RVC
JobsFor Employers
16 jobsSort: Relevance
4d 5h ago

IT Security & Compliance Manager

VIA HealthTech·General InfoSec · Healthtech
🏢On-site
|Berlin, Germany
iso_27001
7d 17h ago

Network Security Administrator

Betby.com·General InfoSec
📡Fully Remote
|Riga
documentationtroubleshootingwaf
11d 21h ago

Security Operations Analyst

Teradata·General InfoSec · Information Technology
📡Fully Remote
firewallspythonsiemtcp_ip
12d 9h ago

Threat Exposure Analyst

True Zero Technologies·General InfoSec · Cybersecurity
📡Fully Remote
analytics
12d 9h ago

Cyber Remediation Coordinator

True Zero Technologies·General InfoSec · Information Technology
📡Fully Remote
12d 10h ago

Security Analyst

Aptoslabs·General InfoSec
📡Fully Remote
$120k - $180k USD
12d 23h ago

IAM Engineer

Primer·General InfoSec · Financial Technology
📡Fully Remote
golangpython
13d 9h ago

Threat Analyst

Sophos·General InfoSec · Cybersecurity
📡Fully Remote
analyticslog_analysistroubleshooting
2d 2h ago

Network Security Engineer

WCC Technologies Group·General InfoSec · Telecom / Communications
📡Fully Remote
$5000 - $7000 USD
ansibleawsazurebgp+13
3d 2h ago

Splunk Developer

PulseRise Technologies·General InfoSec · Information technology
📡Fully Remote
automationbashcloud_servicesdata_science/data_engineering+9
3d 12h ago

Application Security Engineer

Ardent·General InfoSec · Information Technology
📡Fully Remote
ci/cddevsecops
5d 11h ago

PSC Engineer

Finite State·General InfoSec · Cybersecurity
📡Fully Remote
apiautomationc_cppgolang+3
6d 13h ago

Ethical Hacker

Insight Assurance·General InfoSec · Audit and Cybersecurity
📡Fully Remote
active_directoryawsazurebash+3
6d 15h ago

Head of IT Compliance

ARRISE·General InfoSec · iGaming
📡Fully Remote
iso_27001risk_management
7d 4h ago

Security Engineer

Mozilla Corporation·General InfoSec · Technology
📡Fully Remote
iso_27001
7d 4h ago

Principal GRC Architect

SimScale GmbH·General InfoSec · Technology, Information and Internet
📡Fully Remote
|Relocation
awsgdprnetwork_security

IT Security & Compliance Manager

VIA HealthTech | General InfoSec | Healthtech
On-site
Part Time
Germany, Berlin
Source not independently verified
Confirm the company and recruiter through an official company domain before applying. Never pay money, share one-time codes, sign out of your Apple or Google account, install apps or configuration profiles, or run code from a repository sent by a recruiter.

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Aufgaben

We are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end.

This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build.

In practice, that means:

  • Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training
  • Controls: deciding what a control should be, building it, and verifying that it works
    Vanta: keeping it current and accurate as we grow
  • Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding
  • SaaS security administration: configuration, permissions, access reviews across our tool landscape
  • Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments
  • Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors

Qualifikation

Required:

  • You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.
  • You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself
  • You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment
  • Pragmatic judgment and strong operational ownership in a small, async-first team
    German at working level and fluent English — auditors and clinical customers are in German, our team works in English

Nice to have:

  • Healthcare, or another environment handling highly sensitive data
  • Experience setting up IT and security in an early-stage or fast-growing company
  • German data protection practice: AVV, VVT, TOM, DPIA. We have an external Datenschutzbeauftragter for the legal depth, so this is useful but not required.

What matters beyond the checklist:

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.

We are not looking for someone who only writes policies, but for someone who builds and operates the security and compliance foundation VIA needs as it scales.

The role is part-time given the small team size, but workloads may vary (eg. increased when building certain security features or during the audit periods).

Benefits

  • Office in Berlin Mitte, flexible hours
  • Direct access to founders, CTO, and the full multidisciplinary team
  • Broad ownership over a core company function
  • Equity participation
  • No micromanagement — results over hours logged
  • Work at the intersection of AI, healthcare, software, and security

Required Skills

iso_27001

Required Languages

🇩🇪 German, 🇬🇧 English

Key competency: General InfoSec
Roles
PythonJavaReactTypeScriptNode.jsGoRustDevOpsData scienceProductDesign
Remote
United StatesUnited KingdomCanadaGermanyPolandSpainNetherlandsPortugal
Work type
Fully remoteRemote in-countryHybridSeniorMid-levelJuniorAll jobs
R© 2026 ReVacancybuild 854cba87
AboutContactPrivacyCookiesRefundsTerms & ConditionsFor Employers