Overview
In this role you lead the Information Security Management System and drive governance, risk, and compliance for DeepL’s SaaS platform. You partner with engineering, product, IT, and legal to embed security controls without slowing product progress. You own audits and evidence programs, guiding teams through ISO 27001, SOC 2 Type II, and related requirements. You enable fast, secure delivery by balancing risk with business velocity, in a collaborative, growth-driven environment.
Leistungen / Benefits
- Hybrid work
- 30 days of annual leave
- Virtual Shares
- Hack Fridays / monthly innovation sessions
- Regular in-person team events
- Mental health resources
Verantwortungsbereiche
- Own and continuously improve ISMS aligned with ISO 27001 and SOC 2 Type II, plus HIPAA/BSI C5 where relevant
- Maintain risk register, policy library, vendor/third-party risk assessments, and control monitoring
- Lead audits and coordinate with auditors, control owners, and leadership to close certification cycles efficiently
- Develop and automate evidence collection and GRC tooling to reduce manual overhead
- Promote product/engineering ownership of evidence throughout the control lifecycle
- Assess risk pragmatically, unblock product/engineering teams with defensible decisions
- Embed security and compliance requirements into workflows with cross-functional partners
- Track regulatory and customer security questionnaires and translate into actionable controls
- Report on security program status, readiness, risks, and remediation to leadership
Zentrale Anforderungen
- 3-5 years of experience in information security, GRC, or compliance, ideally in a SaaS environment and scaleup pace
- Hands-on experience with ISO 27001 and SOC 2 Type II from design to certification
- HIPAA and/or BSI C5 experience is a strong plus
- Experience with GRC/evidence automation tooling such as Vanta (or equivalent)
- Track record of shifting evidence ownership to the teams generating it
- Strong risk judgment to unblock product teams
- Excellent stakeholder management with engineers, product managers, and leadership
- Fluent English and German at C1 level (or near)
- Clear, structured communicator who can translate compliance requirements for technical teams
- stakeholder management
- clear communication
- collaboration
- ISO 27001
- SOC 2 Type II
- HIPAA
Senior Information Security Manager (GRC) in Bonn Arbeitgeber: DeepL
DeepL ist ein hervorragender Arbeitgeber, der eine dynamische und unterstützende Arbeitsumgebung bietet, in der Innovation und persönliches Wachstum gefördert werden. Mit flexiblen Arbeitszeiten und der Möglichkeit, remote zu arbeiten, ermöglicht DeepL seinen Mitarbeitern, ihre Work-Life-Balance zu optimieren, während sie an bedeutungsvollen Projekten im Bereich KI-Technologie arbeiten. Die Unternehmenskultur basiert auf offener Kommunikation und Teamzusammenhalt, was durch regelmäßige Teamevents und monatliche Hackdays unterstützt wird, um Kreativität und Zusammenarbeit zu fördern.