Principal Information Security Manager

Staffbase

Dresden

On-site

EUR 70,000 - 90,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive Compensation
Flexible working time models
31 vacation days annually

Job summary

jobr.pro in Dresden is seeking a Senior InfoSec Manager to lead their InfoSec function, managing audits and representing the department both internally and externally. You'll coordinate closely with various stakeholders to ensure compliance and security standards are met.

Successful candidates will have over 5 years of InfoSec experience, including ownership of ISO 27001 and/or SOC 2 programs. The role offers competitive compensation, flexible work models, and significant vacation days.

Qualifications

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company.
  • Proven ownership of ISO 27001 and/or SOC 2 programs.
  • Track record of representing InfoSec to enterprise customers.

Responsibilities

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end.
  • Own enterprise customer security questionnaires and RFPs.
  • Maintain the risk register and drive risk treatment decisions.

Skills

ISO 27001 program ownership
SOC 2 program management
Fluent in German
Fluent in English
AI-driven automation

Job description

This is not a build‑from‑scratch role. It is a step up in maturity: fewer manual processes and sharper governance. The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to. You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI‑assisted workflows, and are empowered to drive that change as we build out our AI‑driven operating model across the company.

What you’ll be doing

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day‑to‑day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.

Compliance & Audit
  • Lead ISO 27001 and SOC 2 audit cycles end‑to‑end in preparation, evidence collection, auditor management, and findings remediation
  • Own the control framework and ensure it stays current as the business evolves
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
  • Own the response to enterprise customer security questionnaires and RFPs
  • Represent Staffbase credibly in customer security reviews, calls, and audits
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
Risk & Vendor Security
  • Maintain the risk register and drive risk treatment decisions with relevant stakeholders
  • Own vendor security assessments for critical and high‑risk suppliers
  • Partner with Procurement and Legal on AI‑assisted review workflows
Policy & Awareness
  • Own the internal security policy framework, keep it current, understandable, and enforced
  • Design and run security awareness programs that change behaviour, not just tick boxes
Incident Response
  • Own the incident response plan and lead execution when incidents occur
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post‑incident reviews and close findings with owners
What you need to be successful
Essential Experience
  • 5+ years of hands‑on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Fluent in German and English
  • Comfortable with AI‑driven tooling; actively looks for automation opportunities in compliance and operations
Highly Desirable
  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
What you’ll get
  • Competitive Compensation - we offer attractive salary packages including LTIP (unit‑based Long Term Incentive Plan)
  • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro‑rated fully paid Fridays off during August
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Information Security Manager
Principal Information Security Manager

Staffbase • Berlin

On-site
EUR 90,000 - 130,000
LTIP (Long Term Incentive Plan)
Hybrid work model
Flex work allowance €1560 per year
+3
Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

Idealworks Inc. • München

On-site
EUR 70,000 - 110,000
Hybrid working model
30 vacation days
Bonus scheme
+4
Principal of Information Security (f/m/d)
Principal of Information Security (f/m/d)

Orbem • München

Hybrid
EUR 120,000 - 180,000
Stock Options
Relocation Support
Learning & Development
+4
Senior Product Security Engineer
Senior Product Security Engineer

Staffbase • Berlin

On-site
EUR 70,000 - 90,000
LTIP program
Hybrid work setup
Annual flex time allowance €1560
+1
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Yoummday GmbH • München

On-site
EUR 90,000 - 130,000
30 days vacation
Job lunch allowance (€69/mo)
Givve card (€50/mo)
+5
Information Security Specialist
Information Security Specialist

Cosmenta • Berlin

On-site
EUR 40,979 - 56,590
Remote-friendly with flexible hours
Annual learning budget for security certifications
Health insurance + pension plan
+2
Information Security Specialist
Information Security Specialist

Vazex • Berlin

Hybrid
EUR 41,047 - 56,684
Health insurance
Pension plan
30 vacation days per year
+3
Information Security Specialist
Information Security Specialist

Declari • Berlin

On-site
EUR 41,065 - 56,709
Remote-friendly
Learning budget
Health insurance
+2
Security Administrator
Security Administrator

Lynx Beleggen • Berlin

On-site
EUR 80,000 - 110,000
Competitive Salary
Free lunch from our cook
Training budget of €2,000 per year
+3
Information Security Officer (f/m/d)
Information Security Officer (f/m/d)

Spread • Berlin

On-site
EUR 70,000 - 110,000
Learning budget
Deutschlandticket mobility budget
Bike leasing
+3