About the Role
VIA HealthTech automates psychotherapy documentation, allowing therapists to focus more on patient care. We operate at the intersection of mental healthcare, AI, and software, with a strong emphasis on security, holding C5 and ISO27001 certifications.
Responsibilities
- Manage IT Compliance, ISMS, and IT security setup end-to-end.
- Maintain policies and implement systems, configure tools, and run audits.
- Work directly with engineering to integrate security into the development process.
- Manage ISO27001 and C5 compliance, including audits, evidence, risk management, corrective actions, auditor communication, and internal training.
- Design, build, and verify the effectiveness of security controls.
- Maintain Vanta and ensure its accuracy as the company grows.
- Own internal IT security design and baselines, including identity, MDM, device policies, endpoint hardening, and access models.
- Administer SaaS security, including configuration, permissions, and access reviews.
- Coordinate external security activities such as penetration tests and security reviews.
- Prepare security documentation like TOMs, VVT, and AVVs with vendors.
Requirements
- Experience carrying an ISO27001 certification or C5 attestation end-to-end, including audit ownership and auditor communication.
- Ability to design and implement controls, not just document them.
- Hands-on experience owning internal IT security, including identity, MDM, endpoint baselines, SaaS administration, and access models.
- Ability to configure systems directly.
- Experience working directly with engineers on technical security topics.
- Ability to judge the effectiveness of controls in a cloud-native, infrastructure-as-code environment.
- Pragmatic judgment and strong operational ownership.
- German language skills at a working level and fluent English.
- Experience in healthcare or environments handling highly sensitive data is a plus.
- Experience setting up IT and security in an early-stage or fast-growing company is a plus.
- Familiarity with German data protection practices (AVV, VVT, TOM, DPIA) is useful but not required.
Skills
- IT Compliance
- ISMS
- IT Security
- ISO27001
- C5
- Audits
- Risk Management
- Security Controls
- Vanta
- Identity Management
- MDM
- Endpoint Security
- Access Management
- SaaS Security
- Penetration Testing
- Security Documentation
- Infrastructure-as-Code
- Cloud-Native Security
Location
- Berlin Mitte
Work Type
- Part-time
- Flexible hours
Experience Level
- Hands-on execution
- Ownership
- Breadth
Benefits
- Office in Berlin Mitte
- Flexible hours
- Direct access to founders, CTO, and the full multidisciplinary team
- Equity participation
- No micromanagement
- Work at the intersection of AI, healthcare, software, and security
About the Company
- VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.
- We work at the intersection of mental healthcare, AI, and software.
- Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.
- We are a 10-person startup.
