Full-Time

Senior Information Security Specialist

German-speaking

Updated on 8/1/2026

Secfix

Secfix

11-50 employees

Automates ISO 27001 and SOC 2

No salary listed

Remote in Germany + 1 more

More locations: Berlin, Germany

Remote

Remote within EU time zones and generally within approximately two hours of Germany GMT+1.

Category
IT & Security (1)
Required Skills
Microsoft Azure
SOC 2
AWS
Google Cloud Platform

Get referred to Secfix

See people who can refer or advise you

Requirements
  • German at C1 or C2 level and fluent English are required.
  • At least 5 years of hands-on information security and governance, risk, and compliance experience in business-to-business software as a service.
  • Experience leading at least three successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company.
  • Hands-on experience with a governance, risk, and compliance platform such as Secfix or a similar platform.
  • Cloud infrastructure readiness across Amazon Web Services, Azure, and Google Cloud Platform, including experience with posture analysis and remediation planning.
  • Strong project management skills, including breaking ambiguous initiatives into concrete deliverables, prioritizing, and shipping.
  • Strong written communication skills for producing clear and precise compliance content for auditors, founders, and engineers.
  • Ability to operate as a senior individual contributor without waiting for direction.
  • The role requires working within European Union time zones and approximately two hours of Germany GMT+1.
  • The role requires in-sync daily communication and does not support fully asynchronous work.
Responsibilities
  • Own and drive the compliance roadmap inside the Secfix platform across ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017, ISO 27018, ISO 42001, C5, and additional frameworks as the offering expands.
  • Implement ISO 27001 and adjacent frameworks end-to-end for customers.
  • Mentor and upskill the compliance team by sharing expertise, reviewing work, and driving consistency in audits and customer deliverables.
  • Conduct internal audits for strategic and complex customers and review internal audits performed by junior team members to drive quality and consistency.
  • Act as a compliance partner to customer success managers and sales representatives by supporting customer questions and joining customer calls when deep expertise is needed.
  • Own the quality of compliance content in the platform, including policies, evidence templates, compliance enablement playbooks for customer success managers, and security awareness training.
  • Close framework gaps and incorporate auditor feedback into team practice and platform improvements.
  • Partner with product and engineering to translate compliance gaps into structured product work.
  • Collaborate with customer success, product, and founders to align compliance, customer, and roadmap priorities.
  • Deepen relationships with existing certification partners and train auditors on the Secfix platform so they can use it during customer audits.
Desired Qualifications
  • Experience implementing one or two additional compliance frameworks, such as SOC 2, GDPR, or NIS 2.
  • Experience mentoring or coaching colleagues in a compliance, audit, or governance, risk, and compliance context.
  • Experience in a startup environment.

Secfix automates security compliance for fast-growing companies by helping them obtain and maintain ISO 27001, TISAX, SOC 2, and GDPR compliance. The platform connects to a company’s apps and infrastructure, tailors itself to the business, and guides users through completing a living compliance checklist, while running hourly checks to monitor asset-wide status. It designs an ISMS and provides an auditor-approved library of security policies, and can conduct audits with certifiers to verify protection against cyber threats. Its edge is end-to-end automation of workflows, continuous monitoring, and a clear security roadmap that speeds up certifications and reduces manual work, enabling faster growth and sales.

Company Size

11-50

Company Stage

Series A

Total Funding

$15.8M

Headquarters

Munich, Germany

Founded

2021

Get referred to Secfix

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Recent $12 million Series A funds European expansion and product development.
  • Continuous monitoring and hourly checks support recurring revenue beyond initial certification.
  • Cross-framework coverage creates upsell paths into NIS2, DORA, and ISO 42001.

What critics are saying

  • Drata and Vanta can outspend Secfix on integrations, sales, and pricing.
  • CISO-as-a-Service adds labor-heavy delivery costs and compresses software margins.
  • Regulatory changes across frameworks force constant product updates and audit-risk exposure.

