ISO 27001 Internal Auditor at Secfix | Torre

ISO 27001 Internal Auditor

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for Germany residents)
Shared by
Emma of Torre.ai
13 days ago

Responsibilities


Remote (+/- 2hrs from Germany GMT+1). C2 or C1 English is essentialAt Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work.Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader.We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.About the RoleWe're hiring an ISO 27001 Internal Auditor to own our internal audits end to end. You stay independent from the implementation work. You audit what a customer has built, review their evidence on the Secfix platform, and give them a clear report before their external audit. You assess, you find what is missing, and you tell them in plain language exactly what to do about it. This is a hands-on individual contributor role with full ownership of a function customers trust us with.What You'll Do:Own internal audits for our customers end to end, from kickoff through to the final report they take into their external auditReview and sample evidence on the Secfix platform and assess it against the relevant ISO 27001 controlsRun the customer calls and walk customers through your findings and any non-conformitiesCatch the non-conformities that matter, including the easy ones, so nothing avoidable surfaces later in an external auditWrite findings a non-technical founder can act on: what is missing, why it matters, and what to do nextKeep several audits moving at once and keep every one on scheduleStay neutral to the implementation and hold a clean line between auditing and helpingLearn our other frameworks (TISAX, ISO 42001) and help build a repeatable audit structure for themHelp improve framework content on the platform, including evidence examples and guidanceShare structured product feedback when you spot recurring issues in the platformAbout You:2 - 3 years of information security experienceHands-on ISO 27001 internal audit experience, with at least 10+ internal audits you have personally runA PECB ISO 27001 Lead Auditor certification or a direct equivalentDirect experience auditing inside a modern GRC platformClear, concrete written and spoken English, with the ability to explain complex requirements simplyBachelor‘s Degree in Computer Science, Information Technology, Software Engineering or related fieldNice-to-have:Experience auditing or implementing TISAX, ISO 42001, NIS2 or SOC 2Experience at an early-stage startup (Seed to Series B)Exposure to a modern SaaS product and cross-functional work with product teamsWhat we offerRemote Work: 100% remote work with a virtual office in Gather.Competitive Salary: Industry-competitive local salaries.We pay local rates that are at or above the market. We share this philosophy with GitLab.Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success.Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors.Development Budget: €1,000 annual personal development budget.Home office Budget: Home office budget and access to co-working spaces.Holidays: 26 days holiday + local public holidays.Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Alicante!).Company Events: Company-wide events to build relationships and have some fun!Tech Equipment: Latest tech equipment (MacBook, monitors, headphones).Interview Process:45 min - Intro call with Talent teamTake-home Assessment1.5hr Assessment review and interview with Compliance Team45 min - Final Founder Interview with CTOPlease note: We are an equal-opportunity employer and a remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here.