talentyGo

Senior Information Security Manager (GRC)

Deepl

📍 Munich, DE0💼 Full-time🕐 today
Apply now →

Sign up free in 30 seconds: you also get the AI match score with your resume.

Role overview

Deepl is hiring for the Senior Information Security Manager (GRC) role in Munich, DE. It is full-time, Senior level. It was posted today.

On TalentyGo you can review this job and apply more effectively: Charlie prepares an ATS-optimized resume and a cover letter tailored to "Senior Information Security Manager (GRC)" at Deepl in about a minute. Before you apply, you can also check how well your profile fits, with a match score based on skills, experience, location and seniority.

Role
Senior Information Security Manager (GRC)
Company
Deepl
Location
Munich, DE
Work mode
On-site
Employment
Full-time
Seniority
Senior
Posted
today

Description

Meet DeepL

DeepL is a global AI product and research company focused on building secure, intelligent solutions to complex business problems. Over 200,000 business customers and millions of individuals across 228 global markets today trust DeepL's Language AI platform for human-like translation, improved writing and real-time voice translation.
Founded in 2017 by CEO Jaroslaw “Jarek” Kutylowski, DeepL now has around 1,000 passionate employees and is supported by world-renowned investors including Benchmark, IVP, and Index Ventures.

Our goal is to become the global leader in trusted, intelligent AI technology, building products that drive better communication, foster connections, and create a meaningful impact. To achieve this, we need talented people like you to join our journey. If you’re ready to shape the future of AI and grow your career in a fast-moving, purpose-driven environment, DeepL is your next destination.

What sets us apart

What sets us apart is our blend of cutting-edge AI technology, meaningful work, and a culture where people truly thrive. We’re a team of innovators, researchers, and creators driven by a shared purpose to unlock human potential by making work simpler, smarter, and more connected.

When we share what it’s like to work at DeepL, the reactions are overwhelmingly positive. This might be because of our technology that helps millions of people and businesses communicate and work better every day, or because of the trust, curiosity, and care that shape our culture.

What we know for sure is this: being part of DeepL means joining a team dedicated to innovation, growth, and well-being. Discover more about life at DeepL onLinkedIn,Instagram, and our Blog.

Meet the team behind this journey

DeepL is looking for a Senior Information Security Manager to strengthen our Governance, Risk, and Compliance (GRC) function. You'll own the day-to-day operation of our information security and compliance program, with a strong focus on ISO 27001 and SOC 2 Type II, and a bonus if you bring HIPAA or BSI C5 experience to the table.

This isn't a "gatekeeper" role. We're a SaaS scale-up, and our product teams move fast. We need someone who understands risk well enough to take calculated ones, someone who can say "yes, and here's how we do it safely" instead of defaulting to "no." You'll be the person who keeps compliance moving at the speed of the business, not the person who slows it down.

You'll be part of our Information Security team, sitting within the broader Security track alongside the IT Security team, both under our Head of Security. You'll work closely with your teammates in Information Security and IT Security to make sure security and compliance work hand in hand rather than in separate lanes.

Your responsibilities

Program ownership

  • Own and continuously improve our Information Security Management System (ISMS), keeping it aligned with ISO 27001, SOC 2 Type II, and, where relevant, HIPAA and BSI C5

  • Maintain and mature our risk register, policy library, vendor/third-party risk assessments, and control monitoring

Audits & evidence

  • Act as a hands-on participant in audits, working directly with auditors, control owners, and leadership to prepare, execute, and close out certification and attestation cycles efficiently rather than through brute force

  • Build and refine evidence collection processes using automation and GRC tooling (e.g. Vanta or similar), reducing manual overhead and audit fatigue across the company

  • Design and roll out a model where product and engineering teams own their evidence throughout the control lifecycle, rather than compliance chasing people down before every audit

Risk & business partnership

  • Assess risk pragmatically: identify real security and compliance exposure, size it accurately, and make calculated calls that unblock product and engineering teams

  • Partner with engineering, product, IT, People, and Legal to embed security and compliance requirements into existing workflows rather than bolting them on afterward

  • Track regulatory and customer-driven compliance requirements — new customer security questionnaires, evolving frameworks — and translate them into practical, actionable controls

Reporting

  • Report on the state of the security and compliance program to stakeholders and leadership, including audit readiness, open risks, and remediation progress

Qualities we look for

  • 3-5 years of experience in information security, GRC, or compliance roles, ideally at a SaaS company, and ideally at scaleup pace and scale

  • Hands-on experience running or supporting ISO 27001 and SOC 2 Type II programs and audits, from control design through evidence collection to certification

  • Experience with HIPAA and/or BSI C5 is a strong plus

  • Practical experience with GRC/evidence automation tooling such as Vanta (or equivalent), including building smooth, low-friction processes around it

  • A track record of building processes that shift evidence ownership to the teams generating the evidence, rather than centralizing it all in compliance

  • Sound risk judgment: comfortable making calculated, defensible risk decisions to keep product teams unblocked, rather than reflexively blocking

  • Strong stakeholder management skills; able to work credibly with engineers, product managers, and leadership without becoming an obstacle

  • Fluent English and German language skills at C1 level (or close by) are required

  • Clear, structured communicator who can translate compliance requirements into language engineering and product teams actually act on

What we offer

  • Diverse and internationally distributed team: joining our team means becoming part of a large, global community with people of more than 90 nationalities. We're more than just colleagues; we're a group of professionals with a shared mission to connect diverse cultures. Our global presence is growing–we've doubled in size nearly every year, with our employees based in the UK, Germany, the Netherlands, Poland, the US, and Jap

The market for this role in Munich

TalentyGo lists 14265 similar roles (4 in Munich), 13% remote. Charlie ranks them against your CV, each with a clear score.

Similar roles
14265
Remote
13%
New / 7d
642

Similar jobs

Lead Physical Security Engineer
📍 Amsterdam · tech
Business Development Manager, DACH
📍 Dublin · sales
Product Design Manager, Global Payments
📍 United Kingdom · design
Deal Desk Manager
📍 Remote - Singapore · Remote · tech
Solutions Consultant Manager, Enterprise
📍 Tokyo · Remote · consulting
Tax Manager
📍 Raleigh · finance
See all similar jobs →
Apply now →

TalentyGo is an aggregator of job postings from public sources. Always verify information directly with the company. Applications go through the original company website; TalentyGo does not manage hiring processes.