Information Security Lead

United States Digital Space LLC

United States

Remote

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
€1,000 annual development budget
Home office budget
Holidays: 26 days + public holidays
Health insurance
Annual retreat
Tech equipment: MacBook, monitors

Job summary

United States Digital Space LLC is seeking an Information Security Lead to strengthen our compliance function as we scale across frameworks and mid-market customers. You will own compliance knowledge in our platform, manage the team, support Customer Success, and be the senior voice for customers, auditors, and product.

You will partner with CS, Product and Founders to align compliance, customer, and roadmap priorities while deepening relationships with certification partners and auditors.

Qualifications

  • 7+ years hands-on information security and GRC in B2B SaaS
  • 2+ years in InfoSec leadership
  • Led 5+ ISO 27001 projects as implementer/auditor
  • Experience with posture analysis and remediation planning on cloud infra (AWS/Azure/GCP)
  • Ability to translate compliance gaps into product work
  • Excellent written compliance content for auditors, founders, engineers
  • Strong ownership and independent contributor mindset
  • Bachelor's degree in CS/IT/SE

Responsibilities

  • Own and drive the compliance roadmap inside the platform across ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA and more
  • Implement ISO 27001 end-to-end for customers
  • Hire, manage and upskill the compliance team and drive audits
  • Conduct internal audits for strategic customers and review audits by team members
  • Serve as compliance partner to CSMs and sales reps, joining calls when needed
  • Own the content quality in the platform (policies, templates, playbooks, trainings)
  • Close framework gaps and incorporate auditor feedback into practice and product
  • Collaborate with product and engineering to translate gaps into work
  • Align compliance with customer and roadmap priorities with CS, Product, Founders
  • Train auditors on the platform for customer audits
  • Support growth into more frameworks and mid-market customers
  • Interlock with Leadership on strategy and delivery

Skills

English fluent
InfoSec leadership
GRC experience
Cloud security (AWS/Azure/GCP)
Project management
Strong written comms
Ownership mindset

Education

Bachelor's degree in CS/IT/SE

Tools

GRC platform

Job description

Remote (+/- 2hrs from Germany, GMT+1). C1 or C2 English language proficiency is essential

At the company, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work.

the company is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused owners to help us automate security and compliance for modern companies and become the European compliance automation leader.

We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.

About the Role

We're hiring an Information Security Lead to strengthen our compliance function as the company scales into more frameworks, mid-market customers, and a growing compliance team. This role sits at the intersection of compliance delivery, content, and team support. You'll own the compliance knowledge that lives inside our platform, manage our compliance specialists, support our customer success team, and act as the senior compliance voice for customers, auditors, and product. You'll work closely with our co-founders and our CS Lead. This is a high-impact role with real influence on how the company delivers compliance: both as a service to customers and as content inside our app.

What You'll Do:

You will own one of the most important pillars of the company: the quality and breadth of our compliance offering. We don't (and can't afford to) micro-manage. We've built strong foundations and will give you full context on what works. You can test new approaches, but at the end of the day, you have full ownership of how you deliver results (with a strong support network from within and outside the company). You will:

