Principal Information Security Manager - remote working within Germany

Remotely

United States

Hybrid

USD 140,000 - 200,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

LTIP (Long Term Incentive Plan)
Hybrid work option
Annual flex work allowance
31 vacation days + floating holiday
Pro rata Fridays off in August
Company pension scheme
Volunteers Day

Job summary

Staffbase is seeking a senior InfoSec leader to own and advance the security program across governance, risk and vendor security. This role partners with Legal, Procurement and Engineering to automate and improve compliant workflows in a SaaS environment.

You will report to the SVP of Business Operations & Transformation and drive investor-ready security practices. The position focuses on establishing scalable controls, incident response and awareness programs while maintaining strong customer

Qualifications

  • 5+ years of hands-on InfoSec in SaaS or B2B tech.
  • Proven ownership of ISO 27001 and/or SOC 2 programs.
  • Experience representing InfoSec to enterprise customers in reviews and escalations.
  • Must be fluent in English.
  • Comfortable with AI-driven tooling and automation opportunities in compliance and operations.

Responsibilities

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end: preparation, evidence collection, auditor management and remediation.
  • Own the control framework and keep it current as the business evolves.
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny.
  • Own responses to enterprise security questionnaires and RFPs.
  • Represent Staffbase credibly in security reviews, calls and audits.
  • Build scalable automation/templates to reduce response time without sacrificing quality.
  • Maintain the risk register and drive risk treatment decisions.
  • Own vendor security assessments for critical and high-risk suppliers.
  • Partner with Procurement and Legal on AI-assisted review workflows.
  • Own the internal security policy framework and enforce it.
  • Design and run security awareness programs that change behaviour.
  • Own the incident response plan and lead execution during incidents.
  • Coordinate with Engineering, Legal, and leadership during incidents.
  • Drive post-incident reviews and close findings with owners.

Skills

InfoSec leadership
ISO 27001 ownership
SOC 2 ownership
Enterprise security
English fluency
Automation mindset

Job description

About Staffbase

We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.

Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience.
We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.

Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.

This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.

The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to. You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.

What you’ll be doing

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.

You will own;

Compliance & Audit

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
  • Own the control framework and ensure it stays current as the business evolves
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny

Customer Trust

  • Own the response to enterprise customer security questionnaires and RFPs
  • Represent Staffbase credibly in customer security reviews, calls, and audits
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality

Risk & Vendor Security

  • Maintain the risk register and drive risk treatment decisions with relevant stakeholders
  • Own vendor security assessments for critical and high-risk suppliers
  • Partner with Procurement and Legal on AI-assisted review workflows

Policy & Awareness

  • Own the internal security policy framework, keep it current, understandable, and enforced
  • Design and run security awareness programs that change behaviour, not just tick boxes

Incident Response

  • Own the incident response plan and lead execution when incidents occur
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post-incident reviews and close findings with owners

What you need to be successful

Essential Experience

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in English
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations

Highly Desirable

  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built

What you'll get

  • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
  • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
  • Support - we’re offering a company pension scheme
  • Volunteers Day - you’ll get one day off per year for supporting a social project
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 140,000 - 200,000
Remote work
Equity package
Development budget
+5
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Senior Staff Software Security Engineer
Senior Staff Software Security Engineer

United States Digital Space LLC • Bellevue (CA)

On-site
USD 247,000 - 290,000
Health insurance
Equity
401(k) matching
+2
IT Manager
IT Manager

SecureBio, LLC • Cambridge (MA)

Hybrid
USD 140,000 - 165,000
401(k) match
Relocation assistance
Commuter benefits
+3
Security & Trust Engineer (SF-based)
Security & Trust Engineer (SF-based)

Alex AI • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision insurance
FSA, DCFSA, HSA options
Flexible paid time off (PTO)
+5
Senior Director, Security Engineering
Senior Director, Security Engineering

iterable • United States

Remote
USD 220,000 - 300,000
Equity
401(k) plan
Medical insurance
+8
Security & Trust Engineer (SF-based)
Security & Trust Engineer (SF-based)

alexai • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Security & Trust Lead
Security & Trust Lead

Alex AI • San Francisco (CA)

On-site
USD 150,000 - 180,000
Healthcare
Vision insurance
Dental insurance
+5
Security Analyst
Security Analyst

AbsenceSoft • Denver (CO)

Hybrid
USD 62,000 - 77,000
Equity opportunities
Performance-based bonus
Remote-first flexibility
+1
Principal Product Cybersecurity Assurance Engineer
Principal Product Cybersecurity Assurance Engineer

Groupe-Ebra-1 • Cambridge (MA)

On-site
USD 150,000 - 230,000