ironquill.tech/board

$ cat jobs/senior-information-security-manager-f-m-d-moss-eb58e32bc8e2.json

Senior Information Security Manager (f/m/d)

Moss·EU·Berlin·senior
Apply on ashby → Get AI match score →
At Moss, we give finance professionals the power to automate their day-to-day and make forward-thinking decisions. Our team and culture make us unique — we’re driven by impact and growth, where every one of us strives to learn and excel. Recognised by Sifted’s Rising 100 https://sifted.eu/rankings/b2b-saas-rising-100-2024 and LinkedIn's Top Startups https://www.linkedin.com/pulse/linkedin-top-startups-2024-20-aufstrebende-unternehmen-bjd0c/, we’re here to help propel your career and together, make Moss a lasting success. Our Information Security team is seeking an Information Security GRC Lead (f/m/d). This role owns our security governance, risk, and compliance program - ensuring Moss meets its regulatory obligations as a BaFin-regulated EMI while enabling the business to move fast. You'll report directly to the Director of Information Security. This is a senior individual contributor role with ownership and autonomy - no direct reports currently, but potential to grow the function over time. We're looking for someone who treats GRC as an engineering problem, not a paperwork exercise. You'll drive automation, continuous control monitoring, and AI-assisted workflows to make compliance scalable and efficient. What you'll own - Unified control framework - Build and maintain a single, unified control framework mapped to DORA, ISO 27001, SOC 2 Type 2, and GDPR. Each control should be defined once - with clear ownership, technical implementation details, and evidence sources - and mapped across all relevant standards. - ICT risk management - Own the ICT risk management framework and register (based on ISO 27005 or equivalent). Identify, assess, track, and report ICT risks. Collaborate with the Risk team to integrate ICT risks into the group-wide enterprise risk framework. - GRC automation - Automate everything you can: evidence collection, control testing, reporting, policy acknowledgements. - DORA compliance - Own the DORA compliance program: gap analysis, remediation t