Doodle is a B2B SaaS platform used by millions of professionals to coordinate meetings and collaboration. As we grow, trust has become one of our most valuable products. Every enterprise deal, every AI feature, every new hire depends on a secure, compliant, well run IT foundation.
You are more than an IT and Security lead. You own the governance, compliance, and operational backbone that lets Doodle move fast without breaking trust. Working closely with the CEO, CFO, PeopleOps, and external partners, you will run our security stack, our compliance programmes, and our AI governance framework, and you will lead the IT team that keeps Doodle running day to day.
As Lead, IT Operations, Cyber Security and Compliance, you will own security, compliance, and IT operations across Doodle.
- Run day to day IT for 100+ employees across Berlin, remote EU, and our contractor base, including onboarding and offboarding, access provisioning, device management, and service desk.
- Own and continuously rationalize our SaaS portfolio of approximately 30 tools.
- Design and automate IT and PeopleOps workflows, including ticketing based onboarding with compliance gates such as NDA sign off, reducing manual work and strengthening contractor governance.
- Evaluate and select tooling, including CLM platforms, to enable self serve, scalable processes.
- Operate and evolve Doodle's full security toolset, including SentinelOne and CrowdStrike for EDR, Jamf Pro and JumpCloud for MDM, Okta and JumpCloud for IAM and SSO, email security, and KnowBe4 for security awareness.
- Lead platform migrations and evaluate new security technologies as our security stack continues to mature.
- Own and drive SOC 2 Type II, ISO 27001, HIPAA, and ISO 42001 programmes simultaneously.
- Serve as Privacy Officer, managing the DPA portfolio and the relationship with our external DPO.
- Maintain a live, prioritized risk register and drive remediation across more than 10 concurrent risk items.
- Run a structured vendor due diligence programme, including SOC 2 reviews, security questionnaires, and code of conduct sign off.
- Support enterprise sales and customer security reviews across regulated industries, including government, energy, and healthcare.
- Design and own Doodle's AI governance framework, including agentic AI security controls, EU AI Act assessments, and risk management for AI tools and external contributors such as MCP and Cursor.
- Translate AI risk into practical policy, risk register updates, and technical enforcement through our SSE platform.
- Author board level cybersecurity posture presentations using the NIST CSF 2.0 framework.
- Translate technical and security risk into clear business language for the CEO, CFO, and Board.Nice to Have
Experience supporting enterprise customers in regulated verticals such as government, energy, or healthcare.
Experience with Netskope or similar SSE platforms.
Experience automating IT workflows using tools such as Linear.
Background in a high growth B2B SaaS environment.
Initial Application Review + BRYQ Assessment
Hiring Manager Interview
Technical Assessment
Cross Functional Technical Interview
Executive Interview + HR Interview
At Doodle, we are committed to providing an environment of mutual trust and respect, where equal employment opportunities are available to all applicants and teammates without regard to age, race, color, disability, religion, gender, or sexual orientation. Diversity and inclusion are important to us because the best products are built by teams with different experiences, perspectives, and backgrounds.
IMPORTANT NOTICE: Please note that we can only consider your application if you are based and have the right to work in Germany. At this time, we are unable to sponsor visas for this position or support relocation.