Senior Information Security Manager (EU Sovereignty)

DeepL
Munich, Cologne, Berlin
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Stakeholder management","Risk judgment","Communication"]

Own and continuously improve the ISMS to keep security and compliance moving at SaaS speed, aligned with ISO 27001 and SOC 2 Type II (and where relevant HIPAA and BSI C5). Run audits and certification/attestation cycles hands-on, build automated evidence collection with GRC tooling like Vanta, maintain risk registers and vendor/third-party risk assessments, and translate regulatory requirements into practical controls—partnering across engineering, product, IT, People, and Legal.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
DeepL
DeepL
1 month ago

Senior Information Security Manager (EU Sovereignty)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Own and continuously improve the ISMS to keep security and compliance moving at SaaS speed, aligned with ISO 27001 and SOC 2 Type II (and where relevant HIPAA and BSI C5). Run audits and certification/attestation cycles hands-on, build automated evidence collection with GRC tooling like Vanta, maintain risk registers and vendor/third-party risk assessments, and translate regulatory requirements into practical controls—partnering across engineering, product, IT, People, and Legal.
Location: Munich, Cologne, Berlin
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Own and continuously improve the Information Security Management System (ISMS) aligned with ISO 27001 and SOC 2 Type II, and where relevant HIPAA and BSI C5.
  • •Maintain and mature the risk register, policy library, and vendor/third-party risk assessments, and monitor control implementation.
  • •Act as a hands-on participant in audits and certification/attestation cycles, partnering with auditors, control owners, and leadership to close efficiently.
  • •Build and refine evidence collection processes using automation and GRC tooling (e.g., Vanta), reducing manual overhead and audit fatigue.
  • •Assess risk pragmatically and translate regulatory/customer compliance requirements into practical, actionable controls across engineering, product, IT, People, and Legal.

Pay and Benefits

Perks:Remote WorkPaid Leave

Key Requirements

  • •3-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company and ideally at scale-up pace.
  • •Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits, from control design through evidence collection to certification.
  • •Experience with HIPAA and/or BSI C5 is a strong plus.
  • •Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent) and building low-friction evidence processes.
  • •Strong stakeholder management and sound risk judgment, with the ability to translate compliance requirements into action for engineering and product teams.
Experience:SaaSGRCCompliance
Skills:Stakeholder managementRisk judgmentCommunication
Languages:EnglishGerman
Tech Stack:ISO 27001SOC 2 Type IIHIPAABSI C5GRCVanta

Company Brief

DeepL
DeepL builds Language AI products (DeepL Translator, DeepL Write, APIs and enterprise solutions) that provide high-accuracy translations and writing assistance to businesses and individuals, focusing on privacy, security and enterprise deployment.
Industry: AI & Machine Learning
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: Cologne, Germany
Founded: 2017
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor