Logo Cosuno

Senior IT Security Manager

Neu

Job

  • Level
    Senior
  • Job Feld
    IT, Security
  • Anstellung
    Vollzeit
  • Vertragsart
    Unbefristetes Dienstverhältnis
  • Gehalt
    80.000 bis 100.000€ Brutto/Jahr
  • Ort
    Berlin
  • Arbeitsmodell
    Full Remote, Hybrid
  • Job Zusammenfassung

    In dieser Rolle übernimmst du die Verantwortung für Informationssicherheit und IT-Governance, führst die ISO 27001-Zertifizierung durch und verwaltest unser ISMS, während du die technische Umsetzung begleitest.

    Job Technologien

    Deine Rolle im Team

    • You'll take full ownership of information security, compliance, and IT governance at Cosuno.
    • You'll build and run our ISMS, lead us through ISO 27001 certification, and become the face of Cosuno's security posture toward enterprise customers and auditors.
    • This is a senior individual contributor role with genuine end-to-end ownership.
    • You won't be managing a team.
    • You'll be the expert doing the work, backed by an Engineering team that implements technical changes you define, and with direct sponsorship from the CTO.
    • Lead our ISO 27001 certification from gap analysis through audit, and run the ISMS afterwards: risk management, Statement of Applicability, internal audits, management reviews, and the annual control cycle.
    • Write and maintain our security policies, making sure they describe how we actually work rather than how a template says we should.
    • Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster.
    • Represent Cosuno in supplier audits by enterprise customers: you'll face customer CISOs and auditors independently, in German or English as needed.
    • Own the operational side of GDPR: drafting and negotiating DPAs (AVVs), managing our subprocessor list and notifications, running vendor security reviews, and supporting DSARs.
    • Work with our external counsel and DPO where legal depth is required, while handling the day-to-day yourself.
    • Own our identity and access management via JumpCloud (MDM, SSO, device policies), including joiner/mover/leaver processes and periodic access reviews.
    • Define our IT security baseline: device hardening, SaaS tooling governance, security awareness training.
    • You own these domains end to end.
    • These responsibilities currently sit with our leadership team; the mandate is to take them over completely, not to assist.
    • We treat security and compliance as a genuine part of how we build trust with enterprise customers, not as a checkbox exercise.
    • When a policy requires technical changes (logging, backup configuration, access controls), you specify what's needed and our Engineering team builds it.
    • You need to understand our stack well enough to have that conversation credibly, but you don't need to write the code yourself.
    • We're 100 people, not 10,000.
    • We want lean, largely automated processes and modern compliance tooling, not committees.
    • We expect you to work heavily with AI tools such as Claude Code to draft policies, answer security questionnaires, analyze audit requirements, and build lightweight automations.
    • The goal is a compliance function that runs on smart processes and AI leverage, not headcount.
    • If your instinct when facing a 300-question security questionnaire is to build a system rather than start typing, you'll fit right in.

    Unsere Erwartungen an dich

    Qualifikationen

    • You'll be a great fit if you have:
    • Full professional fluency in German and English.
    • A significant part of our compliance and customer-facing security work is conducted in German, and this is a firm requirement.
    • You've built or run an ISMS before, ideally leading a company through certification.
    • You know the Annex A controls and how companies actually implement them, and you can talk to an auditor without a script.
    • Operational GDPR expertise.
    • You can draft a DPA, you know your Art. 28 from your Art. 32, and you've handled subprocessor management, vendor reviews, and DSARs in practice.
    • Genuine technical literacy.
    • You understand how a modern SaaS product is built and run (cloud infrastructure, CI/CD, SaaS tooling).
    • You can read an architecture diagram, ask engineers the right questions, and write a System Development Policy that matches reality.
    • Fluency with AI tools in your daily work.
    • You already use tools like Claude, Claude Code, or similar as a core part of how you get things done, whether that's drafting a policy, working through a questionnaire, or automating a recurring task.
    • You see AI as a force multiplier for a one-person function, and you're eager to push it further.
    • Independence in front of customers.
    • You're comfortable being the sole security counterpart in an enterprise audit or a customer CISO call.
    • The organisational maturity to run multiple threads in parallel: a certification project, an audit, three questionnaires, and a DPA negotiation, without things slipping.
    • Bonus points for:
    • ISO 27001 Lead Implementer / Lead Auditor certification, or CIPP/E

    Erfahrung

    • Deep, hands-on ISO 27001 experience.
    • Experience with compliance automation tooling (Kertos, Vanta, Drata, Secfix, or similar)
    • Experience building your own automations with AI (agents, scripts, or workflows for questionnaires, evidence collection, or vendor reviews)
    • Experience administering an MDM / IdP (JumpCloud, Okta, Jamf, or similar)
    • Experience with other frameworks relevant to our customers (SOC 2, TISAX, BSI C5, NIS2)
    • Prior experience at a B2B SaaS company selling to enterprise customers

    Unser Angebot

    • Real ownership: You'll build the security and compliance function of a Series B company from a strong foundation, and shape it your way.
    • Competitive compensation: A salary above the market average, reflecting the seniority of the role.
    • Work-life balance: Work 100% remotely or from our modern office in Berlin, with flexible working hours.
    • Top-notch equipment: A new MacBook Pro to ensure you have the best tools for the job.
    • A great team: Regular company off-sites and team events that connect us as people, not just colleagues.
    • Job security: A permanent contract in a stable, well-funded company.

    Themen mit denen du dich im Job beschäftigst

    Job Standorte

    • Standort Berlin

      Deutschland

    Das ist dein Arbeitgeber

    Cosuno

    Cosuno

    Cosuno Ventures GmbH ist ein dynamisches Startup, das eine KI-gestützte Plattform für das Bauwesen entwickelt hat. Mit Fokus auf Ausschreibungs- und Vergabemanagement ermöglicht es Nutzern, ihre Projekte effizient zu steuern und mit einer Vielzahl von Fachleuten zu interagieren.

    Description

  • Unternehmenstyp
    Startup
  • Arbeitsmodell
    Full Remote, Hybrid, Onsite
  • Branche
    Bau, Immobilien, Haustechnik
  • Logo Cosuno

    Senior IT Security Manager

    Gehalt
    80.000 bis 100.000€ Brutto/JahrNetto aus dem Bruttogehalt im Inserat mit Steuerklasse I umgerechnet.48.049 bis 58.031 € netto/Jahr · Steuerklasse I
    Ort
    Berlin
    Arbeitsmodell
    Full Remote, Hybrid
    Diversität
    Für alle Personen geeignet (m/w/d)

    Weitere Jobs