Tech Stack
Job Description, Responsibilities & Requirements
About the Position
We are seeking a Principal Information Security Manager to lead our ISO 27001 and SOC 2 audit cycles, ensuring compliance and enterprise customer trust. This role is based in Chemnitz, Germany, with the possibility of remote work within Germany, and also available in Berlin and Dresden.
Responsibilities
You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
Compliance & Audit
- Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
- Own the control framework and ensure it stays current as the business evolves
- Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
- Own the response to enterprise customer security questionnaires and RFPs
- Represent Staffbase credibly in customer security reviews, calls, and audits
- Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
Risk & Vendor Security
- Maintain the risk register and drive risk treatment decisions with relevant stakeholders
- Own vendor security assessments for critical and high-risk suppliers
- Partner with Procurement and Legal on AI-assisted review workflows
Policy & Awareness
- Own the internal security policy framework, keep it current, understandable, and enforced
- Design and run security awareness programs that change behavior, not just tick boxes
Incident Response
- Own the incident response plan and lead execution when incidents occur
- Coordinate with Engineering, Legal, and leadership during incidents
- Drive post-incident reviews and close findings with owners
Requirements
Essential Experience
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in German and English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Highly Desirable
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
We Offer
- Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
- Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
- Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
- Support - we’re offering a company pension scheme
- Volunteers Day - you’ll get one day off per year for supporting a social project
About the Company
We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels – intranet, employee app and email solutions – create engaging experiences that connect and empower employees.
Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 2,000+ customers – reaching over 16.4 million employees – in transforming their employee experience.
We are proud to be a Unicorn company – privately valued at over $1 billion – demonstrating strong growth, innovation, and lasting impact in our industry.
Together, we’re shaping the future of workplace communication.