Logo fiskaly GmbH

Information Security & Compliance Manager

New

Job

  • Level
    Senior
  • Job Field
    IT, DevOps, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Location
    Vienna
  • Working Model
    Hybrid, Onsite
  • Job Summary

    In this role, you take ownership of the ISMS, close open nonconformities, conduct internal audits, and lead the company through its ISO 27001 re-certification scheduled for 2027.

    Job Technologies

    Your role in the team

    • fiskaly is certified to ISO 27001, and our re-certification audit is scheduled for early 2027. We're looking for an Information Security & Compliance Manager to take end-to-end ownership of our ISMS: close the open nonconformities from our last audit, mature the management system, and lead us through re-certification - then keep raising the bar as we scale across seven European markets.
    • This is an ownership role, not a coordination role. You set the direction - what needs to happen, in which order and why - and you deliver a good part of it yourself: improving processes, running internal audits, preparing evidence and sitting in the room with the auditors. Towards our management team you are the independent expert voice on security and compliance; towards Engineering, Product and Legal you are the hands-on partner who makes controls work in a cloud-native SaaS environment.
    • Beyond ISO 27001, you'll look after our ISO 9001 quality management system and our GDPR framework, and keep us ahead of NIS2 and the AI Act.
    • Own our ISMS end-to-end - scope, policies, controls, risk register, management review and continuous improvement - and be accountable for its effectiveness, not just its documentation.
    • Leiten Sie unsere Rezertifizierung Anfang 2027: Bewerten Sie den aktuellen Stand (vorherige Erkenntnisse, bestehende Richtlinien und Prozesse, Lücken), schließen Sie die offenen Nichtkonformitäten, planen und führen Sie interne Audits durch, bereiten Sie die Managementbewertung und die Nachweise vor, koordinieren Sie mit der Zertifizierungsstelle und seien Sie während des Audits präsent.
    • Define and build ISMS processes tailored to fiskaly - business continuity, change management, incident and vulnerability management, supplier management - designed for how a cloud-native engineering team actually works, not copied from a template.
    • Run the company-wide risk management programme, translating abstract risks into prioritised, actionable engineering and business tasks, and explaining business risk vs. technical risk to leadership.
    • Sei die unabhängige Expertenstimme gegenüber dem Management: Berichte über den Stand der Sicherheit und Compliance, erkläre, wofür unsere Prozesse dienen, und gib konkrete Anweisungen, was verbessert werden soll und in welcher Reihenfolge.
    • Partner with Engineering and Product to embed security-by-design into the SDLC, CI/CD and infrastructure-as-code, and move evidence collection from manual gathering to automated, continuous monitoring wherever possible.
    • Support Legal and Sales on customer due diligence: security questionnaires, contract security reviews and enterprise customer audits.
    • Überwachen Sie das Risikomanagement von Anbietern mit leichten, skalierbaren Bewertungen, die Drittanbieter-Risiken aufdecken, ohne den Beschaffungsprozess zu verzögern.
    • Maintain our ISO 9001 QMS and GDPR framework, monitor the regulatory landscape (NIS2, AI Act) and translate it into practical roadmaps for leadership.
    • Foster a security-aware culture beyond mandatory training - position compliance as a business enabler, not a blocker.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • You have owned at least one ISO 27001 certification, surveillance or re-certification audit end-to-end - from gap assessment and closing nonconformities to sitting across from the auditor.
    • Deep knowledge of ISO 27001 (2022) and its controls; working knowledge of ISO 9001 and GDPR; able to navigate NIS2 without hand-holding.
    • Genuine fluency in SaaS and cloud environments: you understand GCP and/or Azure, CI/CD, infrastructure-as-code and modern change management well enough to audit them and to talk to engineers as a peer.
    • A solid understanding of secure SDLC - what good looks like and where the evidence lives.
    • Strong risk management foundations (ISO 31000, COSO or comparable) and the ability to present risk to C-level stakeholders in business terms.
    • A hands-on, delivery mindset: you define what needs to be done, then do it, scaling your effort to the deadline.
    • Excellent communication and presentation skills in English (C1); German is a plus.
    • Based in Vienna or willing to relocate, with regular on-site presence and full presence during audits.

    Experience

    • 5+ years in Information Security, Compliance or Risk Management, with a track record of building or maturing an ISMS.
    • Relevant certifications (ISO 27001 Lead Implementer / Lead Auditor, CISM, CISSP, CISA) and experience with modern GRC platforms (e.g. Vanta, Drata) are strong pluses.

    This text has been machine translated. Show original

    What we offer

    • A real ownership mandate: you'll be the person who takes fiskaly through re-certification and shapes how security, quality and compliance work at scale.
    • A highly collaborative and international team that values trust, growth, and transparency.
    • Wettbewerbsfähiges Gehalt und Leistungspaket.
    • Hybrid setup with a modern office in Vienna, modern tools, and a strong culture of autonomy.
    • Zeit und Budget für kontinuierliches Lernen und Zertifizierungen.

    This text has been machine translated. Show original

    Benefits

    Work-Life-Integration

    Food & Drink

    Higher Take-Home Pay

    Health, Fitness & Fun

    Topics You Will Work On

    Job Locations

    • Location Vienna

      Austria

    About Your Employer

    fiskaly GmbH

    fiskaly GmbH

    Wien

    At Fiskaly, we're the leading provider of cloud-based fiscalization solutions in Germany. Our mission is to make the world a safe and fair place by enabling trusted records. We provide a reliable and robust digital signature service that ensures the legitimacy of your receipts, while keeping our solution simple and convenient.

    Description

  • Company Size
    50-249 Employees
  • Founding Year
    2019
  • Language
    German, English
  • Company Type
    Startup
  • Working Model
    Hybrid, Onsite
  • Industry
    Internet, IT, Telecommunication
  • Employer reviews

    by devworkplaces.com

    Total

    (2 Reviews)
    3.5
    • Culture

      3.2
    • Workingconditions

      4.4
    • Career Growth

      4.0
    • Engineering

      2.7
    Show all reviews
    Logo fiskaly GmbH

    Information Security & Compliance Manager

    Location
    Vienna
    Working Model
    Hybrid, Onsite
    Diversity
    Open for all genders

    More Jobs