Staffbase logo
StaffbasePosted 1 month ago

Principal Information Security Manager

HybridDresden, Saxony, Germany

Full TimeSenior LevelLargeCommunication Software

Job Summary

Lead ISO 27001 and SOC 2 audit cycles end-to-end, manage evidence collection, and drive findings remediation while maintaining a current control framework. Own the response to enterprise customer security questionnaires and RFPs, representing Staffbase credibly in security reviews and audits. Maintain the risk register, drive risk treatment decisions, and oversee vendor security assessments for critical suppliers. Own the internal security policy framework, design awareness programs to change behavior, and lead incident response execution and post-incident reviews. Coordinate with Engineering, Legal, Procurement, and external auditors to prepare the program for investor and M&A due diligence scrutiny. Act as the senior deputy for InfoSec within Finance & Operations, leveraging AI-assisted workflows to reduce manual friction.

Required Qualifications

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in German and English
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations

Desired Qualifications

  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce