ApexHire
United Kingdom (UK) πŸ›‘οΈ UK Work Eligibility πŸ’Ό Full-time
Staffbase - Principal Information Security Manager
Staffbase βœ“ Verified Employer

Principal Information Security Manager

πŸ“ Dresden, Sachsen β€’ πŸ•’ Active Opening
Verified Base Compensation
Salary Disclosed on Application / year
⚑ Full Benefits Package Apply Now β†’
Official Specifications

Role Overview & Mandate

Executive Summary

<div class="content-intro"><h3><strong>About Staffbase</strong></h3> <p>We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communica

πŸ›‘οΈ
Verified by ApexHire Intelligence Desk Active Audit

Reviewed by Compensation & Visa Analysts
Sources: USCIS E-Verify & Home Office CoS

Featured Partner Opportunities
Sponsored
<div class="content-intro"><h3><strong>About Staffbase</strong></h3> <p>We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first <strong>AI-native Employee Experience Platform</strong>. Our<strong> industry-leading and award-winning agentic AI communications channels</strong> - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.</p> <p>Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St.β€―Paul, our diverse team of 550+ employees supports 1,500+ customersβ€”reaching over 14 million employeesβ€”in transforming their employee experience.<br>We are proud to be a&nbsp;<strong data-stringify-type="bold">Unicorn</strong>&nbsp;companyβ€”privately valued at over $1 billionβ€”demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.</p></div><p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.</span></p> <p><span style="font-family: arial, helvetica, sans-serif;"><span style="font-size: 14pt;">This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.<br><br></span><span style="font-size: 14pt;">The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.&nbsp;<br><br></span><span style="font-size: 14pt;">You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.</span></span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>What you’ll be doing</strong></span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">You will act as the senior deputy for InfoSec within our Finance &amp; Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">You report directly to the SVP Business Operations &amp; Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.<br><br>You will own;</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Compliance &amp; Audit</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif;"><span style="font-size: 14pt;">Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation</span></span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Own the control framework and ensure it stays current as the business evolves</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Prepare the InfoSec program for investor and M&amp;A due diligence scrutiny</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Customer Trust</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Own the response to enterprise customer security questionnaires and RFPs</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Represent Staffbase credibly in customer security reviews, calls, and audits</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Risk &amp; Vendor Security</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Maintain the risk register and drive risk treatment decisions with relevant stakeholders</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Own vendor security assessments for critical and high-risk suppliers</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif;"><span style="font-size: 14pt;">Partner with Procurement and Legal on AI-assisted review workflows</span></span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Policy &amp; Awareness</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Own the internal security policy framework, keep it current, understandable, and enforced</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Design and run security awareness programs that change behaviour, not just tick boxes</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Incident Response</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Own the incident response plan and lead execution when incidents occur</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Coordinate with Engineering, Legal, and leadership during incidents</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Drive post-incident reviews and close findings with owners</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>What you need to be successful </strong></span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Essential Experience</strong></span></p> <ul class="ul1"> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">5+ years of hands-on InfoSec experience in a SaaS or B2B tech company</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Proven ownership of ISO 27001 and/or SOC 2 programs</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Track record of representing InfoSec to enterprise customers, including security reviews and escalations</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Must be fluent in German and English</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations</span></li> </ul> <p class="p1"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>Highly Desirable</strong></span></p> <ul class="ul1"> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Experience supporting or preparing for M&amp;A or investor due diligence processes</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Background working alongside Legal, Procurement, and Engineering</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Practical understanding of cloud security architecture (enough to challenge and validate, not operate)</span></li> <li class="li1" style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;">Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><strong>What you'll get&nbsp;</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif;"><em>Competitive Compensation</em> - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-size: 14pt; font-family: arial, helvetica, sans-serif;"><em>Flexibility </em>- we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-family: arial, helvetica, sans-serif;"><em>Recharge</em> - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-size: 14pt; font-family: arial, helvetica, sans-serif;"><em>Support</em><strong> </strong>-<strong> </strong>we’re offering a company pension scheme</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 14pt;"><span style="font-size: 14pt; font-family: arial, helvetica, sans-serif;"><em>Volunteers Day</em><strong> </strong>- you’ll get one day off per year for supporting a social project</span></li> </ul><div class="content-conclusion"><h3><strong><img src="https://imgur.com/a/kIbq0q5" alt="" style="max-width: 100%;"></strong></h3></div>

Find Jobs in Germany on Arbeitnow

Verified Partner Network
Sponsored
Ready to submit your candidacy? Apply Now β†’
Compensation Analytics

Estimated Take-Home Pay

Calculator β†’

Projected statutory deductions based on standard single-filer baseline tax regulations in the Dresden, Sachsen corridor.

Gross Annual Package Salary Disclosed on Application
Est. Income Tax Band 20% - 40% Progressive Bracket
Statutory Insurance / FICA 8% Class 1 National Insurance (NI)
Estimated Monthly Net Β£3,900 - Β£4,401 / mo
Regional Economics

Cost of Living (Dresden, Sachsen)

Bureau Data
Est. Rent (1-Bed)
Β£1,100 - Β£1,750
Monthly Utilities
Β£140 - Β£210
Cost Index
112.5
Disposable Tier
Top 15% Rank
πŸ›‚
Compliance Standards

Work Authorization Framework

βœ“ Verified Status: UK Work Eligibility
β„Ή Corridor: UK Employment Corridor
πŸ›‘οΈ Zero Fee: Direct corporate recruitment with zero placement charges.

Candidate Selection Pipeline

Direct Corridor Track
01
Direct Apply

Submit verified credentials & CV.

02
HR Screening

2-4 day credential verification.

03
Technical Panel

In-depth domain & team interview.

04
Official Offer

Corridor contract & relocation.

Peer Roles

Explore Related Positions (Dresden, Sachsen)

View All UK Jobs β†’
Kensington Capital & Analytics
Kensington Capital & Analytics πŸ“ London, England
Β£75,000 - Β£95,000

Principal Data Analytics Specialist

πŸ›‘οΈ UK Right to Work / Skilled Worker Eligible View Role
NHS Greater Manchester Health Trust
NHS Greater Manchester Health Trust πŸ“ Manchester, England
Β£43,742 - Β£50,056

Senior Clinical Diagnostic Radiographer

πŸ›‘οΈ HCPC Registration Required View Role
Caledonia Cloud Infrastructure
Caledonia Cloud Infrastructure πŸ“ Edinburgh, Scotland
Β£70,000 - Β£88,000

Senior Site Reliability & Kubernetes Engineer (SRE)

πŸ›‘οΈ Skilled Worker Visa Sponsor View Role
University Hospitals Birmingham NHS Trust
University Hospitals Birmingham NHS Trust πŸ“ Birmingham, England
Β£93,666 - Β£126,281

Consultant Acute Care Physician (General Medicine)

πŸ›‘οΈ GMC Specialist Register Required View Role
Thames Corporate Assurance Ltd
Thames Corporate Assurance Ltd πŸ“ London, England
Β£95,000 - Β£125,000

Head of Cyber Security & Zero Trust Architecture

πŸ›‘οΈ UK Right to Work / Tier 2 Licensed View Role
diligentcorporation
diligentcorporation πŸ“ London
Salary Disclosed on Application

Senior Solutions Sales Executive - Risk & Audit

πŸ›‘οΈ UK Work Eligibility View Role
Career Discovery Hubs

Browse Connected Categories & Regional Corridors