Senior IT Security Manager

Cosuno

Berlin

Vor Ort

EUR 120.000 - 180.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

MacBook Pro equipped
Remote work option
Office in Berlin
Regular company off-sites

Zusammenfassung

Cosuno is seeking a senior information security professional to own ISMS, ISO 27001 certification, and GDPR operations. You will drive security policy, audits, and vendor reviews while partnering with the CTO and Engineering teams.

You will represent Cosuno in customer audits and enterprise RFIs, fluently handling German and English communications with auditors and clients. This is a remote-friendly, Berlin-based senior role.

Qualifikationen

  • ISO 27001: lead certification and ongoing ISMS management.
  • Operational GDPR: DPAs, subprocessor reviews, DSARs.
  • Hands-on security for modern SaaS products; architecture literacy.

Aufgaben

  • Lead ISO 27001 certification and maintain the ISMS.
  • Write and maintain security policies reflecting real practice.
  • Own responses to enterprise security questionnaires and RFIs.
  • Represent Cosuno in supplier audits with enterprise customers (German/English).
  • Own GDPR operations: DPAs, subprocessor list, vendor reviews, DSARs.
  • Define IT security baseline: IAM, device policies, SaaS tooling governance.
  • Collaborate with Engineering and CTO sponsorship; policies defined by you, implemented by engineers.

Kenntnisse

ISO 27001
German/English fluency
GDPR expertise
Security governance
AI tooling
Customer facing
Audit liaison

Tools

JumpCloud
Okta

Jobbeschreibung

Your mission

You'll take full ownership of information security, compliance, and IT governance at Cosuno. You'll build and run our ISMS, lead us through ISO 27001 certification, and become the face of Cosuno's security posture toward enterprise customers and auditors.

This is a senior individual contributor role with genuine end-to-end ownership. You won't be managing a team. You'll be the expert doing the work, backed by an Engineering team that implements technical changes you define, and with direct sponsorship from the CTO.

What you'll own

ISMS & ISO 27001

  • Lead our ISO 27001 certification from gap analysis through audit, and run the ISMS afterwards: risk management, Statement of Applicability, internal audits, management reviews, and the annual control cycle

  • Write and maintain our security policies, making sure they describe how we actually work rather than how a template says we should

Customer trust & audits

  • Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster

  • Represent Cosuno in supplier audits by enterprise customers: you'll face customer CISOs and auditors independently, in German or English as needed

Data protection (GDPR)

  • Own the operational side of GDPR: drafting and negotiating DPAs (AVVs), managing our subprocessor list and notifications, running vendor security reviews, and supporting DSARs

  • Work with our external counsel and DPO where legal depth is required, while handling the day-to-day yourself

IT governance & access management

  • Own our identity and access management via JumpCloud (MDM, SSO, device policies), including joiner/mover/leaver processes and periodic access reviews

  • Define our IT security baseline: device hardening, SaaS tooling governance, security awareness training

How we work
  • High autonomy, high impact: You own these domains end to end. These responsibilities currently sit with our leadership team; the mandate is to take them over completely, not to assist.

  • Compliance as a product: We treat security and compliance as a genuine part of how we build trust with enterprise customers, not as a checkbox exercise.

  • You define, Engineering implements: When a policy requires technical changes (logging, backup configuration, access controls), you specify what's needed and our Engineering team builds it. You need to understand our stack well enough to have that conversation credibly, but you don't need to write the code yourself.

  • Pragmatic, not bureaucratic: We're 100 people, not 10,000. We want lean, largely automated processes and modern compliance tooling, not committees.

  • AI-first by default: We expect you to work heavily with AI tools such as Claude Code to draft policies, answer security questionnaires, analyze audit requirements, and build lightweight automations. The goal is a compliance function that runs on smart processes and AI leverage, not headcount. If your instinct when facing a 300-question security questionnaire is to build a system rather than start typing, you'll fit right in.

Your profile

You’ll be a great fit if you have:

  • Full professional fluency in German and English. A significant part of our compliance and customer‑facing security work is conducted in German, and this is a firm requirement.

  • Deep, hands‑on ISO 27001 experience. You’ve built or run an ISMS before, ideally leading a company through certification. You know the Annex A controls and how companies actually implement them, and you can talk to an auditor without a script.

  • Operational GDPR expertise. You can draft a DPA, you know your Art. 28 from your Art. 32, and you’ve handled subprocessor management, vendor reviews, and DSARs in practice.

  • Genuine technical literacy. You understand how a modern SaaS product is built and run (cloud infrastructure, CI/CD, SaaS tooling). You can read an architecture diagram, ask engineers the right questions, and write a System Development Policy that matches reality.

