Job
- Level
- Senior
- Job Feld
- IT, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Gehalt
- 80.000 bis 100.000€ Brutto/Jahr
- Ort
- Berlin
- Arbeitsmodell
- Full Remote, Hybrid
Job Zusammenfassung
In dieser Rolle übernimmst du die Verantwortung für Informationssicherheit und IT-Governance, führst die ISO 27001-Zertifizierung durch und verwaltest unser ISMS, während du die technische Umsetzung begleitest.
Job Technologien
Deine Rolle im Team
- You'll take full ownership of information security, compliance, and IT governance at Cosuno.
- You'll build and run our ISMS, lead us through ISO 27001 certification, and become the face of Cosuno's security posture toward enterprise customers and auditors.
- This is a senior individual contributor role with genuine end-to-end ownership.
- You won't be managing a team.
- You'll be the expert doing the work, backed by an Engineering team that implements technical changes you define, and with direct sponsorship from the CTO.
- Lead our ISO 27001 certification from gap analysis through audit, and run the ISMS afterwards: risk management, Statement of Applicability, internal audits, management reviews, and the annual control cycle.
- Write and maintain our security policies, making sure they describe how we actually work rather than how a template says we should.
- Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster.
- Represent Cosuno in supplier audits by enterprise customers: you'll face customer CISOs and auditors independently, in German or English as needed.
- Own the operational side of GDPR: drafting and negotiating DPAs (AVVs), managing our subprocessor list and notifications, running vendor security reviews, and supporting DSARs.
- Work with our external counsel and DPO where legal depth is required, while handling the day-to-day yourself.
- Own our identity and access management via JumpCloud (MDM, SSO, device policies), including joiner/mover/leaver processes and periodic access reviews.
- Define our IT security baseline: device hardening, SaaS tooling governance, security awareness training.
- You own these domains end to end.
- These responsibilities currently sit with our leadership team; the mandate is to take them over completely, not to assist.
- We treat security and compliance as a genuine part of how we build trust with enterprise customers, not as a checkbox exercise.
- When a policy requires technical changes (logging, backup configuration, access controls), you specify what's needed and our Engineering team builds it.
- You need to understand our stack well enough to have that conversation credibly, but you don't need to write the code yourself.
- We're 100 people, not 10,000.
- We want lean, largely automated processes and modern compliance tooling, not committees.
- We expect you to work heavily with AI tools such as Claude Code to draft policies, answer security questionnaires, analyze audit requirements, and build lightweight automations.
- The goal is a compliance function that runs on smart processes and AI leverage, not headcount.
- If your instinct when facing a 300-question security questionnaire is to build a system rather than start typing, you'll fit right in.
Unsere Erwartungen an dich
Qualifikationen
- You'll be a great fit if you have:
- Full professional fluency in German and English.
- A significant part of our compliance and customer-facing security work is conducted in German, and this is a firm requirement.
- You've built or run an ISMS before, ideally leading a company through certification.
- You know the Annex A controls and how companies actually implement them, and you can talk to an auditor without a script.
- Operational GDPR expertise.
- You can draft a DPA, you know your Art. 28 from your Art. 32, and you've handled subprocessor management, vendor reviews, and DSARs in practice.
- Genuine technical literacy.
- You understand how a modern SaaS product is built and run (cloud infrastructure, CI/CD, SaaS tooling).
- You can read an architecture diagram, ask engineers the right questions, and write a System Development Policy that matches reality.
- Fluency with AI tools in your daily work.
- You already use tools like Claude, Claude Code, or similar as a core part of how you get things done, whether that's drafting a policy, working through a questionnaire, or automating a recurring task.
- You see AI as a force multiplier for a one-person function, and you're eager to push it further.
- Independence in front of customers.
- You're comfortable being the sole security counterpart in an enterprise audit or a customer CISO call.
- The organisational maturity to run multiple threads in parallel: a certification project, an audit, three questionnaires, and a DPA negotiation, without things slipping.
- Bonus points for:
- ISO 27001 Lead Implementer / Lead Auditor certification, or CIPP/E
Erfahrung
- Deep, hands-on ISO 27001 experience.
- Experience with compliance automation tooling (Kertos, Vanta, Drata, Secfix, or similar)
- Experience building your own automations with AI (agents, scripts, or workflows for questionnaires, evidence collection, or vendor reviews)
- Experience administering an MDM / IdP (JumpCloud, Okta, Jamf, or similar)
- Experience with other frameworks relevant to our customers (SOC 2, TISAX, BSI C5, NIS2)
- Prior experience at a B2B SaaS company selling to enterprise customers
Unser Angebot
- Real ownership: You'll build the security and compliance function of a Series B company from a strong foundation, and shape it your way.
- Competitive compensation: A salary above the market average, reflecting the seniority of the role.
- Work-life balance: Work 100% remotely or from our modern office in Berlin, with flexible working hours.
- Top-notch equipment: A new MacBook Pro to ensure you have the best tools for the job.
- A great team: Regular company off-sites and team events that connect us as people, not just colleagues.
- Job security: A permanent contract in a stable, well-funded company.
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
Cosuno
Cosuno Ventures GmbH ist ein dynamisches Startup, das eine KI-gestützte Plattform für das Bauwesen entwickelt hat. Mit Fokus auf Ausschreibungs- und Vergabemanagement ermöglicht es Nutzern, ihre Projekte effizient zu steuern und mit einer Vielzahl von Fachleuten zu interagieren.
Description
- Unternehmenstyp
- Startup
- Arbeitsmodell
- Full Remote, Hybrid, Onsite
- Branche
- Bau, Immobilien, Haustechnik