Principal Information Security Manager

Staffbase

München

Hybrid

EUR 90.000 - 130.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

LTIP
Hybrid work
Flex time
Vacation days
Pension plan
Volunteers Day

Zusammenfassung

Staffbase is seeking a senior deputy for InfoSec within the Finance & Operations department to own day-to-day security governance, representing the function internally and externally, and driving it with greater intelligence.

You will report to the SVP Business Operations & Transformation and collaborate with Legal, Procurement, Engineering, auditors and enterprise customers to strengthen security posture across the company.

Qualifikationen

  • 5+ years of hands-on InfoSec in a SaaS or B2B tech company.
  • Proven ownership of ISO 27001 and/or SOC 2 programs.
  • Track record representing InfoSec to enterprise customers.
  • Must be fluent in German and English.
  • Comfortable with AI-driven tooling; actively looks for automation opportunities.

Aufgaben

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end from prep to remediation.
  • Own the control framework and ensure it stays current with business changes.
  • Prepare InfoSec for investor and due-diligence scrutiny.
  • Own responses to enterprise security questionnaires and RFPs.
  • Represent Staffbase credibly in security reviews and audits.
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time.
  • Maintain the risk register and drive risk treatment decisions.
  • Own vendor security assessments for critical suppliers.
  • Partner with Procurement and Legal on AI-assisted review workflows.
  • Own the internal security policy framework and enforcement.
  • Design and run security awareness programs to change behaviour.
  • Own the incident response plan and lead execution during incidents.
  • Coordinate with Engineering, Legal, and leadership during incidents.
  • Drive post-incident reviews and close findings with owners.

Kenntnisse

InfoSec experience
ISO 27001
SOC 2
German language
English language
AI tooling

Tools

AI tooling

Jobbeschreibung

We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.

Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St.Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience. We are proud to be aUnicorncompany—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.

Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.

This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.

You coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.

You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.

What you’ll be doing

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.

You will own;

Compliance & Audit
  • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
  • Own the control framework and ensure it stays current as the business evolves
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
  • Own the response to enterprise customer security questionnaires and RFPs
  • Represent Staffbase credibly in customer security reviews, calls, and audits
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
  • Maintain the risk register and drive risk treatment decisions with relevant stakeholders
  • Own vendor security assessments for critical and high-risk suppliers
  • Partner with Procurement and Legal on AI-assisted review workflows
  • Own the internal security policy framework, keep it current, understandable, and enforced
  • Design and run security awareness programs that change behaviour, not just tick boxes
  • Own the incident response plan and lead execution when incidents occur
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post-incident reviews and close findings with owners
What you need to be successful
  • 5+ years of hands‑on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in German and English
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Highly Desirable
  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
What you'll get
  • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
  • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
  • Support -we’re offering a company pension scheme
  • Volunteers Day - you’ll get one day off per year for supporting a social project
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Principal Information Security Manager
Principal Information Security Manager

Staffbase • Berlin

Hybrid
EUR 95.000 - 135.000
LTIP (unit‑based Long Term Incentive)
Hybrid work model
Flexibility in working time models
+4
Principal Information Security Manager
Principal Information Security Manager

Staffbase • Chemnitz

Hybrid
EUR 90.000 - 130.000
Competitive compensation
Hybrid work option
Annual flex work allowance €1560
+3
Principal Information Security Manager
Principal Information Security Manager

Staffbase • Deutschland

Hybrid
EUR 70.000 - 100.000
Competitive compensation with LTIP
Flexible working time models
31 vacation days annually
+2
Principal Information Security Manager
Principal Information Security Manager

Chemnitz attracts • Chemnitz

Hybrid
EUR 70.000 - 100.000
Competitive Compensation including LTIP
31 vacation days annually
Flexible working time models
+2
Principal Information Security Manager
Principal Information Security Manager

Staffbase • Dresden

Vor Ort
EUR 70.000 - 90.000
Competitive Compensation
Flexible working time models
31 vacation days annually
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Chemnitz

Hybrid
EUR 80.000 - 110.000
LTIP (unit-based Long Term Incentive  
Hybrid work option
Yearly flex work allowance €1560
+4
Senior Product Security Engineer
Senior Product Security Engineer

Staffbase • Chemnitz

Vor Ort
EUR 70.000 - 100.000
LTIP
Hybrid work
Flex work allowance
+3
Senior Product Security Engineer
Senior Product Security Engineer

Staffbase • Dresden

Vor Ort
EUR 70.000 - 110.000
LTIP
Hybrid work
Vacation days
+2
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Dresden

Hybrid
EUR 90.000 - 130.000
Competitive LTIP
Hybrid work option
Vacation days + float holiday
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Berlin

Hybrid
EUR 70.000 - 95.000