GRC & Information Security Specialist

Flip GmbH
Stuttgart, Germany
3 months ago
Apply on de.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English, German
Job source

Tech stack

Software as a Service Cyber Security Phishing Tisax Information Security Management System Software Version Control

Job description

As a GRC & Information Security Specialist (m/f/d)), you will be at the center of our compliance operations. You’ll be responsible for managing evidence collection, audit coordination, and the policy lifecycle across four concurrent frameworks (ISO 27001, TISAX, SOC 2 Type II, and Cyber Essentials Plus). This role is ideal for a proactive, tech-savvy professional with 2-4 years of experience who is passionate about acting as a bridge between compliance mandates and technical teams to enable secure, international growth., * Compliance Control Management: Own the day-to-day administration and continuous improvement of our ISMS (ISO 27001/27017/27018), TISAX assessments, SOC 2 Type II controls, and Cyber Essentials Plus recertification.

  • Evidence & Audit Ownership: Coordinate internal and external audits end-to-end. You will collect, package, and present the evidence trail, managing auditor walkthroughs and finding remediations.
  • Liaison & Collaboration: Act as the crucial link between security and control owners in Engineering and HR. Translate complex compliance requirements into actionable tasks that embed seamlessly into team workflows.
  • Risk Management Execution: Maintain the risk register, coordinate quarterly reviews, and ensure treatment plans are actively managed and documented.
  • Policy Lifecycle & Privacy: Draft and version-control 90+ policies while assisting with data privacy operations, including RoPA, DPAs, and support for Data Subject Requests (DSRs) under GDPR.
  • Security Awareness & Trust: Plan and deliver security training and phishing simulations, while maintaining our Trust Centre content to transform internal security info into client-facing documents.

Requirements

We’re seeking a detail-oriented, pragmatic professional who can balance robust security requirements with the pace of a fast-growing start-up., * Proven Experience: 2-4 years of experience in a GRC or Information Security role.

  • Framework Expertise: Strong, hands-on experience with ISO 27001 and at least one other framework (TISAX, SOC 2, or Cyber Essentials Plus).
  • Policy & Risk Management: Experience managing a significant policy lifecycle (50+ policies) and maintaining risk registers/treatment plans.
  • Technical Fluency: A solid understanding of how SaaS companies operate, with the ability to translate compliance needs for engineering and product teams.
  • Language Skills: Excellent communication skills in English & German is a big plus!

Nice to Haves:

  • Background in B2B SaaS or tech start-up environments (~100-300 employees).
  • Familiarity with GRC tooling, audit management platforms, or compliance automation tools.
  • Experience working directly alongside engineering teams.

Benefits & conditions

Pulled from the full job description

  • Gym membership
  • Work from home

About the company

Our mission is to be the world’s most used AI employee experience platform by changing the way frontline employees work.

Flip is the leading AI-powered employee experience platform for frontline workers. We’re transforming how people do their jobs across the industries that keep the world running: retail, manufacturing, and logistics. One app. One touch. Everything they need.

Our mission: Connect every employee to everything they need in one touch., What we offer you

  • Work mode: We’re remote-first, giving you flexibility to work from home. At the same time, we deeply value the power of in-person collaboration. Depending on the role, you’ll join occasional team events, workshops, or meetings in our Berlin or Stuttgart offices - always with plenty of notice. The exact balance will be discussed during your interview.
  • Work-Life-Balance: We don’t want you to grow roots to your desk chair. That’s why we cover the costs of your E-Gym-Wellpass membership and offer job bike leasing.
  • Celebrating success: Expect highly motivated and committed people in a relaxed working atmosphere.
  • Be part of something bigger: You actively shape Flip in your role. Along the way, you are an enabler of the rapid growth process of a young tech company and grow towards your goals, fun is guaranteed.
  • Happy to be a Flipster: Stay tuned for regular team events and culture days that bring us together as Flipsters.
  • Working abroad: At Flip you can also work abroad in the European Union. Let’s talk about remote work in the interview.

At Flip, everyone is welcome - no matter what gender you identify as or how old you are. Sexual identity, origin, religion, world view and disabilities do not influence your potential job at Flip. The most important thing is that YOU fit in!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on de.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:15 min

Overcoming cultural resistance to achieve international security compliance standards

Ali Yazdani Ali Yazdani · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all