Senior Information Security Manager (EU Sovereignty)
DeepL
Seniority
Senior
Model
In-Office
Sector
Salary
Undisclosed
Contract
Full-Time
DeepL is looking for a Senior Information Security Manager to strengthen our Governance, Risk, and Compliance (GRC) function. You'll own the day-to-day operation of our information security and compliance program, with a strong focus on ISO 27001 and SOC 2 Type II, and a bonus if you bring HIPAA or BSI C5 experience to the table.
What you'll do
- Own and continuously improve our Information Security Management System (ISMS), keeping it aligned with ISO 27001, SOC 2 Type II, and, where relevant, HIPAA and BSI C5
- Maintain and mature our risk register, policy library, vendor/third-party risk assessments, and control monitoring
- Act as a hands-on participant in audits, working directly with auditors, control owners, and leadership to prepare, execute, and close out certification and attestation cycles efficiently
- Build and refine evidence collection processes using automation and GRC tooling (e.g. Vanta or similar), reducing manual overhead and audit fatigue across the company
- Assess risk pragmatically and make calculated calls that unblock product and engineering teams
- Partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows
- Track regulatory and customer-driven compliance requirements and translate them into practical, actionable controls
- Report on the state of the security and compliance program to stakeholders and leadership
What you'll need
- 3-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company at scaleup pace and scale
- Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits
- Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent)
- A track record of building processes that shift evidence ownership to the teams generating the evidence
- Sound risk judgment and comfort making calculated, defensible risk decisions
- Strong stakeholder management skills; able to work credibly with engineers, product managers, and leadership
- Fluent English and German language skills at C1 level (or close by) are required
- Clear, structured communicator who can translate compliance requirements into language engineering and product teams actually act on
Nice to have
- Experience with HIPAA and/or BSI C5
What they offer
- Diverse and internationally distributed team with people of more than 90 nationalities
- Open communication, regular feedback, and direct collaboration
- Hybrid work schedule with flexible hours
- Virtual Shares - An ownership opportunity

