About the job
Fully Remote (CET ±2h) | Proficiency in German (C1/C2) & English is essential.
While we prefer a full-time commitment, we also offer this role for contractors with 25+ hours-per-week available in the initial months.
At Secfix, our customers are our priority, and we seek a standout Information Security Specialist to support clients in the DACH region. In this role, you will manage the complete security and compliance lifecycle—from onboarding through certification and ongoing compliance. As a trusted advisor, you will improve processes, collaborate with various teams, and contribute to innovative AI products. You will enjoy competitive equity and benefits while working in a 100% remote environment alongside a talented and engaging team.
About Secfix
Secfix is on an ambitious mission to create a robust platform that simplifies security compliance for growing businesses across Europe. We have successfully assisted numerous startups and scaleups in the DACH region in becoming audit-ready in record time—and we are just getting started. Recently, we secured $12 million in Series A funding, with backing from prominent VCs such as Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.
Responsibilities
The Information Security Specialist at Secfix combines the roles of vCISO and account manager. You will assess clients' existing security and compliance frameworks, provide actionable recommendations, assist in implementation, and serve as the primary contact for audits. Additionally, you will collaborate closely with our CTO on new AI product features.
Manage the compliance lifecycle: Oversee onboarding, certification, and continuous compliance; define controls (SoA), drive risk mitigation, and document evidence and closure of gaps; create customer roadmaps; conduct audits ensuring a successful outcome as the main security point of contact.
Enhance the tech stack: Evaluate security posture and align controls with AWS/Azure/GCP, Kubernetes/Docker/Terraform; formulate new best practices; prioritize actionable remediation with set timelines.
Leverage framework expertise: Customize programs across ISO 27001, SOC 2, NIST, and other frameworks, aligning them with clients' specific environments and goals.
Facilitate delivery & represent Secfix: Develop and maintain runbooks, templates, quality assurance, and more to ensure effective operations.

