368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$72k – $176k per year (Estimated)
Location
Remote/Hybrid (Germany)
Seniority
Principal · 5+ years exp
Overview
Company
Impact
Profile match
In a polarized world, we inspire people to achieve great things together. Our mission is o help organizations unlock the power of inspirational communication so they can thrive in the Narrative Age. Our award-winning communications channels - int...

About Staffbase

We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Ourindustry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.

Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis-St. Paul, our diverse team of 750+ employees supports 2,000+ customers-reaching over 16.4 million employees-in transforming their employee experience.

We are proud to be a Unicorn  company-privately valued at over $1 billion-demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.

Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.

This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.

The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to. 

You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.

What you’ll be doing

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.

You will own;

Compliance & Audit

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
  • Own the control framework and ensure it stays current as the business evolves
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny

Customer Trust

  • Own the response to enterprise customer security questionnaires and RFPs
  • Represent Staffbase credibly in customer security reviews, calls, and audits
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality

Risk & Vendor Security

  • Maintain the risk register and drive risk treatment decisions with relevant stakeholders
  • Own vendor security assessments for critical and high-risk suppliers
  • Partner with Procurement and Legal on AI-assisted review workflows

Policy & Awareness

  • Own the internal security policy framework, keep it current, understandable, and enforced
  • Design and run security awareness programs that change behaviour, not just tick boxes

Incident Response

  • Own the incident response plan and lead execution when incidents occur
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post-incident reviews and close findings with owners

What you need to be successful

Essential Experience

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in German and English
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations

Highly Desirable

  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built

What you'll get 

  • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
  • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
  • Support - we’re offering a company pension scheme
  • Volunteers Day - you’ll get one day off per year for supporting a social project

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$184k – $225k per year • Remote • Internship • PhD
AI/ML
AI Agents
LLM Guardrails
DevOps
CI/CD
Cybersecurity
ISO 27001
SOC 2
Apply
$195k – $229k per year • Remote • Full-Time • 6+ years exp
Node JS
TypeScript
JavaScript
AI/ML
AI Agents
Frontend
React.js
DevOps
AWS
Azure
GCP
Cybersecurity
FedRAMP
HIPAA
ISO 27001
NIST 800-53
SOC 2
Apply
$200k – $240k per year • Remote/Hybrid • Full-Time • 8+ years exp • San Francisco
AI/ML
Ray
OpenAI
DevOps
AWS
Azure
Kubernetes
Cybersecurity
ISO 27001
SOC 2
Apply
$36k – $90k per year (Estimated) • In office • 5+ years exp • Bengaluru
C#
Java
TypeScript
DevOps
Azure
Chaos Engineering
CI/CD
Grafana
Kubernetes
OpenTelemetry
Platform Engineering
Prometheus
Pulumi
Self-Healing
Terraform
Cybersecurity
FedRAMP
GDPR
SOC 2
Apply
$33k – $83k per year (Estimated) • In office • 5+ years exp • Pune
C#
Java
TypeScript
DevOps
Azure
Chaos Engineering
CI/CD
Grafana
Kubernetes
OpenTelemetry
Platform Engineering
Prometheus
Pulumi
Self-Healing
Terraform
Cybersecurity
FedRAMP
GDPR
SOC 2
Apply
$75k – $151k per year (Estimated) • Remote/Hybrid • 5+ years exp • Berlin
Go
JavaScript
Kotlin
Node JS
TypeScript
AI/ML
AI Agents
Frontend
React.js
DevOps
CI/CD
Docker
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Terraform
GitHub
QA
Cypress
Selenium
Apply
$78k – $173k per year (Estimated) • Remote/Hybrid • Berlin
JavaScript
Kotlin
Python
TypeScript
AI/ML
AI Agents
DevOps
CI/CD
Kubernetes
Kustomize
Terraform
Apply
$101k – $214k per year (Estimated) • Remote/Hybrid • Chemnitz
Go
JavaScript
Kotlin
TypeScript
AI/ML
AI Agents
Frontend
React.js
Tailwind CSS
DevOps
CI/CD
Docker
Terraform
QA
Playwright
Apply
$101k – $214k per year (Estimated) • Remote/Hybrid • Berlin
Go
JavaScript
Kotlin
TypeScript
AI/ML
AI Agents
Frontend
React.js
Tailwind CSS
DevOps
CI/CD
Docker
Terraform
QA
Playwright
Apply
$78k – $173k per year (Estimated) • Remote/Hybrid • Dresden
JavaScript
Kotlin
Python
TypeScript
AI/ML
AI Agents
DevOps
CI/CD
Kubernetes
Kustomize
Terraform
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.