IT Security & Compliance Lead — Opportunihub
Job

IT Security & Compliance Lead

VIA HealthTech · Berlin

At a glance

Type
Job
Organisation
VIA HealthTech
Location
Berlin
Work mode
On-site
Deadline
Rolling / not stated
Posted
6 Jul 2026

About this job

<p>VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.</p> <p>We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.</p> <h2>Tasks</h2> <p>We are looking for a hands-on IT Security &#x26; Compliance Lead to own security and compliance end-to-end at VIA.</p> <p>This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build.</p> <p>Your goal is to make VIA more secure while helping the team move faster, not slower.</p> <p><strong>What you’ll do</strong></p> <ul> <li>Own internal IT security end-to-end: devices, access management, 2FA, endpoint protection, policies, onboarding and offboarding</li> <li>Professionalize and operate our internal IT setup</li> <li>Own IT Compliance (ISO27001 and C5), including audits, evidence management, policies, risk management, corrective actions, auditor communication, and internal training</li> <li>Improve cloud security across infrastructure, access control, encryption, logging, monitoring, and operational processes</li> <li>Work closely with engineering on product security across web, desktop, mobile, backend, and AI-related systems</li> <li>Help embed security into the development lifecycle without creating unnecessary overhead</li> <li>Coordinate external security work such as penetration tests, security reviews, and vendor assessments where needed</li> <li>Identify security gaps, prioritize what matters, and implement pragmatic improvements</li> </ul> <h2>Requirements</h2> <p><strong>Required:</strong></p> <ul> <li>Strong hands-on experience in IT Security, Information Security, Cloud Security, or a closely related field</li> <li>Practical experience securing cloud-based software products and internal IT environments</li> <li>Solid understanding of IAM, endpoint security, device management, encryption, logging, access control, and incident response</li> <li>Experience with ISO27001 and/or C5, ideally including audit ownership or major audit involvement</li> <li>Ability to work directly with engineering teams on technical security topics</li> <li>Strong operational ownership: you see what needs to be done and make it happen</li> <li>Pragmatic judgment: you know how to raise the security bar without blocking a fast-moving team</li> <li>Clear communication and comfort working in an async-first startup environment</li> </ul> <p><strong>Nice to have:</strong></p> <ul> <li>Experience in healthcare, regulated environments, or companies handling highly sensitive data</li> <li>Experience with application security, secure SDLC, threat modeling, or vulnerability management</li> <li>Experience with desktop app, mobile app, or AI security</li> <li>Experience setting up or improving security processes in an early-stage or fast-growing company</li> </ul> <p><strong>What matters beyond the checklist</strong></p> <p>We are a 10-person startup. This role requires breadth, ownership, and hands-on execution.</p> <p>You should be comfortable moving between strategic questions and operational details: one day improving cloud security architecture, another day tightening access policies, preparing audit evidence, reviewing product security, or configuring internal IT tools.</p> <p>We are not looking for someone who only writes policies. We are looking for someone who builds and operates the security foundation VIA needs as it scales.</p> <h2>Benefits</h2> <ul> <li>Office in Berlin Mitte, flexible hours</li> <li>Direct access to founders, CTO, and the full multidisciplinary team</li> <li>Broad ownership over a core company function</li> <li>Equity participation</li> <li>No micromanagement — results over hours logged</li> <li>Work at the intersection of AI, healthcare, software, and security</li> </ul> <p>Find <a href="https://www.arbeitnow.com/">Jobs in Germany</a> on Arbeitnow</a>

How to apply

  1. 1 Read the full details above and confirm you meet the eligibility criteria.
  2. 2 Prepare your documents — an updated CV, and any cover letter, proposal or certificates required.
  3. 3 Click Apply on official site to complete your application on VIA HealthTech’s official page.
  4. 4 Submit as early as possible — many close once filled.
Apply on official site

Sourced from arbeitnow. Always verify details on the official website. Opportunihub never charges you to apply.

Frequently asked questions

How do I apply for IT Security & Compliance Lead?

Review the full details and eligibility on this page, prepare your documents, then use the “Apply on official site” button to complete your application on VIA HealthTech’s official page.

Is this opportunity remote or location-based?

This opportunity is based in Berlin. Check the official listing for any relocation or on-site requirements.

Is IT Security & Compliance Lead free to apply for?

Opportunihub lists this Job for free. Legitimate Jobs do not ask for payment to apply — never pay a fee to submit an application.