Senior Information Security Specialist (German-speaking)

Secfix

2h ago • 1 views • 0 applications
Full-time Remote
Remote - Europe
Competitive
Full-time

Job Description

Senior Information Security Specialist (m/f/d)

Location: Remote (+/- 2hrs from Germany GMT+1). C1 or C2 German Language is essential.

At Secfix, we're not just automating security compliance; we're redefining it across Europe. We empower companies to achieve and maintain ISO 27001, GDPR, TISAX, and SOC 2 certifications swiftly and effortlessly, eliminating hundreds of hours of tedious manual work.

We're a high-performing, 100% remote team with hubs in Munich, Berlin, and London. Having recently closed our $12M Series A funding round with backing from leading VCs like Alstin Capital, Neosfer (Commerzbank), and Bayern Capital, we're poised for exponential growth. We're seeking passionate, execution-focused owners to help us become the undisputed leader in European compliance automation.

About the Role: Drive the Future of Compliance Automation

As we scale into more frameworks, expand our mid-market customer base, and grow our compliance team, we're looking for a Senior Information Security Specialist to significantly strengthen our compliance function. This pivotal role sits at the dynamic intersection of compliance delivery, content creation, and team mentorship.

You will take full ownership of the compliance knowledge embedded within our platform, provide crucial mentorship to our junior compliance specialists, offer expert support to our customer success team, and serve as the senior compliance voice for customers, auditors, and product development. You’ll work closely with our Co-founder & CISO and our CS Lead in a high-impact position that directly influences how Secfix delivers compliance – both as a service and as innovative in-app content.

What You'll Do: Own & Elevate Our Compliance Offering

You will be instrumental in shaping one of Secfix's most critical pillars: the unparalleled quality and expansive breadth of our compliance solutions. We foster an environment of autonomy, not micromanagement. With robust foundations and comprehensive context at your disposal, you'll have full ownership to test new approaches and deliver outstanding results, backed by a strong internal and external support network. Your responsibilities will include:

Own and drive the compliance roadmap within the Secfix platform, covering a diverse range of frameworks including ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand.
Implement ISO 27001 and adjacent frameworks end-to-end for our customers.
Mentor and upskill our compliance team: share your expertise, review work, and ensure consistency in audit practices and customer deliverables.
Conduct internal audits directly for strategic and complex customers, and meticulously review audits performed by junior team members to guarantee quality and consistency.
Act as a trusted compliance partner to Customer Success Managers and sales representatives, providing swift, reliable support for customer queries and joining calls when deep expertise is required.
Own the quality of all compliance content in the platform, including creating policies, evidence templates, compliance enablement playbooks for our CSMs, and security awareness trainings.
Identify and close framework gaps, incorporating valuable auditor feedback into both team practices and platform enhancements.
Partner strategically with Product and Engineering teams to translate complex compliance requirements into actionable product development initiatives.
Collaborate closely with CS, Product, and Founders to align compliance, customer, and overarching roadmap priorities.
Deepen relationships with our existing certification partners and train auditors on the Secfix platform to ensure their confident use during customer audits.

What You'll Bring: Your Expertise & Impact

German (C1/C2) and English (fluent) is an absolute must for this role.
5+ years of hands-on information security and GRC experience, specifically within B2B SaaS environments.
Proven track record having led 3+ successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company.
Hands-on experience with a GRC platform like Secfix, or similar GRC solutions.
Strong understanding of cloud infrastructure readiness across AWS, Azure, and GCP, coupled with experience in posture analysis and remediation planning.
Exceptional project management skills, with the ability to break down ambiguous initiatives into concrete, actionable deliverables, prioritize ruthlessly, and deliver results.
Excellent written communication skills, especially in producing clear, precise compliance content tailored for diverse audiences (auditors, founders, engineers).
A strong ownership mindset: you operate as a senior individual contributor, proactively driving initiatives without waiting for direction.

Bonus Points: Stand Out From The Crowd

Experience implementing one or two additional compliance frameworks (e.g., SOC 2, GDPR, NIS 2).
Experience mentoring or coaching colleagues in a compliance, audit, or GRC context.
Prior experience in a dynamic startup environment.

Why Join Secfix? Perks & Benefits

Remote Work: We are a 100% remote company with a vibrant virtual office experience in Gather.
Competitive Salary: Enjoy industry-competitive local salaries that are at or above market rates, aligning with a philosophy similar to GitLab.
Equity: Receive a generous equity package – we are all owners of Secfix and direct beneficiaries of our collective success.
Mentorship: Benefit from direct access to world-class mentors through our top VC and accelerator backing.
Development Budget: €1,000 annual personal development budget to fuel your continuous growth.
Home Office & Co-working: A dedicated home office budget and access to co-working spaces.
Holidays: 26 days of holiday + local public holidays.
Health Insurance: Comprehensive health coverage.
Annual Retreat: Connect and innovate at our exciting annual company retreats (our last one was in sunny Alicante, Spain!).
Company Events: Regular company-wide events to foster relationships and have fun.
Tech Equipment: Get set up with the latest tech equipment, including MacBook, monitors, and headphones.

Our Interview Process: Your Journey to Secfix

45 min - Intro call with our Talent team
Take-home Assessment
1.5hr - Assessment review and interview with our CS Lead and CEO
45 min - Final Founder Interview with Co-Founders (CTO & CISO)

Please note: We are an equal-opportunity and remote-only company. At this time, we can support hiring only within EU time zones. We leverage Gather as our virtual office to work in sync. As a fast-growing company, we believe in the need for a synchronous component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here.