IT Security & Compliance Manager (Part-Time)

Meyandy LLC

Berlin

Vor Ort

EUR 50.000 - 70.000

Teilzeit

14 Tage+
Bewerbungsgenerator

Verschicke keinen 08/15-Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Equity participation
Direct access to founders & CTO
Broad ownership over a core function

Zusammenfassung

Meyandy LLC in Berlin is seeking a hands-on IT Security & Compliance Manager to own our IT compliance, ISMS, and security setup end-to-end. You will implement systems, run audits, and work with engineering to embed security into our software.

The role requires practical security design and ownership in a small, async-first team. The position is part-time with a broad remit, offering direct access to founders and the CTO, equity participation, and ownership over a core company function at the

Qualifikationen

  • ISO27001 certification or C5 attestation ownership and audit communication.
  • Ability to design and implement controls, not just document them.
  • Hands-on internal IT security experience including identity, MDM, endpoints and SaaS administration.

Aufgaben

  • Own end-to-end IT compliance: ISO27001 and C5 audits, evidence, risk management, corrective actions, auditor communication, training.
  • Define and verify controls; build and operationalize them in a cloud-native environment.
  • Maintain current and accurate configurations in Vanta.
  • Lead internal IT security: identity, MDM, endpoint baselines, SaaS administration, access model, onboarding/offboarding.
  • Coordinate external security work: pen tests, security reviews, vendor assessments.
  • Prepare security documentation relied on by auditors and customers (TOMs, VVT, AVVs).

Kenntnisse

ISO27001
C5 attestation
Audit ownership
Identity management
Endpoint hardening
SaaS security
Vanta
German language (working)
English (fluent)
Security governance

Tools

Vanta

Jobbeschreibung

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients. We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Aufgaben

We are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end. This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build.

In practice, that means:

  • Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training
  • Controls: deciding what a control should be, building it, and verifying that it works
  • Vanta: keeping it current and accurate as we grow
  • Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding SaaS security administration: configuration, permissions, access reviews across our tool landscape
  • Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments
  • Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors
Qualifikation Required
  • You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well.
  • You can design and implement controls, not just document them.
  • You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself.
  • You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment.
  • Pragmatic judgment and strong operational ownership in a small, async-first team.
  • German at working level and fluent English — auditors and clinical customers are in German, our team works in English.
Nice to have
  • Healthcare, or another environment handling highly sensitive data.
  • Experience setting up IT and security in an early-stage or fast-growing company.
  • German data protection practice: AVV, VVT, TOM, DPIA. We have an external Datenschutzbeauftragter for the legal depth, so this is useful but not required.
Benefits
  • Office in Berlin Mitte, flexible hours
  • Direct access to founders, CTO, and the full multidisciplinary team
  • Broad ownership over a core company function
  • Equity participation
  • No micromanagement — results over hours logged
  • Work at the intersection of AI, healthcare, software, and security
What matters beyond the checklist

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works. We are not looking for someone who only writes policies, but for someone who builds and operates the security and compliance foundation VIA needs as it scales.

The role is part-time given the small team size, but workloads may vary (eg. increased when building certain security features or during the audit periods).

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT Security & Compliance Lead - HealthTech (w/m/d)
IT Security & Compliance Lead - HealthTech (w/m/d)

Right Search • Berlin

Vor Ort
EUR 70.000 - 100.000
4,5‑Tag‑Woche bei 28 Tagen Urlaub
Firmenwagen zur privaten Nutzung
JobRad‑Leasing
+3
IT Security & Compliance Lead | HealthTech (w/m/d)
IT Security & Compliance Lead | HealthTech (w/m/d)

Right Search • Berlin

Hybrid
Confidential
28 Tage Urlaub
Equity über VESOP
Firmenwagen zur privaten Nutzung
+4
Information Security Manager (m/f/d)
Information Security Manager (m/f/d)

Synaptikon GmbH • Berlin

Vor Ort
EUR 85.000 - 110.000
BVG ticket
Urban Sports Club membership
IT Security & Compliance Lead | HealthTech (w/m/d)
IT Security & Compliance Lead | HealthTech (w/m/d)

Join • Berlin

Hybrid
EUR 70.000 - 100.000
4,5‑Tag‑Woche
Firmenwagen zur privaten Nutzung
JobRad‑Leasing
+4
Security Engineer (f/m/d)
Security Engineer (f/m/d)

1&1 IONOS SE • Berlin

Hybrid
EUR 90.000 - 130.000
Hybrid working model
Home office option
Subsidized canteen
+5
Lead Security Engineer (m/w/d)
Lead Security Engineer (m/w/d)

Recare Deutschland GmbH • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-friendly
Flexible hours
Edenred card
+2
Lead Security Engineer (m/w/d)
Lead Security Engineer (m/w/d)

Recare • Deutschland

Hybrid
EUR 90.000 - 130.000
Information Security Manager
Information Security Manager

develop • Berlin

Hybrid
EUR 80.000 - 100.000
Information Security Lead
Information Security Lead

Secfix • Deutschland

Remote
EUR 90.000 - 130.000
Remote Work
Competitive Salary
Equity
+8
Senior Cyber Security Engineer (f/m/d) Cloud
Senior Cyber Security Engineer (f/m/d) Cloud

IONOS Group • Berlin

Hybrid
EUR 90.000 - 130.000
Hybrid work model
Flexible hours
Canteen subsidy
+5