Senior Information Security Manager (GRC)
DeepLJob Description
📋 Description Own and run ISMS aligned with ISO 27001 and SOC 2 Type II Manage risk register, policy library, and third-party risk reviews Lead audits, evidence collection, and certification cycles Automate evidence collection with GRC tooling (e.g., Vanta) Embed security requirements into product/engineering workflows Partner with Legal, IT, and People to manage regulatory needs 🎯 Requirements 3-5 years in information security, GRC, or compliance Hands-on ISO 27001 and SOC 2 Type II program/audit experience HIPAA or BSI C5 a strong plus GRC/evidence automation tooling experience (Vanta or equivalent) Ability to shift ownership to product/engineering teams Fluent English and German (C1) preferred 🎁 Benefits Hybrid work, flexible hours Virtual Shares and ownership mindset Regular in-person team events and monthly hack days 30 days annual leave, mental health resources Competitive, location-aware benefits