ISO 27001 Internal Auditor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
ISO 27001 Internal Auditor (Cybersecurity): Managing end-to-end internal audits for customers to ensure certification readiness with an accent on evidence review, non-conformity identification, and clear reporting. Focus on maintaining audit independence, streamlining compliance processes, and providing actionable guidance to non-technical stakeholders.
Location: Must be based within +/- 2 hours of Germany (GMT+1)
Company
is a high-growth startup automating security compliance for modern companies, backed by top-tier VCs.
What you will do
- Own internal audits from kickoff to final report delivery.
- Review and sample evidence on the platform against ISO 27001 controls.
- Conduct customer calls to explain findings and non-conformities.
- Write clear, actionable reports for non-technical founders.
- Manage multiple audit timelines simultaneously.
- Provide structured product feedback to improve framework content and platform features.
Requirements
- English: C2 level proficiency is essential.
- Must be based within +/- 2 hours of Germany (GMT+1).
- Up to 2 years of information security background.
- Hands-on experience with at least 10+ ISO 27001 internal audits.
- PECB ISO 27001 Lead Auditor certification or direct equivalent.
- Direct experience auditing within a modern GRC platform.
Nice to have
- Experience auditing or implementing TISAX, ISO 42001, NIS2, or SOC 2.
- Experience at an early-stage startup (Seed to Series B).
- Exposure to modern SaaS products and cross-functional work.
Culture & Benefits
- 100% remote work environment using Gather for daily syncs.
- Competitive local salaries and generous equity package.
- €1,000 annual personal development budget.
- Home office budget and access to co-working spaces.
- 26 days of holiday plus local public holidays.
- Comprehensive health insurance and annual company retreats.
Hiring process
- Intro call with the Talent team (45 min).
- Take-home assessment.
- Assessment review and interview with the Compliance Team (1.5 hr).
- Final interview with the CTO (45 min).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →