Lead, IT Operations, Cyber Security and Compliance - All Genders

Doodle
Berlin, Germany
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software as a Service Cyber Security Cursor (Graphical User Interface Elements) Identity and Access Management Information Technology Operations User Provisioning Software Okta Casper Suite SentinelOne Expertise

Job description

As Lead, IT Operations, Cyber Security and Compliance, you will own security, compliance, and IT operations across Doodle. AI Governance

  • Design and own Doodle’s AI governance framework.
  • Cover agentic AI security controls, EU AI Act assessment, and MCP and Cursor risk management for external contributors.
  • Build out policy, the risk register, and technical enforcement through our SSE platform, currently evaluating Netskope.

Board & Leadership

  • Author board level cybersecurity posture presentations using the NIST CSF 2.0 framework.
  • Translate technical risk into business language for the CEO and CFO.

Compliance Programmes

  • Own and drive SOC 2 Type II, HIPAA, ISO 27001, and ISO 42001 programmes at the same time.
  • Serve as Privacy Officer, managing GDPR and Swiss FADP obligations, the DPA portfolio, and the external DPO relationship.

Security Stack

  • Operate and evolve Doodle’s full security toolset: SentinelOne and CrowdStrike for EDR, Jamf Pro for MDM, Okta and JumpCloud for IAM and SSO, Proofpoint PPS for email security (extending to Slack), and KnowBe4 for security awareness.
  • Led the EDR migration from CyberReason.
  • Operate Netskope as our CASB and SSE layer.

Vendor & Risk

  • Run a structured vendor due diligence programme: SOC 2 reviews, security questionnaires, code of conduct sign offs.
  • Support enterprise customers across government, energy, and healthcare.
  • Maintain a live risk register in Linear across 10+ active items.

IT Operations

  • Lead a lean IT team supporting 100+ headcount across Berlin, remote EU, and our contractor base.
  • Own the full lifecycle: onboarding and offboarding, access provisioning through Okta, a SaaS portfolio of around 30 tools, device management, and the service desk.
  • Maintain a compliance audit trail for SOC 2 throughout.

Process & Tooling

  • Built and automated a joint IT and PeopleOps onboarding workflow, from email to Linear ticketing with an NDA hard gate, cutting ad hoc access requests and strengthening contractor governance.
  • Evaluated and drove CLM tooling selection between Juro and Ironclad to enable self serve enterprise contract acceptance.

Requirements

We are looking for a leader who combines deep security and compliance expertise with the operational instincts to run IT for a fast moving SaaS business. Security & Compliance Expertise

  • Proven experience owning multi framework compliance programmes such as SOC 2, ISO 27001, ISO 42001, or HIPAA.
  • Experience serving as a Privacy Officer or managing GDPR/FADP obligations directly.
  • Strong understanding of EDR, MDM, IAM/SSO, and CASB/SSE tooling in a live production environment.

Governance & Risk

  • Experience building AI governance frameworks, including emerging regulation such as the EU AI Act.
  • Comfortable running a live risk register and structured vendor due diligence process.
  • Able to assess and manage risk from external contributors and third party tools.

IT Operations Leadership

  • Experience leading a lean IT team supporting 100+ employees across multiple locations.
  • Hands on with the full employee lifecycle: onboarding, offboarding, access provisioning, device management, and service desk.
  • Comfortable owning a SaaS portfolio and driving tooling decisions such as CLM platform selection.

Communication & Stakeholder Management

  • Able to translate technical risk into business language for CEO and CFO audiences.
  • Comfortable presenting security posture at board level.
  • Strong cross functional partner to PeopleOps, Legal, and external DPO relationships.

Nice to Have

  • Experience supporting enterprise customers in regulated verticals such as government, energy, or healthcare.
  • Experience with Netskope or similar SSE platforms.
  • Experience automating IT workflows using tools such as Linear.
  • Background in a high growth B2B SaaS environment.

About the company

Doodle is a B2B SaaS platform used by millions of professionals to coordinate meetings and collaboration. As we grow, trust has become one of our most valuable products. Every enterprise deal, every AI feature, every new hire depends on a secure, compliant, well run IT foundation.

You are more than an IT and Security lead. You own the governance, compliance, and operational backbone that lets Doodle move fast without breaking trust. Working closely with the CEO, CFO, PeopleOps, and external partners, you will run our security stack, our compliance programmes, and our AI governance framework, and you will lead the IT team that keeps Doodle running day to day.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:08 min

Intersecting neurodivergent support and technical operations consulting

Videos

See all

Related articles

See all