GRC & Information Security Specialist (m/w/d)

2 hours, 35 minutes ago
Full-time
Junior
Cybersecurity
Flip App

Flip App

Flip is the employee app reshaping workplace communication by empowering every employee with a digital workspace for effective communication and workflow management.

Internet Software & Services
51-250
Founded 2018

Description

  • Manage the daily administration and continuous improvement of the ISMS and related compliance controls across ISO 27001/27017/27018, TISAX, SOC 2 Type II, and Cyber Essentials Plus.
  • Coordinate internal and external audits end to end, including evidence collection, auditor walkthroughs, and tracking corrective actions.
  • Act as the liaison between security stakeholders and control owners in Engineering and HR, translating compliance requirements into actionable tasks.
  • Maintain the risk register, lead quarterly risk reviews, and ensure treatment plans are actively managed and documented.
  • Own the policy lifecycle, including creating, versioning, and maintaining more than 90 policies.
  • Support privacy operations, including records of processing activities, data processing agreements, and data subject requests under GDPR.
  • Plan and deliver security awareness trainings and phishing simulations.
  • Maintain the Trust Center and turn internal security information into customer-ready documentation.

Requirements

  • 2–4 years of relevant experience in GRC or information security.
  • Hands-on experience with ISO 27001 and at least one additional framework such as TISAX, SOC 2, or Cyber Essentials Plus.
  • Experience managing a large policy lifecycle of 50+ policies and maintaining risk registers and action plans.
  • Solid understanding of how SaaS companies operate and the ability to explain compliance needs to Engineering and Product teams.
  • Excellent communication skills in German and English at business-fluent level.
  • Experience in B2B SaaS or tech startups with around 100–300 employees is preferred.
  • Familiarity with GRC software, audit management platforms, or compliance automation tools is preferred.
  • Experience working directly with Engineering teams is preferred.

Benefits

  • Remote-first work setup with flexibility to work from home.
  • Occasional in-person collaboration, team events, workshops, or meetings in Berlin or Stuttgart with advance notice.
  • Company-covered EGYM Wellpass membership.
  • JobRad bicycle leasing.
  • Regular team events and Culture Days.
  • Opportunity to work from other European countries as part of a workation arrangement.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Global Sanctions Lead

Stripe 5K-10K Diversified Financial Services

Stripe is seeking a Global Sanctions Lead to own and evolve its worldwide sanctions program within the Financial Crimes team, modernizing operations while helping protect the platform from financial crime and regulatory risk.

29 minutes ago

Security Operations Center (SOC) Engineer

FirmaTRUST Internet Software & Services

ICE Consulting is hiring a Security Operations Center (SOC) Engineer to monitor, analyze, and respond to security threats while strengthening the company’s and clients’ security posture.

DNS HTTP Metasploit PowerShell Python SIEM Splunk TCP/IP
1 hour, 27 minutes ago

GRC and Security Analyst

Lucidya 51-250 Media

Lucidya is hiring a Security Analyst to support global security, privacy, and compliance operations across its AI-native customer experience platform as it expands internationally.

Bash Penetration Testing Python Ruby Ruby on Rails
3 hours, 5 minutes ago

Healthcare Compliance Manager

Reworks Solutions Internet Software & Services

ReWorks Solutions is seeking a remote Healthcare Compliance Manager in South Africa to oversee compliance operations, maintain regulatory adherence, and support audits and risk management for U.S.-hour healthcare work.

HIPAA
3 hours, 20 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers