Principal Information Security Manager — Opportunihub
Job

Principal Information Security Manager

Staffbase · Chemnitz, Sachsen

At a glance

Type
Job
Organisation
Staffbase
Location
Chemnitz, Sachsen
Work mode
On-site
Deadline
Rolling / not stated
Posted
1 Sep 2026

About this job

&lt;div class=&quot;content-intro&quot;&gt;&lt;h3&gt;&lt;strong&gt;About Staffbase&lt;/strong&gt;&lt;/h3&gt; &lt;p&gt;We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first &lt;strong&gt;AI-native Employee Experience Platform&lt;/strong&gt;. Our&lt;strong&gt; industry-leading and award-winning agentic AI communications channels&lt;/strong&gt; - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.&lt;/p&gt; &lt;p&gt;Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience.&lt;br&gt;We are proud to be a&amp;nbsp;&lt;strong data-stringify-type=&quot;bold&quot;&gt;Unicorn&lt;/strong&gt;&amp;nbsp;company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.&lt;/p&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-size: 14pt;&quot;&gt;This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 14pt;&quot;&gt;The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.&amp;nbsp;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 14pt;&quot;&gt;You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;What you’ll be doing&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;You will act as the senior deputy for InfoSec within our Finance &amp;amp; Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;You report directly to the SVP Business Operations &amp;amp; Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.&lt;br&gt;&lt;br&gt;You will own;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Compliance &amp;amp; Audit&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-size: 14pt;&quot;&gt;Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Own the control framework and ensure it stays current as the business evolves&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Prepare the InfoSec program for investor and M&amp;amp;A due diligence scrutiny&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Customer Trust&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Own the response to enterprise customer security questionnaires and RFPs&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Represent Staffbase credibly in customer security reviews, calls, and audits&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Risk &amp;amp; Vendor Security&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Maintain the risk register and drive risk treatment decisions with relevant stakeholders&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Own vendor security assessments for critical and high-risk suppliers&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;span style=&quot;font-size: 14pt;&quot;&gt;Partner with Procurement and Legal on AI-assisted review workflows&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Policy &amp;amp; Awareness&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Own the internal security policy framework, keep it current, understandable, and enforced&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Design and run security awareness programs that change behaviour, not just tick boxes&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Incident Response&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Own the incident response plan and lead execution when incidents occur&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Coordinate with Engineering, Legal, and leadership during incidents&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Drive post-incident reviews and close findings with owners&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;What you need to be successful &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Essential Experience&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul class=&quot;ul1&quot;&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;5+ years of hands-on InfoSec experience in a SaaS or B2B tech company&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Proven ownership of ISO 27001 and/or SOC 2 programs&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Track record of representing InfoSec to enterprise customers, including security reviews and escalations&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Must be fluent in German and English&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p class=&quot;p1&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;Highly Desirable&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul class=&quot;ul1&quot;&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Experience supporting or preparing for M&amp;amp;A or investor due diligence processes&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Background working alongside Legal, Procurement, and Engineering&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Practical understanding of cloud security architecture (enough to challenge and validate, not operate)&lt;/span&gt;&lt;/li&gt; &lt;li class=&quot;li1&quot; style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;strong&gt;What you&#39;ll get&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;em&gt;Competitive Compensation&lt;/em&gt; - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-size: 14pt; font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;em&gt;Flexibility &lt;/em&gt;- we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;em&gt;Recharge&lt;/em&gt; - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-size: 14pt; font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;em&gt;Support&lt;/em&gt;&lt;strong&gt; &lt;/strong&gt;-&lt;strong&gt; &lt;/strong&gt;we’re offering a company pension scheme&lt;/span&gt;&lt;/li&gt; &lt;li style=&quot;font-family: arial, helvetica, sans-serif; font-size: 14pt;&quot;&gt;&lt;span style=&quot;font-size: 14pt; font-family: arial, helvetica, sans-serif;&quot;&gt;&lt;em&gt;Volunteers Day&lt;/em&gt;&lt;strong&gt; &lt;/strong&gt;- you’ll get one day off per year for supporting a social project&lt;/span&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div class=&quot;content-conclusion&quot;&gt;&lt;h3&gt;&lt;strong&gt;&lt;img src=&quot;https://imgur.com/a/kIbq0q5&quot; alt=&quot;&quot; style=&quot;max-width: 100%;&quot;&gt;&lt;/strong&gt;&lt;/h3&gt;&lt;/div&gt;<p>Find <a href="https://www.arbeitnow.com">Jobs in Germany</a> on Arbeitnow</a>

How to apply

  1. 1 Read the full details above and confirm you meet the eligibility criteria.
  2. 2 Prepare your documents — an updated CV, and any cover letter, proposal or certificates required.
  3. 3 Click Apply on official site to complete your application on Staffbase’s official page.
  4. 4 Submit as early as possible — many close once filled.
Apply on official site

Sourced from arbeitnow. Always verify details on the official website. Opportunihub never charges you to apply.

Frequently asked questions

How do I apply for Principal Information Security Manager?

Review the full details and eligibility on this page, prepare your documents, then use the “Apply on official site” button to complete your application on Staffbase’s official page.

Is this opportunity remote or location-based?

This opportunity is based in Chemnitz, Sachsen. Check the official listing for any relocation or on-site requirements.

Is Principal Information Security Manager free to apply for?

Opportunihub lists this Job for free. Legitimate Jobs do not ask for payment to apply — never pay a fee to submit an application.