Senior Information Security Manager (GRC)

DeepL
Munich, Cologne, Berlin
Workplace: HybridFull timeFunction: CybersecurityExperience: 3-5 yearsSkills: ["Stakeholder management","Risk judgment","Structured communication","Partnering","Process building"]

Own and continuously improve the ISMS aligned to ISO 27001 and SOC 2 Type II, maintaining the risk register, policies, vendor/third-party risk assessments, and control monitoring. Lead audits and certification/attestation cycles with direct evidence collection using GRC tooling (e.g., Vanta), and shift evidence ownership to product and engineering teams. Partner across engineering, product, IT, People, and Legal to translate regulatory and customer requirements into practical controls, and report program status to leadership.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
DeepL
DeepL
2 days ago

Senior Information Security Manager (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Own and continuously improve the ISMS aligned to ISO 27001 and SOC 2 Type II, maintaining the risk register, policies, vendor/third-party risk assessments, and control monitoring. Lead audits and certification/attestation cycles with direct evidence collection using GRC tooling (e.g., Vanta), and shift evidence ownership to product and engineering teams. Partner across engineering, product, IT, People, and Legal to translate regulatory and customer requirements into practical controls, and report program status to leadership.
Location: Munich, Cologne, Berlin
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Own and continuously improve the ISMS aligned with ISO 27001, SOC 2 Type II, and relevant HIPAA/BSI C5 requirements.
  • •Maintain and mature the risk register, policy library, vendor/third-party risk assessments, and control monitoring.
  • •Act as a hands-on participant in audits and certification/attestation cycles, working with auditors, control owners, and leadership.
  • •Build and refine evidence collection processes using automation and GRC tooling to reduce manual effort and audit fatigue.
  • •Assess risk pragmatically and translate regulatory/customer requirements into practical controls in partnership with engineering, product, IT, People, and Legal.

Pay and Benefits

Perks:Hybrid WorkFlexible HoursAnnual LeaveEquity

Key Requirements

  • •3-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company.
  • •Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits end-to-end.
  • •Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent).
  • •Experience using HIPAA and/or BSI C5 is a strong plus.
  • •Fluent English and German language skills at C1 level (or close by).
Experience:3-5 yearsSaaS
Skills:Stakeholder managementRisk judgmentStructured communicationPartneringProcess building
Languages:EnglishGerman
Tech Stack:ISO 27001SOC 2 Type IIHIPAABSI C5VantaGRC tooling

Company Brief

DeepL
DeepL builds Language AI products (DeepL Translator, DeepL Write, APIs and enterprise solutions) that provide high-accuracy translations and writing assistance to businesses and individuals, focusing on privacy, security and enterprise deployment.
Industry: AI & Machine Learning
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: Cologne, Germany
Founded: 2017
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor