Principal Information Security Manager
HybridDresden, Saxony, Germany
Job Summary
Lead ISO 27001 and SOC 2 audit cycles end-to-end, manage evidence collection, and drive findings remediation while maintaining a current control framework. Own the response to enterprise customer security questionnaires and RFPs, representing Staffbase credibly in security reviews and audits. Maintain the risk register, drive risk treatment decisions, and oversee vendor security assessments for critical suppliers. Own the internal security policy framework, design awareness programs to change behavior, and lead incident response execution and post-incident reviews. Coordinate with Engineering, Legal, Procurement, and external auditors to prepare the program for investor and M&A due diligence scrutiny. Act as the senior deputy for InfoSec within Finance & Operations, leveraging AI-assisted workflows to reduce manual friction.
Required Qualifications
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in German and English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Desired Qualifications
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.