Role Overview
▪ Job Title: IT Security & Compliance Lead
▪ Department / Team: Security & Compliance (working closely with Engineering & CTO)
▪ Reason for Hiring: Need full ownership of security & compliance as the company scales
▪ Reports to: CTO (close collaboration with CEO)
▪ Team Size: 10-person startup; sole dedicated security lead
▪ No. of Vacancies: 1
Location & Working Model
▪ Primary Location: Berlin Mitte, Germany
▪ Remote / Hybrid / On-Site Policy: Hybrid (0–2 home-office days per week); fully remote not possible
▪ Travel Requirements: None
Key Responsibilities
▪ Own security & compliance end-to-end (cloud, product, internal IT)
▪ Harden AWS/GCP environments: IAM, networking, encryption, logging, monitoring, detection
▪ Embed DevSecOps into SDLC: threat modeling & vulnerability management with engineers
▪ Maintain & improve ISO 27001 and C5 certifications; lead audits and corrective actions
▪ Manage external security work: penetration tests, security reviews, vendor assessments
▪ Design & enforce internal IT baseline: identity, MDM, device policies, access model, on/off-boarding
▪ Provide security training and guidance across the organization
Ideal Candidate Profile
Must-Haves:
▪ Hands-on cloud security (AWS or GCP) incl. Terraform IaC
▪ End-to-end ownership of ISO27001 or C5 certification & audits
▪ DevSecOps, secure SDLC, threat modeling, vulnerability management experience
▪ German & English – full professional fluency
▪ 5+ years in similar security/compliance roles
Nice-to-Haves:
▪ Healthcare / highly sensitive data environments
▪ Medical Device Regulation exposure (MDR, IEC 62304)
▪ AI/LLM security design experience
Dealbreakers / Red Flags:
▪ Policy-only background with no hands-on technical work
▪ Lacking audit ownership experience (ISO/C5/SOC2)
▪ Cannot work on-site in Berlin when required
Personality Traits:
▪ Reliable ▪ Autonomous ▪ Conscientious
Experience & Education
▪ Experience: Minimum 5 years in IT security & compliance with audit ownership
▪ Education: Bachelor’s degree required (field not specified)
▪ Specific Tools/Technologies: AWS, GCP, Terraform, logging/monitoring stacks, Vanta (for compliance evidence)
Job Type: Full-time
Pay: 60.000,00€ - 100.000,00€ per year
Application Question(s):
- Do you accept to work one site HQ & Locations: Berlin Mitte, Germany (primary and current office) ?
- What is your desired gross annual salary for this role?
- Do you have Minimum 5 years in IT security & compliance with audit ownership ?
Language:
- native german (Preferred)
Work Location: In person