Principal Information Security Manager - remote working within Germany
Staffbase
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
222 open information roles across 106 companies are on ApplySarthi right now, most of them in Hyderabad (15), Bengaluru (14), Pune (7).
- Senior Information Security AnalystCirrus
- Tech Risk and Control Lead, Information SecurityJPMorgan
- Manager - Information TechnologyMaersk
- Junior Consultant Information Security (m/f/d)Dataguard
- Responsable Systèmes d'Information & Outils internes H/FN2JSoft
What information roles keep asking for: SaaS (18%), GCP (12%) — counted across their open postings here.
Staffbase has 23 open roles listed here.
- Fullstack Engineer - Mid Level - Actions Team
- Senior Implementation Consultant
- Join Our Talent Community: Enterprise Account Executive
- Backend Engineer - Mid Level - Autopilot Team
- Enterprise Sales Development Representative
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for information roles keep coming back to SaaS, GCP. Practise those questions before you sit with Staffbase.
Questions you are likely to be asked
- Why do you want to join Staffbase?
- What is your experience with B2B? Tell me one thing you learned the hard way.
- Walk me through how code gets from a commit to production where you work.
- Tell me about an outage you handled. What did you learn from it?
- How do you decide what to monitor, and what should wake someone up at night?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Principal Information Security Manager - remote working within Germany at Staffbase interview free →About Staffbase
We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.
Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience.
We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.
Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.
This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.
The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.
You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.
What you’ll be doing
You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.
You will own;
Compliance & Audit
- Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
- Own the control framework and ensure it stays current as the business evolves
- Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
- Own the response to enterprise customer security questionnaires and RFPs
- Represent Staffbase credibly in customer security reviews, calls, and audits
- Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
Risk & Vendor Security
- Maintain the risk register and drive risk treatment decisions with relevant stakeholders
- Own vendor security assessments for critical and high-risk suppliers
- Partner with Procurement and Legal on AI-assisted review workflows
Policy & Awareness
- Own the internal security policy framework, keep it current, understandable, and enforced
- Design and run security awareness programs that change behaviour, not just tick boxes
Incident Response
- Own the incident response plan and lead execution when incidents occur
- Coordinate with Engineering, Legal, and leadership during incidents
- Drive post-incident reviews and close findings with owners
What you need to be successful
Essential Experience
- 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
- Proven ownership of ISO 27001 and/or SOC 2 programs
- Track record of representing InfoSec to enterprise customers, including security reviews and escalations
- Must be fluent in English
- Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations
Highly Desirable
- Experience supporting or preparing for M&A or investor due diligence processes
- Background working alongside Legal, Procurement, and Engineering
- Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
- Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built
What you'll get
- Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
- Flexibility - we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
- Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
- Support - we’re offering a company pension scheme
- Volunteers Day - you’ll get one day off per year for supporting a social project
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Senior Product Security Engineer - Remote working within GermanyStaffbase
- Join Our Talent Community: Enterprise Account ExecutiveStaffbase
- Principal, Partnership Management – Strategic Partners EuropeStaffbase
- Associate Legal CounselStaffbase
- Associate Technical ConsultantStaffbase
- Backend Engineer - Mid Level - Autopilot TeamStaffbase
- Corporate Sales Development RepresentativeStaffbase
- Demand Generation LeadStaffbase
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-09-17. ApplySarthi collects openings and links to application pages; the role is advertised by Staffbase, not by us.