfoSec.
Required Qualifications
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in German and English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Desired Qualifications
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.