DeepL7 дней назад

Senior Information Security Manager (GRC)

Зарплата не указана
РЫНОК
15 000медиана по профессии
CISO · 7 вакансий с указанной зарплатой
7 333половина предложений: 9 417–15 04219 167
Работодатель не указал зарплату — сравните с рынком сами.
Полная занятостьMunich

Обязанности

  • 01Own and continuously improve our Information Security Management System (ISMS), keeping it aligned with ISO 27001, SOC 2 Type II, and, where relevant, HIPAA and BSI C5
  • 02Maintain and mature our risk register, policy library, vendor/third-party risk assessments, and control monitoring
  • 03Act as a hands-on participant in audits, working directly with auditors, control owners, and leadership to prepare, execute, and close out certification and attestation cycles efficiently rather than through brute force
  • 04Build and refine evidence collection processes using automation and GRC tooling (e.g. Vanta or similar), reducing manual overhead and audit fatigue across the company
  • 05Design and roll out a model where product and engineering teams own their evidence throughout the control lifecycle, rather than compliance chasing people down before every audit
  • 06Assess risk pragmatically: identify real security and compliance exposure, size it accurately, and make calculated calls that unblock product and engineering teams
  • 07Partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows rather than bolting them on afterward
  • 08Track regulatory and customer-driven compliance requirements — new customer security questionnaires, evolving frameworks — and translate them into practical, actionable controls
  • 09Report on the state of the security and compliance program to stakeholders and leadership, including audit readiness, open risks, and remediation progress

Требования

  • 013-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company, and ideally at scaleup pace and scale
  • 02Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits, from control design through evidence collection to certification
  • 03Experience with HIPAA and/or BSI C5 is a strong plus
  • 04Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent), including building smooth, low-friction processes around it
  • 05A track record of building processes that shift evidence ownership to the teams generating the evidence, rather than centralizing it all in compliance
  • 06Sound risk judgment: comfortable making calculated, defensible risk decisions to keep product teams unblocked, rather than reflexively blocking
  • 07Strong stakeholder management skills; able to work credibly with engineers, product managers, and leadership without becoming an obstacle
  • 08Fluent English and German language skills at C1 level (or close by) are required
  • 09Clear, structured communicator who can translate compliance requirements into language engineering and product teams actually act on

Условия

  • 01Diverse and internationally distributed team: joining our team means becoming part of a large, global community with people of more than 90 nationalities. We're more than just colleagues; we're a group of professionals with a shared mission to conne