Назад
3 часа назад

Senior Information Security Manager (GRC)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Information Security Manager (GRC): Operating and continuously improving an information security and compliance program for a SaaS product with an accent on ISO 27001, SOC 2 Type II, risk management, and audit automation. Focus on designing pragmatic controls, embedding evidence ownership across engineering and product teams, and making calculated risk decisions that keep the business moving safely.

Location: Munich, Berlin, or Cologne, Germany. Hybrid work with office attendance twice a week and flexible working hours.

Company

DeepL is an AI product and research company building secure Language AI solutions for translation, writing improvement, and real-time voice translation.

What you will do

  • Own and continuously improve the Information Security Management System in alignment with ISO 27001 and SOC 2 Type II.
  • Maintain the risk register, policy library, vendor risk assessments, and control monitoring processes.
  • Coordinate certification and attestation audits with auditors, control owners, and leadership.
  • Build automated evidence collection workflows using GRC tools such as Vanta or equivalent platforms.
  • Partner with engineering, product, IT, People, and Legal to integrate security and compliance requirements into existing workflows.
  • Report audit readiness, open risks, remediation progress, and program status to stakeholders and leadership.

Requirements

  • 3–5 years of experience in information security, GRC, or compliance, preferably in a SaaS scale-up.
  • Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits from control design through certification.
  • Practical experience with GRC and evidence automation tooling such as Vanta or an equivalent solution.
  • Strong risk judgment and the ability to make calculated, defensible decisions that support product and engineering teams.
  • Strong stakeholder management and communication skills when working with engineers, product managers, and leadership.
  • Fluent English and German at C1 level, or close to it, are required.

Nice to have

  • Experience with HIPAA and/or BSI C5.
  • Experience shifting evidence ownership to the teams generating the evidence.

Culture & Benefits

  • Internationally distributed workforce representing more than 90 nationalities.
  • Open communication, regular feedback, and an emphasis on empathy and a growth mindset.
  • Hybrid schedule, flexible working hours, and location-aware collaboration.
  • Virtual Shares for every employee.
  • Regular in-person team events, monthly Hack Fridays, 30 days of annual leave, and mental health resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →