Senior Information Security Manager (GRC)

Senior Information Security Manager (GRC)

München Vollzeit 72000 - 88000 € / Jahr (geschätzt) Homeoffice (teilweise)
United States Digital Space LLC

Auf einen Blick

  • Aufgaben: Leite unser Informationssicherheits- und Compliance-Programm mit Fokus auf ISO 27001 und SOC 2 Type II.
  • Unternehmen: DeepL, ein globales KI-Unternehmen mit einer Kultur der Innovation und Zusammenarbeit.
  • Vorteile: Hybridarbeit, flexible Arbeitszeiten, 30 Tage Urlaub und virtuelle Anteile.
  • Weitere Informationen: Dynamisches Team aus über 90 Nationalitäten mit regelmäßigen Teamevents und Hack Fridays.
  • Warum dieser Job: Gestalte die Zukunft der KI und arbeite an bedeutungsvollen Projekten.
  • Qualifikationen: 3-5 Jahre Erfahrung in Informationssicherheit und GRC, idealerweise in einem SaaS-Unternehmen.

Das prognostizierte Gehalt liegt zwischen 72000 - 88000 € pro Jahr.

Meet Deep LDeep L is a global AI product and research company focused on building secure, intelligent solutions to complex business problems.

Over 200,000 business customers and millions of individuals across 228 global markets today trust the company's Language AI platform for human-like translation, improved writing and real-time voice translation.

Founded in 2017 by CEO Jaroslaw “Jarek” Kutylowski, the company now has around 1,000 passionate employees and is supported by world-renowned investors including Benchmark, IVP, and Index Ventures.

Our goal is to become the global leader in trusted, intelligent AI technology, building products that drive better communication, foster connections, and create a meaningful impact.

To achieve this, we need talented people like you to join our journey.

If you’re ready to shape the future of AI and grow your career in a fast-moving, purpose-driven environment, the company is your next destination.

What sets us apart

What sets us apart is our blend of cutting-edge AI technology, meaningful work, and a culture where people truly thrive.

We’re a team of innovators, researchers, and creators driven by a shared purpose to unlock human potential by making work simpler, smarter, and more connected.

When we share what it’s like to work at the company, the reactions are overwhelmingly positive.

This might be because of our technology that helps millions of people and businesses communicate and work better every day, or because of the trust, curiosity, and care that shape our culture.

What we know for sure is this: being part of the company means joining a team dedicated to innovation, growth, and well-being.

Discover more about life at the company on Linked In, Instagram, and our Blog.

Meet the team behind this journey

Deep L is looking for a Senior Information Security Manager to strengthen our Governance, Risk, and Compliance (GRC) function.

You'll own the day-to-day operation of our information security and compliance program, with a strong focus on ISO 27001, SOC 2 Type II, and a bonus if you bring HIPAA or BSI C5 experience to the table.

This isn't a "gatekeeper" role.

We're a Saa S scale-up, and our product teams move fast.

We need someone who understands risk well enough to take calculated ones, someone who can say "yes, and here's how we do it safely" instead of defaulting to "no." You'll be the person who keeps compliance moving at the speed of the business, not the person who slows it down.

You'll be part of our Information Security team, sitting within the broader Security track alongside the IT Security team, both under our Head of Security.

You'll work closely with your teammates in Information Security and IT Security to make sure security and compliance work hand in hand rather than in separate lanes.

  • Your responsibilities
  • Program ownership
  • Own and continuously improve our Information Security Management System (ISMS), keeping it aligned with ISO 27001, SOC 2 Type II, and, where relevant, HIPAA and BSI C5
  • Maintain and mature our risk register, policy library, vendor/third-party risk assessments, and control monitoring
  • Audits & evidence
  • Act as a hands-on participant in audits, working directly with auditors, control owners, and leadership to prepare, execute, and close out certification and attestation cycles efficiently rather than through brute force
  • Build and refine evidence collection processes using automation and GRC tooling (e. g. Vanta or similar), reducing manual overhead and audit fatigue across the company
  • Design and roll out a model where product and engineering teams own their evidence throughout the control lifecycle, rather than compliance chasing people down before every audit
  • Risk & business partnership
  • Assess risk pragmatically: identify real security and compliance exposure, size it accurately, and make calculated calls that unblock product and engineering teams
  • Partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows rather than bolting them on afterward
  • Track regulatory and customer-driven compliance requirements — new customer security questionnaires, evolving frameworks — and translate them into practical, actionable controls
  • Reporting
  • Report on the state of the security and compliance program to stakeholders and leadership, including audit readiness, open risks, and remediation progress
  • Qualities we look for
  • 3-5 years of experience in information security, GRC, or compliance roles, ideally at a Saa S company, and ideally at scaleup pace and scale
  • Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits, from control design through evidence collection to certification
  • Experience with HIPAA and/or BSI C5 is a strong plus
  • Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent), including building smooth, low-friction processes around it
  • A track record of building processes that shift evidence ownership to the teams generating the evidence, rather than centralizing it all in compliance
  • Sound risk judgment: comfortable making calculated, defensible risk decisions to keep product teams unblocked, rather than reflexively blocking
  • Strong stakeholder management skills; able to work credibly with engineers, product managers, and leadership without becoming an obstacle
  • Fluent English and German language skills at C1 level (or close by) are required
  • Clear, structured communicator who can translate compliance requirements into language engineering and product teams actually act on

