Senior IT Security Manager
Cosuno
Berlin/Remote · Onsite · Full Time
Posted
Job description
Your mission You'll take full ownership of information security, compliance, and IT governance at Cosuno. You'll build and run our ISMS, lead us through ISO 27001 certification, and become the face of Cosuno's security posture toward enterprise customers and auditors. This is a senior individual contributor role with genuine end-to-end ownership. You won't be managing a team. You'll be the expert doing the work, backed by an Engineering team that implements technical changes you define, and with direct sponsorship from the CTO. What you'll own ISMS & ISO 27001 Lead our ISO 27001 certification from gap analysis through audit, and run the ISMS afterwards: risk management, Statement of Applicability, internal audits, management reviews, and the annual control cycle Write and maintain our security policies, making sure they describe how we actually work rather than how a template says we should Customer trust & audits Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster Represent Cosuno in supplier audits by enterprise customers: you'll face customer CISOs and auditors independently, in German or English as needed Data protection (GDPR) Own the operational side of GDPR: drafting and negotiating DPAs (AVVs), managing our subprocessor list and notifications, running vendor security reviews, and supporting DSARs Work with our external counsel and DPO where legal depth is required, while handling the day-to-day yourself IT governance & access management Own our identity and access management via JumpCloud (MDM, SSO, device policies), including joiner/mover/leaver processes and periodic access reviews Define our IT security baseline: device hardening, SaaS tooling governance, security awareness training How we work High autonomy, high impact: You own these domains end to end. These responsibilities currently sit with our leadership team; the mandate is to take them over completely, not to assist. Compliance as a product: We treat security and compliance as a genuine part of how we build trust with enterprise customers, not as a checkbox exercise. You define, Engineering implements: When a policy requires technical changes (logging, backup configuration, access controls), you specify what's needed and our Engineering team builds it. You need to understand our stack well enough to have that conversation credibly, but you don't…