RS
IT Security & Compliance Lead | HealthTech (w/m/d)
Right Search
Contract type
Ongoing
Work mode
Hybrid · Hybrid (inferred: EU/NL where applicable)
Experience
Senior · 5+ years
Job description
Key details
- Own security and compliance end-to-end across cloud, product, and internal IT
- Harden and operate AWS/GCP environments: IAM, networking, encryption, logging, monitoring, and detection
- Embed DevSecOps into the SDLC: threat modeling, vulnerability management, and secure code reviews
- Lead ISO 27001 and BSI-C5 certifications including audits, evidence, and risk management
- Coordinate pen tests, security reviews, and vendor assessments
- Define and maintain internal IT baselines: identity, MDM, device policies, and on/offboarding
- Provide pragmatic security guidance and push back on architecture decisions
- Company mission
- To develop AI-supported software that automates psychotherapeutic documentation, relieving therapists of administrative tasks and improving patient care
Primary stack
Core technologies
TerraformAWSGoogle Cloud Platform (GCP)
Benefits
- 4.5-day week with 28 days vacation
- Company car for private use
- JobRad leasing
- EGYM Wellpass
- Subsidized company pension
- Team events and an inclusive work environment
- Attractive salary up to €100k
- Virtual equity participation (VESOP)
Requirements & details
- At least 5 years of hands-on experience in cloud security (AWS or GCP) including Terraform
- Full audit ownership of ISO 27001 / BSI-C5 including successful certification
- Experience with DevSecOps, secure SDLC, threat modeling, and vulnerability management
- Fluent German and English (C1)
- Bachelor's degree or equivalent qualification
- Proven collaboration with engineering teams in small, async-first environments
- Not suitable for freelancers, job hoppers, policy-only backgrounds, or those without audit experience
- Willingness to work on-site in Berlin
- Terraform, AWS, GCP
- Terraform
- AWS
- Google Cloud Platform (GCP)
