IT Security & Compliance Manager (Part-Time)

VIA HealthTech

Berlin · Onsite · Full Time

Posted

Job description

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients. We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification. Aufgaben We are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end. This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build. In practice, that means: Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training Controls: deciding what a control should be, building it, and verifying that it works Vanta: keeping it current and accurate as we grow Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding SaaS security administration: configuration, permissions, access reviews across our tool landscape Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors Qualifikation Required: You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them. You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment Pragmatic judgment and strong operational ownership in a small, async-first team German at working level and fluent English — auditors and clinical customers are in German, our team works in English Nice to have: Healthcare, or another environment handling highly sensitive data Experience setting up IT and security in an…

Apply for this job