Skip to main content
Secfix

ISO 27001 Internal Auditor (German-speaking)

RemoteEurope· UTC-1…UTC+3
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to Anywhere in Europe · UTC-1…UTC+3. Set where you work from to check your eligibility.

No BS summary

ISO 27001 internal auditor with 3–4 years in information security, 10+ personally run internal audits, and a PECB ISO 27001 Lead Auditor certification or equivalent. Must have C1/C2 German, fluent English, experience auditing in a modern GRC platform, and be hireable within EU time zones.

Core skills

ISO 27001GRC platform

Optional skills

TISAXISO 42001NIS2SOC 2SaaS

Required languages

German C1/C2English Fluent

What you'll do

  • Own internal audits for our customers end to end, from kickoff through to the final report they take into their external audit
  • Review and sample evidence on the Secfix platform and assess it against the relevant ISO 27001 controls
  • Run the customer calls and walk customers through your findings and any non-conformities
  • Catch the non-conformities that matter, including the easy ones, so nothing avoidable surfaces later in an external audit
  • Write findings a non-technical founder can act on: what is missing, why it matters, and what to do next
  • Keep several audits moving at once and keep every one on schedule
  • Stay neutral to the implementation and hold a clean line between auditing and helping
  • Learn our other frameworks (TISAX, ISO 42001) and help build a repeatable audit structure for them
  • Help improve framework content on the platform, including evidence examples and guidance
  • Share structured product feedback when you spot recurring issues in the platform

What they require

  • German (C1/C2) and English (fluent) are a must for this role
  • 3 to 4 years of information security experience
  • Hands-on ISO 27001 internal audit experience, with at least 10+ internal audits you have personally run
  • A PECB ISO 27001 Lead Auditor certification or a direct equivalent
  • Direct experience auditing inside a modern GRC platform
  • Clear, concrete written and spoken English, with the ability to explain complex requirements simply
  • Bachelor's Degree in Computer Science, Information Technology, Software Engineering or related field
  • Preferred: Experience at an early-stage startup (Seed to Series B)
  • Preferred: Exposure to a modern SaaS product and cross-functional work with product teams
  • At this time, we can support hiring only within EU time zones
  • We work in sync using Gather as our virtual office
  • As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work

Benefits

  • Remote Work: 100% remote work with a virtual office in Gather.
  • Competitive Salary: Industry-competitive local salaries.We pay local rates that are at or above the market. We share this philosophy with GitLab.
  • Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success.
  • Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors.
  • Development Budget: €1,000 annual personal development budget.
  • Home office Budget: Home office budget and access to co-working spaces.
  • Holidays: 26 days holiday + local public holidays.
  • Health Insurance: Comprehensive health coverage.
  • Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Alicante!).
  • Company Events: Company-wide events to build relationships and have some fun!
  • Tech Equipment: Latest tech equipment (MacBook, monitors, headphones).

Technology

🇩🇪 GermanyInformation SecurityStartup
Salary not disclosed