About The Position

As an Information Security Manager (m/f/d), you will be responsible for driving information security and ICT risk management. You will own the ISMS under ISO 27001 and hold the ICT Risk Management Function under DORA, covering risk assessment, ICT incident classification, and third-party risk oversight. This role involves close collaboration with Engineering and Platform teams to integrate security into development processes and serves as the central point of contact for audits. The position reports directly to the Management Board and works closely with the Chief Legal Officer. We are seeking individuals who take ownership and are eager to grow with the company, rather than administrators.

Requirements

  • A degree in information security, computer science, law/compliance or a comparable qualification, plus relevant professional experience in information security and ICT risk management
  • Solid hands-on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities
  • Experience working directly with software engineering, product or DevOps teams in a technology-led environment
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is explicitly welcome
  • A strong hands-on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment
  • Confident communication in German and English, with both technical and non-technical audiences

Responsibilities

  • Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments – including preparing and steering certification and surveillance audits.
  • Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Initiate penetration tests, run security incident response from triage through post-incident review, and strengthen security awareness across the company through training and workshops.

Benefits

  • Direct reporting lines to C-level
  • A modern, hybrid working model across our Berlin and Munich locations
  • A personal budget for development
  • Semi-annual feedback
  • Clear growth paths
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service