What makes Secfix unique

  • Automates ISO 27001, TISAX, SOC 2, GDPR, and EU AI Act workflows.
  • Connects directly to AWS, Azure, GCP, Jira, Office 365, and Personio.
  • Combines compliance automation with CISO-as-a-Service and auditor-approved policy libraries.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Paid Holidays

Health Insurance

Company Equity

Professional Development Budget

Home Office Stipend

Mentorship Program

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-11%

2 year growth

-9%
Tech.eu
Feb 25th, 2026
Secfix raises $12M Series A to build end-to-end security compliance platform

Secfix raises $12M Series A to build end-to-end security compliance platform. Secfix has raised new funding to expand its AI-driven security compliance platform across Europe, aiming to help mid-sized companies automate certification and manage ongoing cybersecurity and regulatory requirements. Munich-based Secfix, an end-to-end security compliance platform, has closed an oversubscribed $12 million Series A round led by Alstin Capital, with participation from Bayern Kapital and existing investor neosfer, an early-stage investor of the Commerzbank Group. The funding will support the company's expansion across Europe and the further development of its AI-native capabilities and CISO-as-a-Service offering. European companies have traditionally faced lengthy and resource-intensive certification processes, often requiring months of manual work and delaying commercial opportunities. Secfix was founded to address this challenge by automating compliance across standards, including ISO 27001, the EU AI Act, NIS2, GDPR, and SOC 2, helping small and mid-sized businesses reduce manual effort and streamline certification. However, certification often proved to be only the first step. As customers achieved initial certifications, many encountered growing security and compliance demands as their organisations scaled, creating demand not only for automation tools but also for ongoing expert support. In response, Secfix expanded its offering into an end-to-end security compliance platform that combines automation with an AI-native CISO-as-a-Service model. The platform provides continuous monitoring, incident management, security questionnaires, gap assessments, policy reviews, access management, cloud security scanning, penetration testing, and broader security leadership support. Fabiola Munguia, CEO and co-founder of Secfix, said the company initially focused on helping businesses achieve certification more efficiently and is now expanding its role to support customers as a broader security and compliance partner beyond the certification phase: Our vision is to solidify Secfix as Europe's leader in end-to-end security compliance - one that grows with companies from their first ISO 27001 certification through their entire security and compliance journey. With regulatory requirements such as ISO 27001, NIS2, DORA, and the EU AI Act increasing the compliance burden on European organisations, Secfix positions its platform as a combined automation and AI-driven solution informed by audit experience, customer feedback, and extensive cybersecurity expertise. The Series A funding will support Secfix's continued European expansion, further product development to enhance its AI-powered automation capabilities, and the scaling of its CISO-as-a-Service offering to meet growing mid-market demand.

Tech Funding News
Feb 25th, 2026
Secfix raises $12M to cut compliance work 90% for European SMBs

Munich-based Secfix has raised $12 million in an oversubscribed Series A round led by Alstin Capital, with participation from Bayern Kapital and existing investor neosfer. The company has now raised $17 million in total funding. Founded in 2021, Secfix provides an AI-native compliance platform that automates security certifications including ISO 27001, NIS2, GDPR, SOC 2 and DORA for European SMBs. The platform reduces compliance work by up to 90%, cutting certification timelines from 12–18 months to several weeks. Secfix combines automation with a CISO-as-a-Service model, offering continuous monitoring, incident management and security assessments. The company serves hundreds of customers across 15 European countries, including WorkMotion, Veremark and Trafigura, achieving 100% audit success rates. The funding will support European expansion and add coverage for EU AI Act, NIS2 and ISO 42001.

Secfix
Mar 2nd, 2023
Secfix announces 3.6 M EUR oversubscribed Seed Round

Secfix has raised 3.6 million EUR in Seed Round funding led by Octopus Ventures with participation from Neosfer (backed by Commerzbank), and serial entrepreneurs...

Silicon Canals
Mar 1st, 2023
Berlin-based cybersecurity firm Secfix bags €3.6M to help SMEs get security certifications easily | Silicon Canals

Berlin-based Secfix, a cybersecurity company, announced on Wednesday that it has raised €3.6M in an oversubscribed Seed round of funding led by Octopus Ventures.

Tech.eu
Mar 1st, 2023
Octopus Ventures is leading German cybersecurity outfit Secfix's €3.6 million seed fundraise

Germany's Secfix has locked down €3.6 million in an oversubscribed seed round led by pan-European VC Octopus Ventures.