Job
- Level
- Erfahren
- Job Feld
- IT, System, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Ort
- Wien, Berlin
- Arbeitsmodell
- Hybrid, Onsite
Job Zusammenfassung
In dieser Rolle übernimmst du die Verantwortung für das ISO/IEC 27001 ISMS, führst Audits durch und entwickelst Datenschutzprogramme, während du eng mit Engineering und Operations an Compliance-Maßnahmen arbeitest.
Job Technologien
Deine Rolle im Team
- We're looking for an Information Security Compliance Manager (ISO 27001 / GDPR / HIPAA) to take ownership of our certified ISO/IEC 27001 ISMS and our privacy program in a health-data SaaS environment.
- You will maintain and continuously improve our ISO 27001 system (supported by Vanta), lead internal and external (surveillance) audits, and evolve our GDPR setup to also cover HIPAA expectations and special categories of data in close partnership with Engineering and Tech.
- Take over end-to-end ownership of our certified ISO 27001 ISMS, ensuring it stays effective, current, and audit-ready year-round.
- Lead preparation and execution support for surveillance audits, including evidence readiness, stakeholder preparation, and closing findings.
- Run the internal audit program and drive corrective actions (CAPA) to closure with clear ownership and measurable outcomes.
- Harmonize security and privacy governance by aligning ISO 27001 and GDPR processes (risk, vendor management, incident/breach handling, access governance, retention).
- Expand the privacy program from GDPR to include HIPAA-related requirements and robust handling of health/sensitive data (incl. vendor/subprocessor controls).
- Translate security/privacy requirements into pragmatic, actionable work for Engineering and Operations ("what needs to be done, how, and what evidence is needed").
- Improve scalability of compliance operations using Vanta (evidence automation, control monitoring, clean documentation) and help prepare for future SOC 2 / NIST needs.
Unsere Erwartungen an dich
Qualifikationen
- Hands-on ownership of an ISO/IEC 27001 ISMS in a certified organization, including operating cadences (risk, SoA, control reviews, metrics, continual improvement).
- Ability to plan/execute (or coordinate) internal audits and drive corrective actions through to verified completion.
- Comfort working in environments processing health data / special categories of data, and ability to operationalize privacy and security expectations (HIPAA exposure is a plus).
- Solid technical foundation to collaborate with Engineering on controls and evidence (IAM/SSO/MFA/RBAC, logging/audit trails, vulnerability & patch mgmt, change mgmt, cloud/SaaS fundamentals).
- Excellent English communication skills (written and verbal); German is a plus.
- Location: Vienna or Berlin (hybrid/onsite expectations as applicable).
Erfahrung
- 3-5 years of experience in information security compliance / ISMS / GRC in a tech or SaaS environment.
- Audit experience you can point to: participation/leadership in external audits (surveillance/recertification) and successful closure of findings.
- Practical GDPR operations experience (e.g., RoPA, DPIAs, vendor/subprocessor governance, DSAR coordination, incident/breach support).
Job Standorte
Themen mit denen du dich im Job beschäftigst
Das ist dein Arbeitgeber
Flinn
Flinn ist ein führendes Unternehmen im Bereich der MedTech-Automatisierung, das eine AI-gesteuerte Plattform zur Optimierung regulatorischer und Qualitätsprozesse anbietet. Das Unternehmen setzt auf innovative Technologien, um die Branche voranzubringen.
Description
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Hybrid, Onsite
- Branche
- Gesundheitswesen, Soziales