IT Security & Compliance Lead
VIA HealthTech
Berlin · Onsite · Full Time
Posted
Job description
VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients. We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification. Tasks We are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA. This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build. Your goal is to make VIA more secure while helping the team move faster, not slower. You own IT security and compliance end-to-end. In practice, that means: Cloud security, hands-on: IAM, network, encryption, logging, monitoring, detection Product security together with engineering: web, desktop, mobile, backend, AI systems DevSecOps: embedding security into the development lifecycle, threat modeling, vulnerability management Compliance end-to-end: ISO27001 and, most importantly, C5 — audits, evidence, risk management, corrective actions, auditor communication, internal training Coordinating external security work: penetration tests, security reviews, vendor assessments Internal IT security: you own design and baseline — identity, MDM, device policies, access model, on-/offboarding Requirements Required: You have built and hardened cloud security yourself (eg. AWS, GCP) — IAM, network, encryption, logging, detection — and you work in infrastructure-as-code: you change Terraform yourself, you don't file tickets for it DevSecOps and application security: secure SDLC, threat modeling, vulnerability management You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them. You work directly with engineers on technical security topics and can push back on architecture Pragmatic judgment and strong operational ownership in a small, async-first team Nice to have: Healthcare, or another environment handling highly sensitive data Experience sett…