Senior Information Security Manager (GRC)
Munich, Cologne, Berlin
Workplace: HybridFull timeFunction: CybersecurityExperience: 3-5 yearsSkills: ["Stakeholder management","Risk judgment","Structured communication","Partnering","Process building"]Own and continuously improve the ISMS aligned to ISO 27001 and SOC 2 Type II, maintaining the risk register, policies, vendor/third-party risk assessments, and control monitoring. Lead audits and certification/attestation cycles with direct evidence collection using GRC tooling (e.g., Vanta), and shift evidence ownership to product and engineering teams. Partner across engineering, product, IT, People, and Legal to translate regulatory and customer requirements into practical controls, and report program status to leadership.
Loading
Loading job details...
Preparing the role view and application actions.