What we offer

  • Diverse and internationally distributed team: joining our team means becoming part of a large, global community with people of more than 90 nationalities.

We’re more than just colleagues; we’re a group of professionals with a shared mission to connect diverse cultures.

Our global presence is growing–we’ve doubled in size nearly every year, with our employees based in the UK, Germany, the Netherlands, Poland, the US, and Japan, and we continue to expand our network.

  • Open communication, regular feedback: as a language-focused company, we value the importance of clear, honest communication.

We value smooth collaboration, direct and actionable feedback, and believe that leading with empathy and growth mindset makes us better together.

  • Hybrid work, flexible hours: we offer a hybrid work schedule, with team members coming into the office twice a week.

This allows you to engage directly with your team and experience the unique energy of our workspace, while still enjoying the flexibility and comfort of working from home.

With flexible working hours and trust in your productivity, we are in sync with your team’s general locations and time zones to foster effective and seamless collaboration.

  • Virtual Shares - An ownership mindset in every role.

We believe everyone should share in our success, and that’s why every employee receives Virtual Shares, linking your contribution directly to the company’s growth and rewarding you with a stake in our future.

  • Regular in-person team events: we bond over vibrant events that are as unique as our team, from local team and business unit gatherings, to new-joiner onboardings, to company-wide events that bring us all together–literally.
  • Monthly full-day hacking sessions: every month, we have Hack Fridays, where you can spend your time diving into a project you're passionate about and get the opportunity to work with other teams–we value your initiatives, impact, and creativity.
  • 30 days of annual leave: we value your peace of mind.

With 30 days off (excluding public holidays) and access to mental health resources, we make sure you're as strong mentally as you are professionally.

  • Competitive benefits: just as our team spans the globe, so does our benefits package.

We’ve crafted it to reflect the diversity of our team and tailored it to align with your unique location, to ensure you feel supported every step of the way.

We are an equal opportunity employer You are welcome at the company for who you are - we appreciate authenticity here.

Our product is for everyone, and so is our workplace.

The more voices we have represented and amplified in our business, the more we will all succeed, contribute, and think forward!

So bring us your personal experience, your perspectives, and your background.

It’s in our diversity that we will find the power to break down language barriers in the world.

#J-18808-Ljbffr

Senior Information Security Manager (GRC) Arbeitgeber: United States Digital Space LLC

Reserved ist ein dynamisches und wachsendes Modeunternehmen, das seinen Mitarbeitenden eine inspirierende Arbeitsumgebung bietet. Mit einer modernen Arbeitswelt, attraktiven Rabatten und umfangreichen Benefits wie Bike Leasing und betrieblicher Altersvorsorge fördern wir nicht nur die Work-Life-Balance, sondern auch die persönliche und berufliche Entwicklung unserer Mitarbeiter. In Mannheim hast du die Möglichkeit, in einem kreativen Team zu arbeiten und deine Leidenschaft für Mode in einem unterstützenden Umfeld auszuleben.

United States Digital Space LLC

Kontaktdaten:

United States Digital Space LLC Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Senior Information Security Manager (GRC) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie United States Digital Space LLC kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von United States Digital Space LLC zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei United States Digital Space LLC.

Wir glauben, dass du diese Fähigkeiten brauchst, um Senior Information Security Manager (GRC) mit Bravour zu bestehen

ISO 27001
SOC 2 Type II
HIPAA
BSI C5
Governance, Risk, and Compliance (GRC)
Auditing
Evidence Collection Automation

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei United States Digital Space LLC vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei United States Digital Space LLC könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. United States Digital Space LLC sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird United States Digital Space LLC auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!