← Back to job listings
C
Senior IT Security Manager
Cosuno · Berlin, Germany
About The Role
Join Cosuno as a Senior IT Security Manager, where you'll take full ownership of information security, compliance, and IT governance. You'll lead the ISO 27001 certification process, manage the ISMS, and represent Cosuno in supplier audits. This is a senior individual contributor role with high autonomy and impact, backed by an Engineering team and direct sponsorship from the CTO. Enjoy flexible working hours, the option to work remotely or from our Berlin office, and the opportunity for workations and regular team events.
- Lead the ISO 27001 certification process from gap analysis through audit, and manage the Information Security Management System (ISMS) afterwards.
- Write and maintain security policies, ensuring they accurately reflect the organization's practices, and own responses to enterprise security questionnaires.
- Represent the company in supplier audits by enterprise customers, and manage the operational side of GDPR, including drafting and negotiating Data Processing Agreements.
- Fluency with AI tools in your daily work. You already use tools like Claude, Claude Code, or similar as a core part of how you get things done, whether that's drafting a policy, working through a questionnaire, or automating a recurring task. You see AI as a force multiplier for a one-person function, and you're eager to push it further
- The organisational maturity to run multiple threads in parallel: a certification project, an audit, three questionnaires, and a DPA negotiation, without things slipping
- Genuine technical literacy. You understand how a modern SaaS product is built and run (cloud infrastructure, CI/CD, SaaS tooling). You can read an architecture diagram, ask engineers the right questions, and write a System Development Policy that matches reality
- Operational GDPR expertise. You can draft a DPA, you know your Art. 28 from your Art. 32, and you've handled subprocessor management, vendor reviews, and DSARs in practice
- Full professional fluency in German and English. A significant part of our compliance and customer-facing security work is conducted in German, and this is a firm requirement
- Deep, hands-on ISO 27001 experience. You've built or run an ISMS before, ideally leading a company through certification. You know the Annex A controls and how companies actually implement them, and you can talk to an auditor without a script
- Independence in front of customers. You're comfortable being the sole security counterpart in an enterprise audit or a customer CISO call
- Prior experience at a B2B SaaS company selling to enterprise customers
- Experience administering an MDM / IdP (JumpCloud, Okta, Jamf, or similar)
- Experience with other frameworks relevant to our customers (SOC 2, TISAX, BSI C5, NIS2)
- Experience building your own automations with AI (agents, scripts, or workflows for questionnaires, evidence collection, or vendor reviews)
- Experience with compliance automation tooling (Kertos, Vanta, Drata, Secfix, or similar)
- ISO 27001 Lead Implementer / Lead Auditor certification, or CIPP/E
This listing was posted by a verified recruiter at Cosuno. Report this listing
JobSpring