Senior Information Security Specialist in Winit Germany GmbH, Bremen at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Information Security Specialist based in Germany.
This fully remote opportunity is designed for an experienced information security professional who wants to shape compliance practices within a fast-growing technology environment. In this role, you will lead security compliance initiatives, strengthen governance processes, and help organizations achieve and maintain key industry certifications. You will combine technical expertise, strategic thinking, and customer-facing skills to improve compliance solutions and support business growth. Working closely with product, customer success, and security teams, you will influence how security frameworks are delivered through modern technology. This position offers significant ownership, leadership opportunities, and the chance to make a measurable impact on security automation across European businesses.
- Own and drive compliance initiatives across multiple security and regulatory frameworks, including ISO 27001, SOC 2, GDPR, TISAX, NIS 2, DORA, ISO 27017/27018, ISO 42001, and C5.
- Lead end-to-end implementation of ISO 27001 and related security frameworks for customers.
- Conduct internal audits for strategic customers and review audit work completed by junior specialists to ensure quality and consistency.
- Mentor and support compliance team members by sharing expertise, improving processes, and strengthening audit delivery standards.
- Act as a trusted security and compliance advisor for customer success and sales teams, supporting customer discussions and complex security questions.
- Create and maintain high-quality compliance content, including policies, evidence templates, security awareness materials, and internal enablement resources.
- Identify compliance gaps, incorporate auditor feedback, and translate improvement opportunities into practical solutions.
- Collaborate with product and engineering teams to convert compliance requirements into structured product improvements.
- Build strong relationships with certification partners and support auditors in effectively using compliance tools and processes.
- Work independently with ownership over priorities, delivery quality, and continuous improvement initiatives.
- Fluent English proficiency (C1 or C2 level) is essential.
- 7+ years of hands-on experience in information security, governance, risk, and compliance (GRC), ideally within B2B SaaS environments.
- Proven experience leading at least five successful ISO 27001 certification projects as an implementer, auditor, or security consultant.
- Hands-on experience with GRC platforms or similar security compliance management tools.
- Strong understanding of cloud security environments, including AWS, Azure, and GCP, with experience in security posture analysis and remediation planning.
- Excellent project management skills with the ability to manage complex initiatives, prioritize effectively, and deliver results independently.
- Strong written communication skills with the ability to create clear compliance documentation for technical and non-technical audiences.
- Senior-level ownership mindset with the ability to operate independently and proactively identify opportunities for improvement.
- Experience with additional frameworks such as SOC 2, GDPR, NIS 2, or similar standards is a plus.
- Previous experience mentoring or coaching compliance, audit, or GRC professionals is considered an advantage.
- Startup or high-growth technology environment experience is a plus.
- Fully remote position based in Europe.
- Competitive salary aligned with local market standards.
- Equity package providing ownership and participation in company growth.
- Annual personal development budget of €1,000.
- Home office budget and access to coworking spaces.
- Comprehensive health insurance coverage.
- 26 days of paid holiday plus local public holidays.
- Latest technology equipment, including laptop and professional accessories.
- Opportunities to work with experienced security professionals, mentors, and industry experts.
- Annual company retreat and team events to build collaboration and connections.