SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
DeepL, a global AI product and research company with ~1,000 employees and 200,000+ business customers, is seeking a Senior Information Security Manager to lead its Governance, Risk, and Compliance (GRC) function. This role owns the day-to-day operation of DeepL's information security and compliance program, with primary focus on ISO 27001 and SOC 2 Type II certifications, plus experience with HIPAA and BSI C5 as valuable additions.
You will own and continuously improve the Information Security Management System (ISMS), maintaining the risk register, policy library, vendor risk assessments, and control monitoring. You'll act as a hands-on participant in audits, working directly with auditors, control owners, and leadership to prepare, execute, and close certification and attestation cycles efficiently. A key responsibility is building and refining evidence collection processes using GRC automation tools (e.g., Vanta), reducing manual overhead and audit fatigue. You'll design a model where product and engineering teams own their evidence throughout the control lifecycle rather than compliance chasing teams down before audits.
On the risk and business partnership side, you'll assess risk pragmatically—identifying real security and compliance exposure, sizing it accurately, and making calculated decisions that unblock product and engineering teams. You'll partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows. You'll track regulatory and customer-driven compliance requirements (security questionnaires, evolving frameworks) and translate them into actionable controls. Finally, you'll report on the state of the security and compliance program to stakeholders and leadership, including audit readiness, open risks, and remediation progress.
This is not a gatekeeper role. DeepL is a SaaS scale-up where product teams move fast, and you need to understand risk well enough to take calculated ones—saying "yes, and here's how we do it safely" rather than defaulting to "no." You'll be part of the Information Security team within the broader Security track, working closely with IT Security under the Head of Security.