Principal Information Security Manager

Il y a 5 heures

belgium belgium Staffbase Temps plein
ph3About Staffbase /h3 /brpWe inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform . Our industry-leading and award-winning agentic AI communications channels
- intranet, employee app and email solutions
- create engaging experiences that connect and empower employees. Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis-St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience. We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we're shaping the future of workplace communication. Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale. This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance. /p /br /brh3What you’ll be doing /h3 /brpYou will act as the senior deputy for InfoSec within our Finance Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence. /p /brpYou report directly to the SVP Business Operations Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers. /p /brul /brliOwn the control framework and ensure it stays current as the business evolves /li /brliPrepare the InfoSec program for investor and MA due diligence scrutiny /li /brliCustomer Trust /li /brliOwn the response to enterprise customer security questionnaires and RFPs /li /brliRepresent Staffbase credibly in customer security reviews, calls, and audits /li /brliBuild scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality /li /brliRisk Vendor Security Maintain the risk register and drive risk treatment decisions with relevant stakeholders /li /brliOwn vendor security assessments for critical and high-risk suppliers /li /brliPartner with Procurement and Legal on AI-assisted review workflows /li /br /ul /br /brh3Policy Awareness /h3 /brul /brliOwn the internal security policy framework, keep it current, understandable, and enforced /li /brliDesign and run security awareness programs that change behaviour, not just tick boxes /li /br /ul /br /brh3Incident Response /h3 /brul /brliOwn the incident response plan and lead execution when incidents occur /li /brliCoordinate with Engineering, Legal, and leadership during incidents /li /brliDrive post-incident reviews and close findings with owners /li /br /ul /br /brh3What you need to be successful /h3 /brul /brli5+ years of hands-on InfoSec experience in a SaaS or B2B tech company /li /brliProven ownership of ISO 27001 and/or SOC 2 programs /li /brliTrack record of representing InfoSec to enterprise customers, including security reviews and escalations /li /brliMust be fluent in English /li /brliComfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations /li /br /ul /br /brh3Highly Desirable Experience /h3 /brul /brlisupporting or preparing for MA or investor due diligence processes /li /brliBackground working alongside Legal, Procurement, and Engineering /li /brliPractical understanding of cloud security architecture (enough to challenge and validate, not operate) /li /br /ul /p