  • Fluency with AI tools in your daily work. You already use tools like Claude, Claude Code, or similar as a core part of how you get things done, whether that’s drafting a policy, working through a questionnaire, or automating a recurring task. You see AI as a force multiplier for a one‑person function, and you’re eager to push it further.

  • Independence in front of customers. You’re comfortable being the sole security counterpart in an enterprise audit or a customer CISO call.

  • The organisational maturity to run multiple threads in parallel: a certification project, an audit, three questionnaires, and a DPA negotiation, without things slipping.

Bonus points for:

  • ISO 27001 Lead Implementer / Lead Auditor certification, or CIPP/E

  • Experience with compliance automation tooling (Kertos, Vanta, Drata, Secfix, or similar)

  • Experience building your own automations with AI (agents, scripts, or workflows for questionnaires, evidence collection, or vendor reviews)

  • Experience administering an MDM / IdP (JumpCloud, Okta, Jamf, or similar)

  • Experience with other frameworks relevant to our customers (SOC 2, TISAX, BSI C5, NIS2)

  • Prior experience at a B2B SaaS company selling to enterprise customers

Why us?
  • Real ownership: You’ll build the security and compliance function of a Series B company from a strong foundation, and shape it your way.

  • Competitive compensation: A salary above the market average, reflecting the seniority of the role.

  • Work‑life balance: Work 100 % remotely or from our modern office in Berlin, with flexible working hours.

  • Top‑notch equipment: A new MacBook Pro to ensure you have the best tools for the job.

  • A great team: Regular company off‑sites and team events that connect us as people, not just colleagues.

  • Job security: A permanent contract in a stable, well‑funded company.

About us

Cosuno – Revolutionizing construction through technology.

We are Cosuno – a fast‑growing tech startup that is making the construction industry more efficient and transparent with our digital platform for tenders and procurement processes. Our goal: to solve the most complex challenges in the industry with innovation and simplicity.

Artificial intelligence is the key to our solution: it analyzes millions of price data points and helps construction companies create precise and efficient bids. This not only saves our customers time but also helps them avoid unnecessary costs.

But for us, it’s not just about technology – it’s about the people who drive it. At Cosuno, you will work with creative minds who are reshaping the construction industry. We believe in diversity because we know that the best ideas come from different perspectives. An integrative and inclusive work environment is a matter of course for us.

Join us – Build the future of construction.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT Administrator
IT Administrator

Cosuno-Ventures-Gmbh • Berlin

Hybrid
EUR 60.000 - 90.000
MacBook Pro
IT Administrator
IT Administrator

Cosuno • Berlin

Hybrid
EUR 60.000 - 85.000
MacBook Pro included
Regular team off-sites
Permanent contract
Engineering Manager
Engineering Manager

Jackalope Digital LLC • Berlin

Hybrid
EUR 110.000 - 170.000
Remote work option
Office in Berlin
Competitive compensation
+2
Principal Full Stack Developer (TypeScript)
Principal Full Stack Developer (TypeScript)

Cosuno • Berlin

Remote
EUR 110.000 - 140.000
Competitive salary
Remote work options
Flexible working hours
+2
Senior Full Stack Developer (TypeScript)
Senior Full Stack Developer (TypeScript)

Cosuno • Berlin

Remote
EUR 70.000 - 110.000
Competitive salary
Flexible working hours
Top-notch equipment
+2
Senior Analytics Engineer
Senior Analytics Engineer

Cosuno • Berlin

Hybrid
EUR 60.000 - 80.000
Competitive salary
Work-life balance
Top-notch equipment
+2
Engineering Manager
Engineering Manager

Meyandy LLC • Berlin

Hybrid
EUR 125.000 - 150.000
Remote work
Berlin office option
MacBook Pro
+2
Customer Success Manager
Customer Success Manager

Cosuno • Berlin

Hybrid
EUR 50.000 - 70.000
Flexible Arbeitsmodelle
Moderne Ausstattung
Teilnahme an Firmenevents
+1
Enterprise Account Executive
Enterprise Account Executive

Cosuno • Deutschland

Hybrid
EUR 60.000 - 80.000
Flexibilität im Homeoffice oder im Büro
Attraktive Vergütung mit Bonus
Regelmäßige Teamevents
AI Automation Engineer
AI Automation Engineer

Cosuno • Berlin

Hybrid
EUR 70.000 - 90.000
Opportunity to solve real business problems
Collaborate with industry leaders
Diversity and inclusion in the workplace