> Markdown version of [/jobs/ext/86183-principal-information-security-manager](https://www.wearedevelopers.com/jobs/ext/86183-principal-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Information Security Manager - **Company:** Staffbase GmbH - **Location:** Chemnitz, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security - **Published:** May 29, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=54a8299be2e40d3b ## About the Role Do you have experience in SaaS?, * 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company * Proven ownership of ISO 27001 and/or SOC 2 programs * Track record of representing InfoSec to enterprise customers, including security reviews and escalations * Fluent in German and English * Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations Highly Desirable * Experience supporting or preparing for M&A or investor due diligence processes * Background working alongside Legal, Procurement, and Engineering * Practical understanding of cloud security architecture (enough to challenge and validate, not operate) * Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built ## Description Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale. This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance. The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to. You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company. What you'll be doing You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence. You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers. You will own; Compliance & Audit * Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation * Own the control framework and ensure it stays current as the business evolves * Prepare the InfoSec program for investor and M&A due diligence scrutiny Customer Trust * Own the response to enterprise customer security questionnaires and RFPs * Represent Staffbase credibly in customer security reviews, calls, and audits * Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality Risk & Vendor Security * Maintain the risk register and drive risk treatment decisions with relevant stakeholders * Own vendor security assessments for critical and high-risk suppliers * Partner with Procurement and Legal on AI-assisted review workflows Policy & Awareness * Own the internal security policy framework, keep it current, understandable, and enforced * Design and run security awareness programs that change behaviour, not just tick boxes Incident Response * Own the incident response plan and lead execution when incidents occur * Coordinate with Engineering, Legal, and leadership during incidents * Drive post-incident reviews and close findings with owners ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)