ISO 27001 Internal Auditor (German-speaking) at Secfix | Berlin | Rezi

ISO 27001 Internal Auditor (German-speaking) at Secfix

ISO 27001 Internal Auditor (German-speaking)

Secfix · Berlin

4 days ago

ISO 27001 Internal Auditor (German-speaking)

Secfix · Berlin

5 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Own internal audits end to end for customers, assessing their evidence against ISO 27001 controls and providing clear reports before external audits. This is a hands-on individual contributor role with full ownership of a critical function.

Responsibilities

  • Own internal audits for customers end to end, from kickoff through to the final report.
  • Review and sample evidence on the Secfix platform and assess it against relevant ISO 27001 controls.
  • Run customer calls and walk customers through findings and non-conformities.
  • Catch non-conformities that matter, including easy ones, to prevent issues in external audits.
  • Write findings that non-technical founders can act on, detailing what is missing, why it matters, and next steps.
  • Manage multiple audits concurrently and ensure they stay on schedule.
  • Maintain neutrality towards implementation, ensuring a clear separation between auditing and assisting.
  • Learn and audit other frameworks like TISAX and ISO 42001, helping to build repeatable audit structures.
  • Contribute to improving framework content on the platform, including evidence examples and guidance.
  • Provide structured product feedback based on recurring issues observed on the platform.

Requirements

  • German (C1/C2) and English (fluent) language proficiency.
  • Up to 2 years of information security background.
  • Hands-on ISO 27001 internal audit experience, with at least 10+ personally conducted internal audits.
  • A PECB ISO 27001 Lead Auditor certification or equivalent.
  • Direct experience auditing within a modern GRC platform.
  • Ability to explain complex requirements simply in clear, concrete written and spoken English.
  • Experience auditing or implementing TISAX, ISO 42001, NIS2, or SOC 2 (nice-to-have).
  • Experience at an early-stage startup (Seed to Series B) (nice-to-have).
  • Exposure to a modern SaaS product and cross-functional work with product teams (nice-to-have).

Skills

  • ISO 27001 internal auditing
  • GRC platform auditing
  • Evidence review and sampling
  • Customer communication
  • Report writing
  • TISAX auditing (nice-to-have)
  • ISO 42001 auditing (nice-to-have)
  • NIS2 auditing (nice-to-have)
  • SOC 2 auditing (nice-to-have)

Location

  • Remote
  • Within EU time zones
  • +/- 2hrs from Germany GMT+1

Work Type

  • Remote
  • Full-time

Experience Level

  • Up to 2 years of information security background
  • 10+ internal audits personally run

Education Level

  • PECB ISO 27001 Lead Auditor certification or direct equivalent

Salary/Compensations

  • Industry-competitive local salaries
  • Local rates at or above market

Benefits

  • 100% remote work
  • Virtual office in Gather
  • Competitive salary
  • Generous equity package
  • Access to world-class mentors
  • €1,000 annual personal development budget
  • Home office budget
  • Access to co-working spaces
  • 26 days holiday + local public holidays
  • Comprehensive health coverage
  • Annual retreat
  • Company events
  • Latest tech equipment (MacBook, monitors, headphones)

About the Company

  • At the forefront of automating security compliance in Europe.
  • Helps companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy, reducing manual work.
  • Run by a 100% remote team with hubs in Munich, Berlin, and London.
  • High-performing team looking for passionate, execution-focused individuals.
  • Mission to automate security and compliance for modern companies and become the European compliance automation leader.
  • Raised $12M Series A, backed by top VCs including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.

Equal Opportunity

  • Equal-opportunity employer.
  • Remote-only company.
  • Support hiring only within EU time zones.
  • Work in sync using Gather as a virtual office.
  • Believe in the need for an in-sync component of daily communication.
  • Cannot support 100% asynchronous work.