Staffbase
Principal Information Security Manager - remote working within Germany
Remote role where the employee must remain based in a particular country.
Germany only
Employer listed it 5 days ago · Added yesterday
First listed 5 days ago and still open.
Salary
Not stated
Location
Germany only
Timezone
CET ±2
Contract
Full-time
Experience
Lead
Category
Operations
This employer didn't state pay. Jobs like this usually pay around $160k–$250k a year, a typical range taken from 145 lead-level operations roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Germany. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Germany Remote, Staffbase GmbH, Berlin, Staffbase GmbH, Chemnitz, Staffbase GmbH, Dresden"
What Nomaders makes of it
- Residency required in Germany
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Staffbase
We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform . Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.
Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience. We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.
Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.
This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance. The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to. You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.
What you’ll be doing
You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.
You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers. You will own;
Compliance & Audit
Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
Own the control framework and ensure it stays current as the business evolves
Prepare the InfoSec program for investor and M&A due diligence scrutiny
Customer Trust
Own the response to enterprise customer security questionnaires and RFPs
Represent Staffbase credibly in customer security reviews, calls, and audits
Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality
Risk & Vendor Security
Maintain the risk register and drive risk treatment decisions with relevant stakeholders
Own vendor security assessments for critical and high-risk suppliers
Partner with Procurement and Legal on AI-assisted review workflows
Policy & Awareness
Own the internal security policy framework, keep it current, understandable, and enforced
Design and run security awareness programs that change behaviour, not just tick boxes
Incident Response
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Staffbase, mentioning your remote working experience and working hours (CET ±2).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open operations roles with comparable remote rules.
Free to apply, no account needed.
Typically $160k to $250k per year · You'll be taken to the employer's careers page.