Logo Staffbase GmbH

Principal Information Security Manager

Job

  • Level
    Senior
  • Job Feld
    IT, Security
  • Anstellung
    Vollzeit
  • Vertragsart
    Unbefristetes Dienstverhältnis
  • Ort
    Chemnitz
  • Arbeitsmodell
    Hybrid, Onsite
  • Job Zusammenfassung

    In dieser Position agierst du als Schlüsselperson im Bereich Informationssicherheit, leitest ISO 27001- und SOC 2-Audits, verwaltest Sicherheitsfragen von Kunden und entwickelst automatisierte Prozesse zur Risikobehandlung.

    Deine Rolle im Team

    • You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
    • You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.
    • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation.
    • Own the control framework and ensure it stays current as the business evolves.
    • Prepare the InfoSec program for investor and M&A due diligence scrutiny.
    • Own the response to enterprise customer security questionnaires and RFPs.
    • Represent Staffbase credibly in customer security reviews, calls, and audits.
    • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality.
    • Maintain the risk register and drive risk treatment decisions with relevant stakeholders.
    • Own vendor security assessments for critical and high-risk suppliers.
    • Partner with Procurement and Legal on AI-assisted review workflows.
    • Own the internal security policy framework, keep it current, understandable, and enforced.
    • Design and run security awareness programs that change behaviour, not just tick boxes.
    • Own the incident response plan and lead execution when incidents occur.
    • Coordinate with Engineering, Legal, and leadership during incidents.
    • Drive post-incident reviews and close findings with owners.

    Unsere Erwartungen an dich

    Qualifikationen

    • Proven ownership of ISO 27001 and/or SOC 2 programs.
    • Track record of representing InfoSec to enterprise customers, including security reviews and escalations.
    • Fluent in German and English.
    • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations.
    • Background working alongside Legal, Procurement, and Engineering.
    • Practical understanding of cloud security architecture (enough to challenge and validate, not operate).
    • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built.

    Erfahrung

    • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company.
    • Experience supporting or preparing for M&A or investor due diligence processes.

    Unser Angebot

    • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan).
    • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560.
    • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August.
    • Support - we're offering a company pension scheme.
    • Volunteers Day - you'll get one day off per year for supporting a social project.

    Themen mit denen du dich im Job beschäftigst

    Job Standorte

    • Standort Chemnitz

      Sachsen

      Deutschland

    Das ist dein Arbeitgeber

    Staffbase GmbH

    Staffbase GmbH

    Staffbase GmbH, gegründet 2014, ist ein innovatives Unternehmen, das interne Kommunikationslösungen entwickelt und Unternehmen dabei unterstützt, ihre Mitarbeiter zu vernetzen.

    Description

  • Unternehmenstyp
    Etablierte Firma
  • Arbeitsmodell
    Hybrid, Onsite
  • Branche
    Internet, IT, Telekom
  • Logo Staffbase GmbH

    Principal Information Security Manager

    Ort
    Chemnitz
    Arbeitsmodell
    Hybrid, Onsite
    Diversität
    Für alle Personen geeignet (m/w/d)

    Weitere Jobs