ISO 27001 Internal Auditor

Posted Yesterday
Be an Early Applicant
26 Locations
Remote
Junior
Information Technology • Consulting • Automation
The Role
Own end-to-end ISO 27001 internal audits: review and sample evidence on the Secfix platform, run customer calls, write clear findings and remediation, keep multiple audits on schedule, stay independent from implementation, and help expand audit structures for other frameworks.
Summary Generated by Built In

Remote (+/- 2hrs from Germany GMT+1). C2 English Language is essential

At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work.

Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader.

We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.

About the Role

We're hiring an ISO 27001 Internal Auditor to own our internal audits end to end. You stay independent from the implementation work. You audit what a customer has built, review their evidence on the Secfix platform, and give them a clear report before their external audit. You assess, you find what is missing, and you tell them in plain language exactly what to do about it. This is a hands-on individual contributor role with full ownership of a function customers trust us with.

What You'll Do:

You will own internal audits to make our customers ready for their certification. We give you full context and best practices, and you own how you deliver the results. You will:

  • Own internal audits for our customers end to end, from kickoff through to the final report they take into their external audit

  • Review and sample evidence on the Secfix platform and assess it against the relevant ISO 27001 controls

  • Run the customer calls and walk customers through your findings and any non-conformities

  • Catch the non-conformities that matter, including the easy ones, so nothing avoidable surfaces later in an external audit

  • Write findings a non-technical founder can act on: what is missing, why it matters, and what to do next

  • Keep several audits moving at once and keep every one on schedule

  • Stay neutral to the implementation and hold a clean line between auditing and helping

  • Learn our other frameworks (TISAX, ISO 42001) and help build a repeatable audit structure for them

  • Help improve framework content on the platform, including evidence examples and guidance

  • Share structured product feedback when you spot recurring issues in the platform

About You:

  • Up to 2 years of information security background

  • Hands-on ISO 27001 internal audit experience, with at least 10+ internal audits you have personally run

  • A PECB ISO 27001 Lead Auditor certification or a direct equivalent

  • Direct experience auditing inside a modern GRC platform

  • Clear, concrete written and spoken English, with the ability to explain complex requirements simply

Nice-to-have:

  • Experience auditing or implementing TISAX, ISO 42001, NIS2 or SOC 2

  • Experience at an early-stage startup (Seed to Series B)

  • Exposure to a modern SaaS product and cross-functional work with product teams

What we offer

  • Remote Work: 100% remote work with a virtual office in Gather.

  • Competitive Salary: Industry-competitive local salaries.We pay local rates that are at or above the market. We share this philosophy with GitLab.

  • Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success.

  • Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors.

  • Development Budget: €1,000 annual personal development budget.

  • Home office Budget: Home office budget and access to co-working spaces.

  • Holidays: 26 days holiday + local public holidays.

  • Health Insurance: Comprehensive health coverage.

  • Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Alicante!).

  • Company Events: Company-wide events to build relationships and have some fun!

  • Tech Equipment: Latest tech equipment (MacBook, monitors, headphones).

Interview Process:

  • 45 min - Intro call with Talent team

  • Take-home Assessment

  • 1.5hr Assessment review and interview with Compliance Team

  • 45 min - Final Founder Interview with CTO

Please note: We are an equal-opportunity employer and a remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here.

Skills Required

  • Up to 2 years of information security background
  • Hands-on ISO 27001 internal audit experience; personally run 10+ internal audits
  • PECB ISO 27001 Lead Auditor certification or direct equivalent
  • Direct experience auditing inside a modern GRC platform
  • C2 English language proficiency (written and spoken)
  • Ability to work remotely within +/-2 hours of Germany (EU time zones)
  • Experience auditing or implementing TISAX, ISO 42001, NIS2 or SOC 2
  • Experience at an early-stage startup (Seed to Series B)
  • Exposure to modern SaaS products and cross-functional product work
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Berlin
23 Employees
Year Founded: 2021

What We Do

Compliance made easy and fast. We are on a mission to automate up to 90% of security compliance for small and medium-sized businesses. We help SMEs to build their own ISMS and automate security standards such as ISO 27001, TISAX, GDPR, SOC2, ISO 27701, ISO 27017, ISO 27018 and more

Similar Jobs

Mondelēz International Logo Mondelēz International

Talent Acquisition Advisor Greece

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
2 Locations
90000 Employees

Pfizer Logo Pfizer

Director, Medical Insights

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
35 Locations
121990 Employees
177K-294K Annually

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
27 Locations
150 Employees

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account