> Markdown version of [/jobs/ext/1176059-grc-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/1176059-grc-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC & Information Security Specialist - **Company:** Flip GmbH - **Location:** Stuttgart, Germany (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Phishing, Tisax, Information Security Management System, Software Version Control - **Published:** July 4, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=04f81bb3c67b75e2 ## About the Role We're seeking a detail-oriented, pragmatic professional who can balance robust security requirements with the pace of a fast-growing start-up., * Proven Experience: 2-4 years of experience in a GRC or Information Security role. * Framework Expertise: Strong, hands-on experience with ISO 27001 and at least one other framework (TISAX, SOC 2, or Cyber Essentials Plus). * Policy & Risk Management: Experience managing a significant policy lifecycle (50+ policies) and maintaining risk registers/treatment plans. * Technical Fluency: A solid understanding of how SaaS companies operate, with the ability to translate compliance needs for engineering and product teams. * Language Skills: Excellent communication skills in English & German is a big plus! Nice to Haves: * Background in B2B SaaS or tech start-up environments (~100-300 employees). * Familiarity with GRC tooling, audit management platforms, or compliance automation tools. * Experience working directly alongside engineering teams. ## Description As a GRC & Information Security Specialist (m/f/d)), you will be at the center of our compliance operations. You'll be responsible for managing evidence collection, audit coordination, and the policy lifecycle across four concurrent frameworks (ISO 27001, TISAX, SOC 2 Type II, and Cyber Essentials Plus). This role is ideal for a proactive, tech-savvy professional with 2-4 years of experience who is passionate about acting as a bridge between compliance mandates and technical teams to enable secure, international growth., * Compliance Control Management: Own the day-to-day administration and continuous improvement of our ISMS (ISO 27001/27017/27018), TISAX assessments, SOC 2 Type II controls, and Cyber Essentials Plus recertification. * Evidence & Audit Ownership: Coordinate internal and external audits end-to-end. You will collect, package, and present the evidence trail, managing auditor walkthroughs and finding remediations. * Liaison & Collaboration: Act as the crucial link between security and control owners in Engineering and HR. Translate complex compliance requirements into actionable tasks that embed seamlessly into team workflows. * Risk Management Execution: Maintain the risk register, coordinate quarterly reviews, and ensure treatment plans are actively managed and documented. * Policy Lifecycle & Privacy: Draft and version-control 90+ policies while assisting with data privacy operations, including RoPA, DPAs, and support for Data Subject Requests (DSRs) under GDPR. * Security Awareness & Trust: Plan and deliver security training and phishing simulations, while maintaining our Trust Centre content to transform internal security info into client-facing documents. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Where to Find German Tech Jobs](https://www.wearedevelopers.com/magazine/366-where-to-find-german-tech-jobs) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [Jobs in Germany for Americans](https://www.wearedevelopers.com/magazine/423-jobs-in-germany-for-americans) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)