Principal Information Security Manager @Staffbase
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay

[Hiring] Principal Information Security Manager @Staffbase

YDay - Staffbase is hiring a remote Principal Information Security Manager. πŸ’Έ Salary: unspecified πŸ“Location: Germany

Role Description

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors, and enterprise customers.

You will own:

  • Compliance & Audit
    • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation.
    • Own the control framework and ensure it stays current as the business evolves.
    • Prepare the InfoSec program for investor and M&A due diligence scrutiny.
  • Customer Trust
    • Own the response to enterprise customer security questionnaires and RFPs.
    • Represent Staffbase credibly in customer security reviews, calls, and audits.
    • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality.
  • Risk & Vendor Security
    • Maintain the risk register and drive risk treatment decisions with relevant stakeholders.
    • Own vendor security assessments for critical and high-risk suppliers.
    • Partner with Procurement and Legal on AI-assisted review workflows.
  • Policy & Awareness
    • Own the internal security policy framework, keep it current, understandable, and enforced.
    • Design and run security awareness programs that change behaviour, not just tick boxes.
  • Incident Response
    • Own the incident response plan and lead execution when incidents occur.
    • Coordinate with Engineering, Legal, and leadership during incidents.
    • Drive post-incident reviews and close findings with owners.

Qualifications

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company.
  • Proven ownership of ISO 27001 and/or SOC 2 programs.
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations.
  • Must be fluent in English.
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations.

Requirements

  • Experience supporting or preparing for M&A or investor due diligence processes (highly desirable).
  • Background working alongside Legal, Procurement, and Engineering (highly desirable).
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate) (highly desirable).
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent (highly desirable). Certification matters less than what you have built.

Benefits

  • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan).
  • Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560.
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August.
  • Support - we’re offering a company pension scheme.
  • Volunteers Day - you’ll get one day off per year for supporting a social project.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Germany
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Principal Information Security Manager @Staffbase
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Germany
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 124,526+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later