SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Information Security Manager - remote working within Germany

Staffbase - Remote - Remote - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Staffbase is an AI-native Employee Experience Platform company (unicorn, $1B+ valuation) with 550+ employees serving 1,500+ customers across 14 million employees globally. The company is headquartered in Chemnitz, Germany with offices in New York, Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul. You will serve as the senior deputy for Information Security within the Finance & Operations department, reporting directly to the SVP Business Operations & Transformation. This is a step-up role focused on maturing the InfoSec program from operationally sound to investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale. You will own the function day-to-day, represent it internally and externally, and drive the shift from manual processes to intelligent, automated workflows. Key Responsibilities: **Compliance & Audit:** Lead ISO 27001 and SOC 2 audit cycles end-to-end (preparation, evidence collection, auditor management, findings remediation). Own and maintain the control framework as the business evolves. Prepare the InfoSec program for investor and M&A due diligence scrutiny. **Customer Trust:** Own responses to enterprise customer security questionnaires and RFPs. Represent Staffbase credibly in customer security reviews, calls, and audits. Build scalable, automated approaches (templates, knowledge base) to reduce response time without sacrificing quality. **Risk & Vendor Security:** Maintain the risk register and drive risk treatment decisions with stakeholders. Own vendor security assessments for critical and high-risk suppliers. Partner with Procurement and Legal on AI-assisted review workflows. **Policy & Awareness:** Own the internal security policy framework, keeping it current, understandable, and enforced. Design and run security awareness programs that change behavior, not just tick boxes. **Incident Response:** Own the incident response plan and lead execution when incidents occur. Coordinate with Engineering, Legal, and leadership. Drive post-incident reviews and close findings with owners. You will work closely with Legal, Procurement, Engineering, external auditors, and enterprise customers. You think in programs and systems, not tasks, and are empowered to identify where manual effort can be replaced by tooling or AI-assisted workflows. **Requirements:** Essential Experience: - 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company - Proven ownership of ISO 27001 and/or SOC 2 programs - Track record of representing InfoSec to enterprise customers, including security reviews and escalations - Fluent in English - Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations Highly Desirable: - Experience supporting or preparing for M&A or investor due diligence processes - Background working alongside Legal, Procurement, and Engineering - Practical understanding of cloud security architecture (enough to challenge and validate, not operate) - Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent (certification matters less than what you have built)

Similar roles