IT Security & Compliance Manager (Part-Time)

United States Digital Space LLC

Berlin

Vor Ort

EUR 40.000 - 60.000

Teilzeit

Vor 8 Tagen

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Office in Berlin Mitte
Equity participation
Direct access to founders, CTO
Broad ownership over a core company函数
No micromanagement

Zusammenfassung

United States Digital Space LLC in Berlin is seeking a hands-on IT Security & Compliance Manager to own our IT compliance, ISMS, and security setup end-to-end.

You will implement systems, run audits, collaborate with engineering, and ensure controls and documentation meet ISO27001 and C5 standards while growing with the company.

The role requires pragmatic ownership in a small, async-first team with security at the core of our healthcare/AI software focus.

Qualifikationen

  • Must have carried ISO27001 certification or C5 attestation end-to-end with audit ownership.
  • Hands-on internal IT security experience including identity, MDM, endpoint baselines, SaaS administration.
  • Ability to work with engineers on security topics in a cloud-native, IaC environment.
  • Pragmatic ownership in a small async-first team.

Aufgaben

  • Own IT Compliance, ISMS and IT security setup end-to-end.
  • Design and implement controls, not just document them.
  • Run audits and coordinate with auditors and vendors.
  • Maintain security policies, TOMs, VVT and AVVs with vendors.

Kenntnisse

ISO27001
C5 attestation
Internal IT security
SaaS security administration
Audit coordination

Jobbeschreibung

the company automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

AufgabenWe are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end.

This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build.

In practice, that means:

  • Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training
  • Controls: deciding what a control should be, building it, and verifying that it works

Vanta: keeping it current and accurate as we grow

  • Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding
  • SaaS security administration: configuration, permissions, access reviews across our tool landscape
  • Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments
  • Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors

QualifikationRequired:

  • You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.
  • You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself
  • You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment
  • Pragmatic judgment and strong operational ownership in a small, async-first team

German at working level and fluent English — auditors and clinical customers are in German, our team works in English

Nice to have:

  • Healthcare, or another environment handling highly sensitive data
  • Experience setting up IT and security in an early-stage or fast-growing company
  • German data protection practice: AVV, VVT, TOM, DPIA. We have an external Datenschutzbeauftragter for the legal depth, so this is useful but not required.

What matters beyond the checklist:

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.

We are not looking for someone who only writes policies, but for someone who builds and operates the security and compliance foundation VIA needs as it scales.

The role is part-time given the small team size, but workloads may vary (eg. increased when building certain security features or during the audit periods).

Benefits

  • Office in Berlin Mitte, flexible hours
  • Direct access to founders, CTO, and the full multidisciplinary team
  • Broad ownership over a core company function
  • Equity participation
  • No micromanagement — results over hours logged
  • Work at the intersection of AI, healthcare, software, and security

Find more English Speaking Jobs in Germany on Arbeitnow

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT Security & Compliance Manager (Part-Time)
IT Security & Compliance Manager (Part-Time)

Meyandy LLC • Berlin

Vor Ort
EUR 50.000 - 70.000
Equity participation
Direct access to founders & CTO
Broad ownership over a core function
IT Security & Compliance Manager (Part-Time)
IT Security & Compliance Manager (Part-Time)

VIA HealthTech • Berlin

Vor Ort
Vertraulich
Office in Berlin Mitte
Equity participation
Direct access to founders and CTO
+2
IT Security & Compliance Lead
IT Security & Compliance Lead

Via Health • Berlin

Hybrid
Vertraulich
Office in Berlin Mitte
Flexible hours
Direct access to founders/CTO
+3
IT Security & Compliance Lead
IT Security & Compliance Lead

United States Digital Space LLC • Berlin

Vor Ort
EUR 90.000 - 130.000
Office in Berlin Mitte
Equity participation
Direct access to founders, CTO, and团队
+3
IT Security & Compliance Lead
IT Security & Compliance Lead

VIA HealthTech • Berlin

Vor Ort
EUR 70.000 - 90.000
Flexible hours
Equity participation
Office in Berlin Mitte
Information Security Manager (m/f/d)
Information Security Manager (m/f/d)

Synaptikon GmbH • Berlin

Vor Ort
EUR 85.000 - 110.000
BVG ticket
Urban Sports Club membership
Information Security & Compliance Officer (f/m/d)
Information Security & Compliance Officer (f/m/d)

United States Digital Space LLC • Berlin

Vor Ort
EUR 65.000 - 90.000
30 vacation days
Deutschlandticket mobility budget
Urban Sports partnership
+1
IT Compliance & Information Security Manager (m/f/d)
IT Compliance & Information Security Manager (m/f/d)

Onventis GmbH • Stuttgart

Hybrid
EUR 70.000 - 90.000
Hybrid work model
Job Ticket
Free parking
+3
Trust & Compliance Manager – Datenschutz & IT-Compliance (m/w/d)
Trust & Compliance Manager – Datenschutz & IT-Compliance (m/w/d)

Lecturio GmbH • Berlin

Vor Ort
EUR 24.000 - 42.000
Semesteranpassbare Arbeitszeiten
Kostenlose Lecturio-Weiterbildungspltt
Team- & Company-Events
+2
Information Security Lead (m/f/d)
Information Security Lead (m/f/d)

TeleClinic • München

Hybrid
EUR 90.000 - 130.000
Urban Sports Club
LinkedIn Learning / Reforge
Jobrad & Finn.auto mobility discounts
+5