首席信息安全管理经理 - 德国境内远程办公
Principal Information Security Manager - remote working within Germany
关于Staffbase
我们激励人们共同取得卓越成就。我们的使命是帮助组织通过首个原生AI的员工体验平台,释放鼓舞人心的沟通力量。我们行业领先的、屡获殊荣的代理型AI通讯渠道——内部网、员工应用和电子邮件解决方案——创造了引人入胜的体验,连接并赋能员工。
总部位于德国开姆尼茨和纽约市,在柏林、伦敦、悉尼、东京、布拉格和明尼阿波利斯-圣保罗设有办公室,我们的550多名员工团队为1500多家客户——覆盖超过1400万名员工——提供支持,助力他们提升员工体验。
我们自豪地成为独角兽公司,私人估值超过10亿美元,这体现了我们在行业中的强劲增长、创新和持久影响。我们正在共同塑造未来的工作场所沟通方式。
我们的信息安全计划符合实际需求且运营稳健。下一阶段的目标是使其具备投资者准备就绪性、AI高效性,并能够大规模维持企业客户的信任。
这不是从零开始的职位。它代表着成熟度的提升:减少人工流程,增强治理能力。
该职位位于信息安全部门的核心;你将跨团队协调,负责成果并代表该职能。你习惯于成为客户和审计人员交谈的对象。
你思考的是项目和系统,而不是任务。你能够识别哪些手动工作可以由工具或AI辅助的工作流替代,并被赋予推动这种变革的权力,因为我们正在公司范围内构建以AI驱动的运营模式。
你将负责的工作
你将在财务与运营部门担任信息安全部门的高级副手,负责日常运作,代表该部门内部和外部,并使其运行更加顺畅和智能。
你直接向首席业务运营与转型官汇报,并与法务、采购、工程、外部审计师和企业客户紧密合作。
你将负责:
合规与审计
- 全程主导ISO 27001和SOC 2审计周期,包括准备、证据收集、审计师管理及问题整改
- 管理控制框架,并确保随着业务发展保持最新
- 为投资者和并购尽职调查做好信息安全计划的准备
客户信任
- 负责企业客户的安全问卷和RFP的响应
- 在客户面前可信地代表Staffbase
查看英文原文
About Staffbase
We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.
Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience.
We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.
Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.
This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.
The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.
You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.
What you’ll be doing
You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.
You will own;
Compliance & Audit
- Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
- Own the control framework and ensure it stays current as the business evolves
- Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
- Own the response to enterprise customer security questionnaires and RFPs
- Represent Staffbase credibly in customer security reviews, calls, and audits
- Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
Risk & Vendor Security
- Maintain the risk register and drive risk treatment decisions with relevant stakeholders
- Own vendor security assessments for critical and high-risk suppliers
- Partner with Procurement and Legal on AI-assisted review workflows
Policy & Awareness
- Own the internal security policy framework, keep it current, understandable, and enforced
- Design and run security awareness programs that change behaviour, not just tick boxes
Incident Response
- Own the incident response plan and lead execution when incidents occur
- Coordinate with Engineering, Legal, and leadership during incidents
- Drive post-incident reviews and close findings with owners
What you need to be successful
Essential Experience
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Highly Desirable
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
What you'll get
- Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
- Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
- Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
- Support-we’re offering a company pension scheme
- Volunteers Day- you’ll get one day off per year for supporting a social project
Originally posted on Himalayas