Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Staffbase

Principal Information Security Manager

Staffbase

. Serve as the senior deputy for InfoSec within the Finance & Operations department .

Posted 9/17/2026full-timeRemote • GermanyLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in InfoSec management, particularly in leading ISO 27001 and SOC 2 audit cycles, while effectively collaborating with cross-functional teams including Legal, Procurement, and Engineering. Proficient in developing security policies, managing incident responses, and driving automation in compliance processes.

Highest-signal resume keywords
ISO 27001 Program OwnershipSOC 2 Program OwnershipInfoSec Representation to Enterprise CustomersCloud Security Architecture UnderstandingCISM or CISSP Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
InfoSec ManagementAudit Cycle ManagementRisk TreatmentSecurity Policy DevelopmentIncident Response PlanningAutomation in ComplianceSecurity Questionnaire ResponsesVendor Security AssessmentsM&A Due Diligence PreparationControl Framework Maintenance
Soft Skills
CollaborationCommunicationLeadershipProblem-SolvingAdaptability
Tools & Technologies
AI-Driven ToolingSecurity Automation ToolsKnowledge Management Systems
Certifications & Qualifications
CISMCISSPISO 27001 Lead AuditorISO 27001 Implementer
Industry Keywords
SaaSB2B TechSecurity ReviewsRisk RegisterSecurity Awareness Programs

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Serve as the senior deputy for InfoSec within the Finance & Operations department
  • Own the InfoSec function day-to-day and represent it internally and externally
  • Report directly to the SVP Business Operations & Transformation
  • Coordinate with Legal, Procurement, Engineering, external auditors, and enterprise customers
  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, including preparation, evidence collection, auditor management, and findings remediation
  • Own and maintain the control framework
  • Prepare the InfoSec program for investor and M&A due diligence
  • Own responses to enterprise customer security questionnaires and RFPs
  • Represent Staffbase in customer security reviews, calls, and audits
  • Build scalable automation, templates, and knowledge bases to reduce response times
  • Maintain the risk register and drive risk treatment decisions
  • Own vendor security assessments for critical and high-risk suppliers
  • Partner with Procurement and Legal on AI-assisted review workflows
  • Own and enforce the internal security policy framework
  • Design and run behaviour-changing security awareness programs
  • Own the incident response plan and lead execution during incidents
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post-incident reviews and close findings with owners

Requirements

What you’ll need
  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in English
  • Comfortable with AI-driven tooling and actively looks for automation opportunities in compliance and operations
  • Experience supporting or preparing for M&A or investor due diligence processes is highly desirable
  • Background working alongside Legal, Procurement, and Engineering is highly desirable
  • Practical understanding of cloud security architecture is highly desirable
  • Relevant certification such as CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent is highly desirable

Benefits

Comp & perks
  • Attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
  • Flexible working time models
  • Option of hybrid work
  • Yearly flex work allowance of €1560
  • 31 vacation days annually, including one floating holiday
  • Pro rata fully paid Fridays off during August
  • Company pension scheme
  • One paid Volunteers Day per year for supporting a social project