  • Own and drive the compliance roadmap inside the the company platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand)
  • Implement ISO 27001 and adjacent frameworks end-to-end for customers
  • Hire, manage and upskill the compliance team: sharing expertise, reviewing work, and helping drive consistency in audits and customer deliverables
  • Conduct internal audits directly for strategic and complex customers, and review the internal audits performed by team members to drive quality and consistency
  • Act as a compliance partner to CSMs and sales reps: fast, reliable support for customer questions, and joining customer calls when deep expertise is needed
  • Own the quality of compliance content in the platform (including creating policies, evidence templates, compliance-enabled playbooks for our CSMs, security awareness trainings and more)
  • Close framework gaps and incorporate auditor feedback into both team practice and platform improvements
  • Partner with product and engineering to translate compliance gaps into structured product work
  • Collaborate closely with CS, Product, and Founders to align compliance, customer, and roadmap priorities
  • Deepen relationships with our existing certification partners and train auditors on the the company platform so they can confidently use it during customer audits
To be qualified for this role, you must have the following:
  • English (fluent) is a must for this role
  • 7+ years of hands-on information security and GRC experience in B2B SaaS, including at least 2 years in an InfoSec leadership role
  • Led 5+ successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company
  • Hands-on experience with a GRC platform like the company, or similar GRC platforms
  • Cloud infrastructure readiness across AWS, Azure, and GCP; experience with posture analysis and remediation planning
  • Strong project management skills with the ability to break down ambiguous initiatives into concrete deliverables, prioritise ruthlessly, and ship
  • Excellent written communication, especially in producing clear, precise compliance content for diverse audiences (auditors, founders, engineers)
  • Strong ownership mindset: operates as a senior individual contributor without waiting for direction
  • Bachelor's degree in Computer Science, Information Technology, Software Engineering or a related field
Bonus:
  • Experience implementing one or two additional compliance frameworks (e.g. SOC 2, GDPR, NIS 2, etc.)
  • Experience in a startup environment is a plus
What we offer
  • Remote Work: 100% remote work with a virtual office in Gather.
  • Competitive Salary: Industry-competitive local salaries. We pay local rates that are at or above the market. We share this philosophy with GitLab.
  • Equity: Generous equity package – we’re all owners of the company and beneficiaries of our collective success.
  • Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors.
  • Development Budget: €1,000 annual personal development budget.
  • Home office Budget: Home office budget and access to co-working spaces.
  • Holidays: 26 days holiday + local public holidays.
  • Health Insurance: Comprehensive health coverage.
  • Annual Retreat: Annual retreat to build connections and inspire ideas (this year we spent an amazing time in Alicante, Spain!).
  • Company Events: Company-wide events to build relationships and have some fun!
  • Tech Equipment: Latest tech equipment (MacBook, monitors, headphones).
Interview Process:
  • 45 min - Intro call with Talent team
  • Take-home Assessment
  • 1.5hr Assessment review and interview with our CS Lead and CEO
  • 45 min - Final Founder Interview with Co-Founders (CTO & CISO)

Please note: We are an equal-opportunity employer and remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here.

Find Jobs in Germany on Arbeitnow

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Specialist
Senior Information Security Specialist

Secfix • Germany (OH)

Hybrid
EUR 90,000 - 130,000
Remote work
Equity
Mentorship
+7
Customer Success Manager (German-speaking)
Customer Success Manager (German-speaking)

Secfix • United States

Remote
EUR 55,000 - 90,000
Remote work across EU time zones
Equity package
26 days holidays + public holidays
+4
Principal Information Security Manager - remote working within Germany
Principal Information Security Manager - remote working within Germany

Remotely • United States

Remote
USD 140,000 - 200,000
LTIP (Long Term Incentive Plan)
Hybrid work option
Annual flex work allowance
+4
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s

Stott and May • New York (NY)

On-site
USD 180,000 - 260,000
Security & Compliance Engineer - Remote Germany
Security & Compliance Engineer - Remote Germany

Linro • United States

Remote
USD 104,000 - 150,000
Equity
Competitive salary
European offsite
+1
Principal Information Security Manager (Fully Remote)
Principal Information Security Manager (Fully Remote)

Staffbase • United States

Remote
USD 140,000 - 210,000
31 vacation days
Flexible working time
LTIP
GRC Specialist (Governance Risk and Compliance) (Fully Remote)
GRC Specialist (Governance Risk and Compliance) (Fully Remote)

Secfix • United States

Remote
USD 120,000 - 180,000
Annual development budget
Home office budget
Co-working spaces
+2
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Global Information Security Lead 100% (f/m/d)
Global Information Security Lead 100% (f/m/d)

Screening Eagle Technologies AG • Indiana (PA)

On-site
USD 90,000 - 120,000
Competitive remuneration package
Team building events
Opportunities for professional development
+1
Lead Governance, Risk, and Compliance Engineer - Remote
Lead Governance, Risk, and Compliance Engineer - Remote

Jobgether • Illinois

On-site
USD 100,000 - 140,000
Flexible work environment
Employer contributions towards healthcare
Equity in the company
+3