← CarreiraAI
Indeed
Híbrido
Information Security Officer (f/m/d)
SPREAD GmbH · Berlin
Publicada em 07/10/2026
Candidatar-se com o CarreiraAI →
Short Description
SPREAD builds engineering intelligence for the world's most complex products. Our AI-native platform gives automotive OEMs, defense primes, and industrial manufacturers a single source of product truth so engineering teams can make confident product decisions, fast. We work with companies like Volkswagen, BMW, Mercedes, Bosch, and Rheinmetall. Backed by HV Capital, DTCP, La Famiglia, and Salesforce.
You'll own SPREAD's information security and compliance program, from ISO 27001, SOC 2, and TISAX audit cycles through to the risk register, policies, and vendor assessments that back them. You set the security requirements across the company and check that day-to-day operations meet them. You work closely with the GTM team on customer security questionnaires and with leadership on ISMS reporting each cycle, and you'll grow the scope of what you own as the program matures.
Your Mission
Own audit cycles end-to-end for ISO 27001, SOC 2, and TISAX, expanding scope as certifications mature.
Answer security questionnaires for customers and OEMs alongside the GTM team, turning fast and accurate answers into a real edge in deals.
Present ISMS status, risk posture, and audit results to leadership every cycle.
Maintain and evolve risk registers, security policies, and vendor security assessments as the company grows.
Run security awareness training and phishing simulations across the organization.
Set the security requirements for identity, device, and endpoint management, and audit that IT operations meet them.
Build and maintain the evidence base behind every control, closing gaps before an auditor finds them.
Automate repetitive compliance and evidence-collection work with platforms like Vanta.
Your Experience
3 to 5 years in information security, GRC, or compliance operations, with direct experience supporting a complete ISO 27001 or SOC 2 audit cycle.
Current or recent experience in a small, close-knit security or compliance function, not a large corpora
Candidatar-se com o CarreiraAI →