Job Search and Career Advice Platform

Aktiviere Job-Benachrichtigungen per E-Mail!

Information Security Specialist (German-speaking)

RxREVU, Inc.

Remote

EUR 60.000 - 80.000

Vollzeit

Heute
Sei unter den ersten Bewerbenden

Erstelle in nur wenigen Minuten einen maßgeschneiderten Lebenslauf

Überzeuge Recruiter und verdiene mehr Geld. Mehr erfahren

Zusammenfassung

A leading cybersecurity firm is seeking an Information Security Specialist to support clients in the DACH region. This role offers ownership of the compliance lifecycle, guidance in security and compliance matters, and the chance to contribute to innovative AI product features. Applicants should be fluent in both German and English and have significant experience in GRC processes and security frameworks. This position is 100% remote and provides generous benefits including equity and a development budget.

Leistungen

100% remote work
Competitive salary
Generous equity
26 days holiday plus local public holidays
Health insurance
Personal development budget of 1,000 EUR per year
Annual retreat
Latest tech equipment
Company-wide events and mentorship opportunities

Qualifikationen

  • 3+ years of hands-on information security and GRC experience, ideally with Big 4 or in-house audit.
  • Led 3+ ISO 27001 certification projects as implementer and/or auditor.
  • Hands-on experience with a GRC platform (Secfix or similar).

Aufgaben

  • Own the compliance lifecycle: onboarding, certification, continuous compliance.
  • Harden tech stack and assess posture against various cloud environments.
  • Shape the AI product by translating frontline insights into product requirements.

Kenntnisse

Fluent German (C1/C2)
Fluent English
Information security experience
GRC expertise
Cloud readiness

Tools

GRC platform
AWS
Azure
GCP
Jobbeschreibung
Overview

Remote (CET 2h) | Fluent German (C1/C2) & English required. Note: While we prefer a full-time commitment, this role is also available for contractors at 25+ hours per week in the first months.

Our customers are at the heart of everything we do at Secfix. We are looking for an Information Security Specialist to support customers from the DACH region. You will own the security and compliance lifecycle end-to-end from day 1 onboarding through certification and continuous compliance. You will act as a trusted advisor to startups, scaleups and German Mittelstand, improve processes, collaborate across teams, and contribute to a new AI product. You will receive generous equity and benefits, a 100% remote environment, and the chance to grow with a smart, fun, dedicated team.

About Secfix

Secfix is building a platform that makes security compliance fast and stress-free for growing companies in Europe. We have helped dozens of startups and scaleups in the DACH region get audit-ready quickly and are growing.

We are backed by top VCs and founders from unicorns, with a lean team of 20 and growing.

What you’ll do

The Information Security Specialist at Secfix is part vCISO, part account manager. You will work with customers from start to finish to assess their current security and compliance framework, provide guidance and recommendations, help implement improvements, and act as their auditor liaison. You will work closely with our CTO on AI product features.

  • Own the compliance lifecycle: onboarding, certification, continuous compliance, scope controls (SoA), risk treatment, evidence and gap closure, draft customer roadmaps, lead audits as the primary security point of contact
  • Harden tech stack: assess posture and map controls to AWS/Azure/GCP, Kubernetes/Docker/Terraform; draft best practices; prioritize actionable remediation with timelines
  • Apply deep framework expertise: tailor programs across ISO 27001, SOC 2, NIST, and more frameworks, aligning requirements to customer environments
  • Scale delivery & represent Secfix: build/run runbooks, templates, QA, and knowledge base; communicate with executives and represent Secfix in select public forums
  • Shape the AI product & platform: turn frontline insights into requirements; partner with Product and Engineering to prioritize and ship features that accelerate evidence, controls, and remediation
Qualifications
  • German (C1/C2) and English (fluent) required
  • 3+ years of hands-on information security and GRC experience, ideally with Big 4 or in-house audit in high-growth SaaS
  • Led 3+ ISO 27001 certification projects as implementer and/or auditor
  • Hands-on experience with a GRC platform (Secfix or similar)
  • Cloud readiness across AWS, Azure, and GCP; experience with posture analysis and remediation planning
Bonus
  • Automated internal processes or built prototypes/tools for compliance, with code or no-code
  • SOC 2 implementation and audit experience
  • Experience as DPO
Consider this role if
  • Do not lead customer-side audits end-to-end or struggle with documenting controls; do not draft security policies or answer security questionnaires
  • Prefer not to onboard into new regulations or infosec standards
  • Cannot create cloud security hardening task lists for AWS, Azure and GCP
Benefits
  • 100% remote work with a virtual office in Gather
  • Autonomy with core hours 10am–4pm CET; flexible outside core hours
  • Competitive local salary
  • Generous equity
  • 26 days holiday plus local public holidays
  • Health insurance
  • Personal development budget of 1,000 EUR per year
  • Remote workspace budget and access to co-working spaces
  • Annual retreat (this year in Milan)
  • Latest tech equipment
  • Company-wide events and mentorship opportunities

Interview Process

  • 15 min – Intro call with talent team
  • 30 min – Meet co-founder & CTO
  • Take-home assessment
  • 1.5 hr – Assessment review and interview with CEO and CISO
  • 45 min – Final virtual on-site in Gather

What we offer

  • Remote work: 100% remote with a Gather virtual office
  • Competitive salary, local rates at or above market
  • Equity: generous equity package
  • Holidays: 26 days plus local holidays
  • Health insurance
  • Development budget: 1,000 EUR per year
  • Workspace budget and access to co-working spaces
  • Annual retreat
  • Tech equipment: latest gear
  • Company events and mentorship opportunities

Please note: We are an equal-opportunity employer and remote-only company. We hire within EU time zones. We use Gather as our virtual office and maintain a synchronized communication approach.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
eine PDF-, DOC-, DOCX-, ODT- oder PAGES-Datei bis zu 5 MB per Drag & Drop ablegen.