Security Lead - m/f/d
1 мес. назад
90k–140k EUR / yearGermanyEuropeLeadOnsite
entra idbug bountydevice managementismsautomation
Lead and own the comprehensive security system, including ISMS, identity management, device management, bug bounty program, and physical security, using automation and AI-first practices.
Обязанности
- Security at is not a policy function on the side. It is the way identities are provisioned, devices are managed, offices are protected, software is built, and customer trust is earned.
- As our Security Lead, you will own that system end to end. You will run our certified ISMS, but you will also configure Entra ID, automate access lifecycle processes, own device management, operate our bug bounty program, maintain physical security, and work directly with engineering on controls that hold up in production.
- This is deliberately a broad role for one ambitious person. We believe that strong automation and an AI-first way of working allow one exceptional operator to own what traditionally requires a small team. The goal is not to create more security work. It is to build systems that keep the operational load low and the security bar high.
- You will report directly to Hendrik Hofstadt and work closely with engineering, operations, and sales.
- Own identity and access. Design and automate onboarding, offboarding, access reviews, and privilege provisioning so the right people have the right access at the right time - and nothing more. You will configure and own Entra ID, including conditional access, group and role design, lifecycle automation, and integrations with the tools our teams use.
- Own every company device. Run MDM and maintain an accurate device inventory. Make sure every device that touches company data is enrolled, encrypted, patched, and recoverable without creating unnecessary friction for the team.
- Run security programs. Set up and operate responsible disclosure and bug bounty, triage findings, and drive them to resolution with engineering. Own physical security across access control, visitor handling, and the controls our certifications and customers expect.
- Run the ISMS. Maintain and continuously improve our ISO 27001 and SOC 2 Type II certified management system so it reflects how actually operates. Keep evidence in Vanta current and audit-ready throughout the year.
- Turn risk into action. Own the risk register, identify and prioritize security risks, and drive treatment plans to closure with the relevant owners. Design the simplest technical or organizational control that produces the required risk reduction.
- Lead audits and new standards. Manage our existing audits end to end and lead scoping and readiness for standards the business needs next, such as C5, TISAX, HDS, FedRAMP-adjacent requirements, or customer-specific frameworks.
- Work inside the business. Partner with engineering, operations, and sales to build controls into CI/CD, infrastructure, access management, and daily workflows instead of bolting security on afterward. Support customer security reviews and due-diligence requests when needed.
- Automate relentlessly. Treat recurring evidence collection, access reviews, provisioning, and questionnaire work as systems to automate. Use scripts, workflows, agents, and itself to compound your output.
Условия
- Salaries are transparent and tied to levels, not negotiation. All roles include equity.
- We will figure out the right level together based on your experience and scope. Levels are about the work you own, not your title or years of experience. We narrow down the expected salary range early in the process.
Как откликнуться
- We move fast. Most processes complete within two weeks.
- The process for this role includes initial conversations, a case study, and an on-site session with the team.
- If this sounds like your kind of work, we would like to meet you.
Другое
- exists to change the way the world works, bridging the gap between what technology can do and what people actually do with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations. Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their employees open to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more creatively, and reach their full potential.
- You will not inherit a narrow compliance role. You will own security across identities, endpoints, premises, processes, audits, and customer trust - with the authority to improve how the system actually works.
- The role sits close to the people building and operating the product. When a control needs to change, you will work with the team that implements it. When a customer asks how protects their data, you will be able to explain the technical reality behind the answer.
- The challenge is to keep security rigorous while making it feel simple. We are looking for someone who wants that breadth, uses automation as leverage, and is excited to prove that a small security function can operate at an exceptional level.
- You have operated an ISO 27001 and/or SOC 2 program through at least one full audit cycle, ideally in a growth-stage SaaS or technology company.
- You have hands-on experience with identity and endpoint management: lifecycle automation, conditional access, least-privilege or just-in-time access, MDM rollout, and policy design.
- You understand cloud infrastructure, identity providers, and modern software development well enough to have specific, credible conversations with engineers.
- You are comfortable configuring systems yourself. You do not stop at writing a policy when the work requires changing Entra ID, improving an MDM setup, or building provisioning automation.
- You are an active user of AI tooling and build scripts, workflows, and agents instead of repeating manual work.
- You prefer pragmatic controls that reduce real risk over bureaucracy that only produces documentation.
- You can explain security clearly to different audiences, from engineers implementing a control to customers evaluating .
- You are highly driven, take broad ownership, and want to build the security function rather than wait for a larger team around you.
- You are a kind person who cares about the people around you.
- We work from our office in Berlin, Greifswalder Strasse 212. Everyone works together in person because the hardest problems get solved faster at a whiteboard than in a Slack thread. Conversations happen faster, problems get solved quicker, and we actually know each other.
- Days start at 8:30. Lunch & dinner are together. We run, go to the gym, and take care of ourselves. Health is not separate from work here, it is part of how we work well.
- The vibe is calm but intense. No one is yelling or panicking. But everyone is working hard on things that matter.