ISO 27001 Internal Auditor at Secfix | DE | Rezi

ISO 27001 Internal Auditor at Secfix

ISO 27001 Internal Auditor

Secfix · DE

1 weeks ago

ISO 27001 Internal Auditor

Secfix · DE

13 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

We are hiring an ISO 27001 Internal Auditor to own internal audits end to end. You will audit customer implementations, review evidence on the Secfix platform, and provide clear reports before external audits. This is a hands-on individual contributor role with full ownership of a critical function.

Responsibilities

  • Own internal audits for customers end to end, from kickoff through to the final report.
  • Review and sample evidence on the Secfix platform against relevant ISO 27001 controls.
  • Conduct customer calls to discuss findings and non-conformities.
  • Identify and document non-conformities, including minor ones.
  • Write actionable findings for non-technical founders, detailing what is missing, why it matters, and next steps.
  • Manage multiple audits concurrently and ensure they stay on schedule.
  • Maintain neutrality between auditing and implementation support.
  • Learn and audit other frameworks such as TISAX, ISO 42001, NIS2, or SOC 2.
  • Contribute to improving framework content on the platform, including evidence examples and guidance.
  • Provide structured product feedback based on recurring issues observed on the platform.

Requirements

  • Up to 2 years of information security background.
  • Hands-on ISO 27001 internal audit experience, with at least 10+ internal audits personally conducted.
  • A PECB ISO 27001 Lead Auditor certification or equivalent.
  • Direct experience auditing within a modern GRC platform.
  • Clear, concrete written and spoken English, with the ability to explain complex requirements simply.
  • Ability to work remotely within +/- 2 hours of Germany GMT+1.
  • Must be able to work in sync using Gather as a virtual office; 100% asynchronous work is not supported.

Skills

  • ISO 27001 internal auditing
  • GRC platform auditing
  • English language proficiency (C2 level)

Location

  • Remote (+/- 2hrs from Germany GMT+1)
  • EU time zones

Work Type

  • Remote
  • Full-time

Experience Level

  • Up to 2 years of information security background
  • 10+ internal audits personally conducted

Education Level

  • PECB ISO 27001 Lead Auditor certification or equivalent

Salary/Compensations

  • Industry-competitive local salaries
  • At or above market local rates

Benefits

  • 100% remote work with a virtual office
  • Competitive salary
  • Generous equity package
  • Access to world-class mentors
  • €1,000 annual personal development budget
  • Home office budget
  • Access to co-working spaces
  • 26 days holiday + local public holidays
  • Comprehensive health coverage
  • Annual retreat
  • Company-wide events
  • Latest tech equipment (MacBook, monitors, headphones)

About the Company

  • At Secfix, we are automating security compliance in Europe, helping companies achieve and maintain ISO 27001, GDPR, TISAX, and SOC 2 certifications efficiently.
  • Secfix operates as a 100% remote team with hubs in Munich, Berlin, and London.
  • We are a high-performing team focused on automating security and compliance for modern companies.
  • The company has successfully raised $12M in Series A funding from investors including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.

Equal Opportunity

  • We are an equal-opportunity employer and a remote-only company.
  • Support for hiring is limited to candidates within EU time zones.