ISO 27001 Internal Auditor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
ISO 27001 Internal Auditor (Cybersecurity): Performing end-to-end internal audits for customers to ensure readiness for certification with an accent on evidence review and non-conformity reporting. Focus on assessing ISO 27001 controls, delivering actionable reports for founders, and developing repeatable audit structures for GRC frameworks.
Location: Remote (Europe), must be based in EU time zones (+/- 2hrs from Germany GMT+1)
Company
is a startup automating security compliance (ISO 27001, GDPR, TISAX, SOC 2) for modern companies to reduce manual workloads.
What you will do
- Own end-to-end internal audits for customers, from kickoff through to the final report.
- Review and sample evidence on the platform against relevant ISO 27001 controls.
- Lead customer calls to communicate findings and non-conformities.
- Translate technical findings into clear, actionable language for non-technical founders.
- Develop repeatable audit structures for TISAX and ISO 42001 frameworks.
- Provide structured product feedback to improve the GRC platform.
Requirements
- German (C1/C2) and fluent English are essential.
- Must be located within EU time zones (+/- 2 hours from Germany GMT+1).
- Up to 2 years of experience in information security.
- Hands-on experience running 10+ internal audits personally.
- PECB ISO 27001 Lead Auditor certification or a direct equivalent.
- Direct experience auditing inside a modern GRC platform.
Nice to have
- Experience auditing or implementing TISAX, ISO 42001, NIS2, or SOC 2.
- Experience working in early-stage startups (Seed to Series B).
- Exposure to modern SaaS products and cross-functional collaboration with product teams.
Culture & Benefits
- 100% remote work utilizing Gather as a virtual office.
- Competitive local salaries and a generous equity package.
- €1,000 annual personal development budget.
- Home office budget and access to co-working spaces.
- 26 days of holiday plus local public holidays.
- Comprehensive health coverage and annual team retreats.
Hiring process
- Introductory call with the Talent team (45 min).
- Take-home assessment.
- Assessment review and interview with the Compliance Team (1.5 hr).
- Final interview with the CTO (45 min).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →