IT Security & Compliance Lead

Via Health

Berlin

Vor Ort

Vertraulich

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Office in Berlin Mitte
Flexible hours
Direct access to founders/CTO
Equity participation
Broad ownership over core function
No micromanagement

Zusammenfassung

VIA HealthTech is seeking a hands-on IT Security & Compliance Lead to own security and compliance end-to-end in a small, fast-moving team. You will implement systems, configure tools, and work closely with engineers to integrate security into the development lifecycle, audits, and risk management for ISO27001 and C5.

This role offers broad ownership across cloud, product, and internal security, with direct access to founders and the CTO, plus equity potential.

Qualifikationen

  • Built and hardened cloud security (AWS/GCP) with IAM, network, encryption, logging, and detection.
  • Experience in DevSecOps, secure SDLC, threat modeling, vulnerability management.
  • Carried ISO27001 or C5 attestation end-to-end, including audit ownership.
  • Ability to work directly with engineers and push back on architecture.
  • Pragmatic, ownership-driven approach in a small async-first team.

Aufgaben

  • Own IT security and compliance end-to-end, defining and implementing controls.
  • Implement systems, configure tools, and improve cloud and product security.
  • Run audits, manage evidence, and coordinate with auditors and engineering.
  • Embed security into the development lifecycle (DevSecOps) and threat modeling.
  • Coordinate external security work (pentests, vendor assessments).
  • Oversee internal IT security design (identity, MDM, device policies).

Kenntnisse

Cloud security
DevSecOps
ISO27001/C5
Infrastructure as Code (Terraform)
Threat modeling
Vulnerability management
Auditing & auditor communication
Operational ownership

Tools

Terraform
AWS
GCP

Jobbeschreibung

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Tasks

We are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA.

This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build.

Your goal is to make VIA more secure while helping the team move faster, not slower.

You own IT security and compliance end-to-end. In practice, that means:

  • Cloud security, hands-on: IAM, network, encryption, logging, monitoring, detection
  • Product security together with engineering: web, desktop, mobile, backend, AI systems
  • DevSecOps: embedding security into the development lifecycle, threat modeling, vulnerability management
  • Compliance end-to-end: ISO27001 and, most importantly, C5 — audits, evidence, risk management, corrective actions, auditor communication, internal training
  • Coordinating external security work: penetration tests, security reviews, vendor assessments
  • Internal IT security: you own design and baseline — identity, MDM, device policies, access model, on-/offboarding
Requirements

Required:

  • You have built and hardened cloud security yourself (eg. AWS, GCP) — IAM, network, encryption, logging, detection — and you work in infrastructure-as-code: you change Terraform yourself, you don't file tickets for it
  • DevSecOps and application security: secure SDLC, threat modeling, vulnerability management
  • You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.
  • You work directly with engineers on technical security topics and can push back on architecture
  • Pragmatic judgment and strong operational ownership in a small, async-first team

Nice to have:

  • Healthcare, or another environment handling highly sensitive data
  • Experience setting up security in an early-stage or fast-growing company What matters beyond the checklist
Where this role can grow
  • Cloud infrastructure: taking on more platform ownership alongside security
  • AI security: building this from scratch — agent permissions, tool access boundaries, data flows to model providers, threat modeling for LLM systems in a clinical context. Very few people have done this yet.
  • Medical Device Regulation: as our product evolves, MDR becomes relevant. The natural entry point is the cybersecurity and software lifecycle side (Annex I 17.2, IEC 62304), which overlaps directly with the security work you'd already own.
What matters beyond the checklist

ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. You will move between cloud security architecture, product reviews, audit evidence, and access policies, sometimes in the same week. We are not looking for someone who only writes policies, but for someone who builds and operates the security foundation VIA needs as it scales.

Benefits
  • Office in Berlin Mitte, flexible hours
  • Direct access to founders, CTO, and the full multidisciplinary team
  • Broad ownership over a core company function
  • Equity participation
  • No micromanagement — results over hours logged
  • Work at the intersection of AI, healthcare, software, and security
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT Security & Compliance Lead
IT Security & Compliance Lead

VIA HealthTech • Berlin

Vor Ort
EUR 70.000 - 90.000
Flexible hours
Equity participation
Office in Berlin Mitte
IT Security & Compliance Lead
IT Security & Compliance Lead

United States Digital Space LLC • Berlin

Vor Ort
EUR 90.000 - 130.000
Office in Berlin Mitte
Equity participation
Direct access to founders, CTO, and团队
+3
IT Security & Compliance Manager (Part-Time)
IT Security & Compliance Manager (Part-Time)

VIA HealthTech • Berlin

Vor Ort
Vertraulich
Office in Berlin Mitte
Equity participation
Direct access to founders and CTO
+2
IT Security & Compliance Manager (Part-Time)
IT Security & Compliance Manager (Part-Time)

Meyandy LLC • Berlin

Vor Ort
EUR 50.000 - 70.000
Equity participation
Direct access to founders & CTO
Broad ownership over a core function
IT Security & Compliance Manager (Part-Time)
IT Security & Compliance Manager (Part-Time)

United States Digital Space LLC • Berlin

Vor Ort
EUR 40.000 - 60.000
Office in Berlin Mitte
Equity participation
Direct access to founders, CTO
+2
Information Security & Compliance Officer (f/m/d)
Information Security & Compliance Officer (f/m/d)

United States Digital Space LLC • Berlin

Vor Ort
EUR 65.000 - 90.000
30 vacation days
Deutschlandticket mobility budget
Urban Sports partnership
+1
Head of IT and InfoSec
Head of IT and InfoSec

Clutch Canada • München

Vor Ort
EUR 90.000 - 130.000
Competitive compensation
Application Security Engineer (Berlin/hybrid)
Application Security Engineer (Berlin/hybrid)

United States Digital Space LLC • Berlin

Hybrid
EUR 60.000 - 85.000
Competitive salary
Company pension with 20% top-up
Monthly budget for benefits
+2
Founding Engineering Team Lead (HandsOn)
Founding Engineering Team Lead (HandsOn)

Cygrid • Berlin

Hybrid
EUR 120.000 - 180.000
Founding Team Member Equity
Competitive Compensation
Founding Team Member Status
+9
IT Manager (Security)
IT Manager (Security)

develop • Berlin

Hybrid
EUR 75.000 - 90.000
Flexible working hours
Collaboration-driven culture