About the Role
Own internal audits end to end for customers, assessing their evidence against ISO 27001 controls and providing clear reports before external audits. This is a hands-on individual contributor role with full ownership of a critical function.
Responsibilities
- Own internal audits for customers end to end, from kickoff through to the final report.
- Review and sample evidence on the Secfix platform and assess it against relevant ISO 27001 controls.
- Run customer calls and walk customers through findings and non-conformities.
- Catch non-conformities that matter, including easy ones, to prevent issues in external audits.
- Write findings that non-technical founders can act on, detailing what is missing, why it matters, and next steps.
- Manage multiple audits concurrently and ensure they stay on schedule.
- Maintain neutrality towards implementation, ensuring a clear separation between auditing and assisting.
- Learn and audit other frameworks like TISAX and ISO 42001, helping to build repeatable audit structures.
- Contribute to improving framework content on the platform, including evidence examples and guidance.
- Provide structured product feedback based on recurring issues observed on the platform.
Requirements
- German (C1/C2) and English (fluent) language proficiency.
- Up to 2 years of information security background.
- Hands-on ISO 27001 internal audit experience, with at least 10+ personally conducted internal audits.
- A PECB ISO 27001 Lead Auditor certification or equivalent.
- Direct experience auditing within a modern GRC platform.
- Ability to explain complex requirements simply in clear, concrete written and spoken English.
- Experience auditing or implementing TISAX, ISO 42001, NIS2, or SOC 2 (nice-to-have).
- Experience at an early-stage startup (Seed to Series B) (nice-to-have).
- Exposure to a modern SaaS product and cross-functional work with product teams (nice-to-have).
Skills
- ISO 27001 internal auditing
- GRC platform auditing
- Evidence review and sampling
- Customer communication
- Report writing
- TISAX auditing (nice-to-have)
- ISO 42001 auditing (nice-to-have)
- NIS2 auditing (nice-to-have)
- SOC 2 auditing (nice-to-have)
Location
- Remote
- Within EU time zones
- +/- 2hrs from Germany GMT+1
Work Type
- Remote
- Full-time
Experience Level
- Up to 2 years of information security background
- 10+ internal audits personally run
Education Level
- PECB ISO 27001 Lead Auditor certification or direct equivalent
Salary/Compensations
- Industry-competitive local salaries
- Local rates at or above market
Benefits
- 100% remote work
- Virtual office in Gather
- Competitive salary
- Generous equity package
- Access to world-class mentors
- €1,000 annual personal development budget
- Home office budget
- Access to co-working spaces
- 26 days holiday + local public holidays
- Comprehensive health coverage
- Annual retreat
- Company events
- Latest tech equipment (MacBook, monitors, headphones)
About the Company
- At the forefront of automating security compliance in Europe.
- Helps companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy, reducing manual work.
- Run by a 100% remote team with hubs in Munich, Berlin, and London.
- High-performing team looking for passionate, execution-focused individuals.
- Mission to automate security and compliance for modern companies and become the European compliance automation leader.
- Raised $12M Series A, backed by top VCs including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.
Equal Opportunity
- Equal-opportunity employer.
- Remote-only company.
- Support hiring only within EU time zones.
- Work in sync using Gather as a virtual office.
- Believe in the need for an in-sync component of daily communication.
- Cannot support 100% asynchronous work.
