Information Security Officer

Spread Group
Berlin, Germany
2 days ago
Apply on www.adzuna.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
German
Job source

Tech stack

Artificial Intelligence Cyber Security Information Technology Operations Anti-Phishing Salesforce.Com Tisax Scripting Information Security Management System

Job description

SPREAD builds engineering intelligence for the world’s most complex products. Our AI-native platform gives automotive OEMs, defense primes, and industrial manufacturers a single source of product truth so engineering teams can make confident product decisions, fast. We work with companies like Volkswagen, BMW, Mercedes, Bosch, and Rheinmetall. Backed by HV Capital, DTCP, La Famiglia, and Salesforce. You’ll own SPREAD’s information security and compliance program, from ISO 27001, SOC 2, and TISAX audit cycles through to the risk register, policies, and vendor assessments that back them. You set the security requirements across the company and check that day-to-day operations meet them. You work closely with the GTM team on customer security questionnaires and with leadership on ISMS reporting each cycle, and you’ll grow the scope of what you own as the program matures. Your Mission

  • Own audit cycles end-to-end for ISO 27001, SOC 2, and TISAX, expanding scope as certifications mature.
  • Answer security questionnaires for customers and OEMs alongside the GTM team, turning fast and accurate answers into a real edge in deals.
  • Present ISMS status, risk posture, and audit results to leadership every cycle.
  • Maintain and evolve risk registers, security policies, and vendor security assessments as the company grows.
  • Run security awareness training and phishing simulations across the organization.
  • Set the security requirements for identity, device, and endpoint management, and audit that IT operations meet them.
  • Build and maintain the evidence base behind every control, closing gaps before an auditor finds them.
  • Automate repetitive compliance and evidence-collection work with platforms like Vanta.

Requirements

  • 3 to 5 years in information security, GRC, or compliance operations, with direct experience supporting a complete ISO 27001 or SOC 2 audit cycle.
  • Current or recent experience in a small, close-knit security or compliance function, not a large corporate GRC team where your scope was narrowly defined.
  • Working knowledge of identity, endpoint, and M365-style device management, strong enough to set requirements and judge whether IT operations meets them.
  • Comfort owning a risk register, a policy set, and vendor security assessments end-to-end.
  • Fluent German proficiency and eligibility to obtain a German security clearance or equivalent.
  • Bonus: Direct exposure to TISAX or the automotive OEM security ecosystem.
  • Bonus: Scripting or automation skills and the instinct to remove repetitive work.
  • Bonus: Vanta or similar compliance platform experience.

Benefits & conditions

  • You’re joining a security program that’s already protecting deals with some of the biggest names in automotive, with a clear path to owning it fully.
  • High ownership and measurable impact. You connect your work directly to the success of the organization.
  • A senior team that values craft, speed, and accountability over process and hierarchy.
  • Strong overall package including attractive compensation, VSO and an annual learning budget.
  • Mobility and wellbeing support through a Deutschlandticket mobility budget, bike-leasing and an Urban Sports partnership.
  • Time off and flexibility with 30 vacation days, and one paid volunteering day per year.

About the company

Stay connected-follow us on LinkedIn for the latest insights and updatesAbout us

SPREAD is pioneering Agentic Engineering Intelligence. Our low-code platform transforms fragmented hardware and software product data into dynamic Product Twins, creating an AI-ready knowledge base that powers smarter decisions and automation across the entire product lifecycle. At the heart of our technology lies the world’s first Universal Engineering Information Model (EIN) - a semantic framework that connects domain-specific and lifecycle data into a federated Engineering Intelligence Graph, continuously evolving over time. This foundation enables specialized AI agents to execute tasks like compliance checks, dependency analysis, and specification generation - seamlessly integrated into the tools engineers already use. The impact is tangible: companies using SPREAD achieve up to 10x faster time-to-market, 50% lower lifecycle costs, and significantly higher product quality. Industry leaders such as Volkswagen, Mercedes-Benz, BMW, Audi, Rheinmetall, and others rely on SPREAD to build the next generation of software-defined products. Headquartered in Berlin, SPREAD delivers enterprise-grade security (ISO 27001 & TISAX), full GDPR compliance, and flexible deployment options - in the cloud or on-premises.

Our Vision The future of engineering is data-driven and agentic. We make product data the most accessible, intuitive, and impactful resource in engineering - so that engineers can unleash their full creativity and drive innovation at scale.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:15 min

Overcoming cultural resistance to achieve international security compliance standards

Ali Yazdani Ali Yazdani · World Congress 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:40 min

Addressing data sovereignty and compliance blind spots within AI

Sebastian Kister Sebastian Kister · World Congress 2026 Europe

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all