Source Job

$86,400–$108,000/yr
Germany

  • Own and run the ISMS, lead ISO 27001 certification, and manage risk, policies, and audits end-to-end.
  • Handle customer security questionnaires, RFIs, and supplier audits independently as the sole security expert.
  • Manage GDPR compliance, including DPAs, subprocessor lists, vendor reviews, and DSARs with operational ownership.

ISO 27001 GDPR IT Governance Technical Literacy

17 jobs similar to Senior IT Security Manager

Jobs ranked by similarity.

Germany

  • Consult clients on creation, implementation, and review of security concepts in a project-leading role.
  • Conduct IT risk analyses and implement security standards and processes.
  • Proactively identify client needs, document and evaluate processes, and design tailored solutions.

SITS Group is a leading IT security group providing holistic security solutions. With over 700 employees, the company fosters an open, respectful, and team-oriented culture that values individual contributions.

$51,840–$64,800/yr
Europe

  • Support the ISO 27001 program by maintaining audit readiness, running evidence collection, and managing access reviews.
  • Perform recurring security operations including vulnerability scanning, risk assessments, and vendor reviews.
  • Collaborate cross-functionally to harden identity and access management, respond to security questionnaires, and support AI governance initiatives.

Didomi is a consent management platform that helps companies manage user consent and data privacy. The company is a growing SaaS organization with a collaborative culture, emphasizing automation and efficiency.

Canada Unlimited PTO

  • Manage multi-jurisdictional compliance execution including HIPAA, GDPR, PIPEDA, and emerging privacy laws.
  • Lead IT operations and service delivery including user onboarding, device management, and identity & access management.
  • Drive vendor risk management and BAA/DPA lifecycle, ensuring breach notification timelines and data deletion commitments.

Practice Better is an all-in-one platform helping health and wellness practitioners run their businesses and scale their impact. We are a remote-first team headquartered in Toronto, made up of curious, driven, and empathetic people, trusted by thousands of practitioners worldwide.

Europe 5w PTO

  • Own the complete internal audit lifecycle, from initial kickoff through final reporting.
  • Review and assess customer evidence against ISO 27001 controls.
  • Conduct customer discussions to explain audit findings and provide recommendations.

The company provides security compliance services, helping organizations achieve and maintain industry-leading standards. It operates as a remote-first environment where ownership, expertise, and clear communication are highly valued.

$132,000–$165,000/yr
US Unlimited PTO

  • Manage and support compliance certifications including SOC 2, HITRUST, and ISO 27001 audits across the audit lifecycle.
  • Serve as the subject matter expert across the company on compliance frameworks and primary point of contact for external auditors.
  • Maintain the risk register, drive risk identification and reporting, and scale GRC function with AI and automation.

Garner transforms the healthcare economy by partnering with employers to redesign healthcare benefits using data-driven insights. It is a fast-growing healthcare technology company with a mission-driven team focused on making healthcare more affordable and high-quality.

Europe 5w PTO

  • Own internal audits end to end for customers, from kickoff to final report.
  • Review evidence against ISO 27001 controls and identify non-conformities.
  • Write clear findings for non-technical founders and keep multiple audits on schedule.

Secfix automates security compliance for companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 certification. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised $12M Series A, and are backed by top VCs.

US

  • Develop and maintain the enterprise IT GRC strategy, framework, and roadmap, presenting updates to executive leadership.
  • Lead enterprise IT risk assessments, maintain risk registers, and oversee remediation efforts.
  • Ensure compliance with regulations like NIST, ISO 27001, SOC, PCI-DSS, HIPAA, GDPR, and SOX.

Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, the company supports data centers, healthcare, and industrial facilities where uptime is non-negotiable.

Global

  • Manage the Compliance and Security workstream within a telecom transformation program, coordinating SOC 2, ISO/IEC 27001, and GDPR readiness activities.
  • Build and maintain the workstream plan with milestones, deliverables, and RAID logs, while driving evidence collection and control-owner alignment.
  • Facilitate workshops, track remediation across multiple domains, and ensure alignment with adjacent program streams and governance forums.

Miratech helps visionaries change the world as a global IT services and consulting company supporting digital transformation for large enterprises. With nearly 1000 professionals operating across 25+ countries and a 99% project success rate, their culture emphasizes relentless performance and growth.

India

  • Manage and conduct internal and external compliance audits for frameworks like ISO, SOC, and NIST.
  • Work with global teams to implement and update compliance controls, policies, and training.
  • Stay updated on regulatory changes and perform gap analysis to maintain certifications.

QAD is building a world-class SaaS company that solves real-world problems in manufacturing and supply chain. They are a growing, virtual-first company with a collaborative culture that values idea-sharing and growth.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

$210,000–$350,000/yr
US

  • Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
  • Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
  • Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.

Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.

$27,000–$29,700/yr
Mexico

  • Operate as a trusted advisor to executive teams, guiding them through complex cybersecurity challenges and building security programs.
  • Develop enterprise security strategies, roadmaps, and governance frameworks, translating technical risks into business impact.
  • Lead risk assessments, incident response planning, and compliance initiatives aligned with NIST, CIS, and ISO frameworks.

DYOPATH simplifies technology for clients while investing deeply in its people. Recognized as a Great Place to Work for five consecutive years, the company prides itself on building exceptional teams to deliver secure solutions.

$107,950–$133,350/yr
UK

  • Lead data protection oversight and provide practical advice across the bank.
  • Manage DPIAs, data breaches, and regulatory engagement with the ICO.
  • Drive projects to build scalable processes for the Global DPO Office.

Monzo is a digital bank on a mission to make money work for everyone, offering personal and business bank accounts and financial products. They have a growing global team with a culture focused on innovation and customer-centric solutions.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$220,000–$245,000/yr
US 4w PTO

  • Own internal IT, security, and compliance strategy across the organization.
  • Lead the migration from MSP to an in-house IT function and manage a SecOps team.
  • Drive enterprise incident response, business continuity, and disaster recovery planning.

Karbon is the global leader in AI-powered practice management software for accounting firms. The company is well-funded, ranked #1 on G2, and has a people-first culture recognized with Great Place To Work certification and on Fortune's Best Small Workplaces list.

$198,238–$233,221/yr
US

  • Own and manage the compliance program including SOC 2 and ISO 27001 readiness and audits.
  • Lead risk assessments, control testing, and enterprise risk management processes.
  • Partner with Engineering, Security, Product, Legal, HR, and Operations to embed compliance into business processes.

Calendly is a scheduling platform used by millions to automate meetings and streamline time management. They are a rapidly growing SaaS company fostering a culture of learning and high performance.