- Company: Get A Job.ai
- Location: Munich
- Salary: Pay not listed
Website Get A Job.ai
Represented by Get A Job.ai
About This Opportunity
Our talent team is representing a confidential AI technology company seeking a Senior Information Security Manager to strengthen their Governance, Risk, and Compliance function. This position is based in Munich and focuses on managing day-to-day operations of information security and compliance programs, with particular emphasis on EU sovereignty requirements.
This role is ideal for someone who understands that compliance at a fast-moving SaaS organization means enabling rather than blocking. You'll be the person who helps product teams move quickly while managing risk intelligently, saying "yes, and here's how we do it safely" rather than defaulting to "no."
Responsibilities
Program Ownership
- Own and continuously improve the Information Security Management System (ISMS), maintaining alignment with ISO 27001, SOC 2 Type II, and where relevant, HIPAA and BSI C5
- Maintain and mature the risk register, policy library, vendor risk assessments, and control monitoring processes
Audits & Evidence Management
- Serve as hands-on participant in audits, working directly with auditors, control owners, and leadership throughout certification and attestation cycles
- Build and refine evidence collection processes using automation and GRC tooling to reduce manual overhead and audit fatigue
- Design systems where product and engineering teams own their evidence throughout the control lifecycle
Risk & Business Partnership
- Assess risk pragmatically to identify real security and compliance exposure while enabling product and engineering teams
- Partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows
- Track regulatory and customer-driven compliance requirements and translate them into practical, actionable controls
Reporting
- Report on program status to stakeholders and leadership, including audit readiness, open risks, and remediation progress
What We're Looking For
- 3-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company operating at scale
- Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits, from control design through evidence collection to certification
- Experience with HIPAA and/or BSI C5 frameworks is a strong advantage
- Practical experience with GRC and evidence automation tooling such as Vanta or equivalent platforms
- Track record of building processes that shift evidence ownership to the teams generating it
- Sound risk judgment with ability to make calculated, defensible risk decisions that keep product teams unblocked
- Strong stakeholder management skills and ability to work credibly with technical and non-technical teams
- Fluent English and German language skills at C1 level required
- Clear communication style that translates compliance requirements into actionable language for engineering and product teams
How We Work With You
When you apply through Get A Job.ai, our recruiting team will review your profile and conduct an initial screening to understand your experience and career goals. If there's a strong match, we'll submit your candidacy to our client for consideration. Please apply exclusively through our platform - direct contact with the client is not part of this process and may disqualify your application.
We'll guide you through each stage of the interview process and provide feedback along the way, acting as your advocate throughout.
Pay
Compensation details will be discussed during the screening process based on your experience level and qualifications.
Equal Employment Opportunity
Get A Job.ai is committed to fair and equitable recruiting practices. We welcome candidates from all backgrounds and evaluate applications based on skills, experience, and potential for success in the role.
Apply with Get A Job.ai
A recruiter will review your profile and submit you to the client. Do not contact the client directly.
Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.
Apply through Get A Job.ai. A recruiter will review your profile and submit you.
Local insights for this role are preparing — this section updates automatically in a few seconds (or refresh).
Listing facts
- Role Senior Information Security Manager (EU Sovereignty)
- Employer Get A Job.ai
- Location Munich
- Type Full Time
- Pay (from listing) Pay not listed
- Posted September 24, 2026
- Apply by October 24, 2026
- Country Germany
- Overview Full job description on this page (545 words)
Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.
Limited public data for this employer
We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.
Explore related openings
Keep exploring on Get A Job.ai
Not quite the right fit? Your next opportunity is a click away.
- Browse all jobs
- More jobs by category
- Remote jobs you can do from anywhere
- Research typical pay for this role
- Set a job alert so new matches reach you first
- Upload your resume to apply faster
Hiring instead? Post a job and reach candidates searching right now.
