Information Security & Compliance Officer
Spread
Seniority
Midweight
Model
Hybrid
Sector
Salary
Undisclosed
Contract
Full-Time
You'll support and grow into owning SPREAD's information security and compliance program: ISO 27001, SOC 2, and TISAX, alongside the technical and IT operations that keep it running. You inherit a working program, three live certifications, and an established evidence base, not a blank slate.
What you'll do
- Support ISO 27001, SOC 2 Type II, and TISAX audit cycles end-to-end, building on our existing evidence base, and take on more ownership of each cycle as you grow into the role.
- Answer customer and OEM security questionnaires directly with the GTM team, turning security review into a reason deals close.
- Present ISMS status and audit results directly to SPREAD's leadership team each cycle.
- Maintain the risk register, policies, and vendor and supplier security assessments, keeping the whole program audit-ready year-round.
- Run security awareness training and phishing simulations across the company.
- Administer identity and access: provisioning, access reviews, conditional access, and RBAC, kept as audit evidence for the program above.
- Manage device and endpoint lifecycle across the company: procurement, enrollment, repair, and retirement.
- Own end-user IT support and the full joiner-mover-leaver process: ticket queue, onboarding and offboarding, and the office network.
What you'll need
- 3 to 5 years of hands-on experience in IT operations, InfoSec operations, or a compliance-adjacent IT role.
- Direct experience supporting a full ISO 27001 or SOC 2 audit cycle, evidence collection and auditor liaison included.
- Currently working, or recently worked, in a small security or compliance function alongside a senior person above you.
- Strong, hands-on identity and access management (Entra ID or comparable IdP): provisioning, access reviews, conditional access, RBAC.
- Strong M365/Exchange Online administration and Mac-first endpoint management.
- Comfortable owning an end-user support queue and the full joiner-mover-leaver process.
- Fluent German proficiency and eligibility to obtain a German security clearance or equivalent.
Nice to have
- Direct exposure to TISAX or the automotive OEM security ecosystem.
- Scripting or automation skills and the instinct to remove repetitive work.
- Exposure to Vanta or a similar compliance platform.
What they offer
- Attractive compensation and VSO
- Annual learning budget
- Deutschlandticket mobility budget, bike-leasing, and Urban Sports partnership
- 30 vacation days and one paid volunteering day per year

