SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security & Compliance Officer (f/m/d)

SPREAD - Berlin, Berlin, Germany - Hybrid - posted 2026-08-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SPREAD builds AI-native engineering intelligence for automotive OEMs, defense primes, and industrial manufacturers. The company works with major clients including Volkswagen, BMW, Mercedes, Bosch, Stadler, and Rheinmetall, and is backed by HV Capital, DTCP, La Famiglia, and Salesforce. You will support and progressively own SPREAD's information security and compliance program, including ISO 27001, SOC 2 Type II, and TISAX certifications. You inherit an established program with three live certifications and an existing evidence base, providing a foundation to build upon rather than starting from scratch. Key responsibilities include: - Support ISO 27001, SOC 2 Type II, and TISAX audit cycles end-to-end, taking on increasing ownership as you develop expertise - Answer customer and OEM security questionnaires directly with the GTM team, positioning security as a deal accelerator - Present ISMS status and audit results to leadership each cycle - Maintain the risk register, policies, and vendor/supplier security assessments to keep the program audit-ready year-round - Run security awareness training and phishing simulations across the company - Administer identity and access management: provisioning, access reviews, conditional access, and RBAC - Manage device and endpoint lifecycle: procurement, enrollment, repair, and retirement - Own end-user IT support and the complete joiner-mover-leaver process, including ticket queue management and office network administration - Automate repetitive IT and evidence-collection work using Vanta and similar tools Required qualifications: 3-5 years of hands-on IT operations, InfoSec operations, or compliance-adjacent IT experience. Direct experience supporting a full ISO 27001 or SOC 2 audit cycle is essential. You should have worked in a small security or compliance function alongside a senior mentor. Strong technical skills required in identity and access management (Entra ID or comparable), M365/Exchange Online administration, and Mac-first endpoint management. Fluent German proficiency and eligibility to obtain a German security clearance are mandatory. Bonus qualifications include TISAX or automotive OEM security ecosystem exposure, scripting/automation skills, and Vanta platform experience. The role offers high ownership and measurable impact, a senior team that values craft and accountability, competitive compensation with equity, VSO, annual learning budget, Deutschlandticket mobility support, bike-leasing, Urban Sports partnership, 30 vacation days, and one paid volunteering day annually.

Similar roles