SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Assurance Specialist

Sumup - Berlin, Berlin, Germany - In-office - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SumUp is a fintech company serving over 4 million small businesses across 38 markets with payment, finance, and customer relationship tools. The Security Assurance team maintains SumUp's information security programme credibility with regulators and merchants, operating across Europe, Brazil, and Chile. In this role, you will: - Review information security controls, audit findings, and risk mitigation plans, coordinating fixes across teams - Conduct third-party due diligence, supplier reviews, and contract assessments as part of third-party risk management - Partner with business stakeholders to promote security practices and embed security principles into day-to-day processes - Support external and internal audits and due diligence requests, responding directly to auditors, clients, and partners - Track relevant laws, regulations, and security standards, identifying gaps against existing controls - Maintain and improve the team's security maturity picture, identifying priority areas and leading or supporting closure initiatives This is an office-first role based in Berlin, offering the opportunity to shape how a fast-growing fintech demonstrates security maturity across multiple regulatory environments with real ownership over improvement areas. Benefits include virtual stock options, €2,000 annual L&D budget, corporate pension scheme (up to 20% match), 28 days paid leave plus public holidays, Urban Sports Club subsidy, subsidised office lunches, and a 1-month sabbatical after 3 years of service. Requirements: - Experience reviewing and improving information security controls in an assurance or GRC-focused role - Strong knowledge of ISO 27001 and NIST information security standards, plus PCI DSS payment security standards - Comfort with third-party risk management, audit procedures, supplier reviews, and contract assessments - Ability to prioritise and simplify complex requests across different regulatory environments - Strong communication skills and confidence engaging stakeholders from engineering teams to external auditors

Similar roles