IT Security & Compliance Manager (Part-Time)
VIA HealthTech · Berlin
Skills in this posting
Extracted from the posting text by the instrument — the demand side, read literally.
The posting
VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.
We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.
Aufgaben
We are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end.
This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build.
In practice, that means
Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training
Controls: deciding what a control should be, building it, and verifying that it works
Vanta: keeping it current and accurate as we grow
Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding
SaaS security administration: configuration, permissions, access reviews across our tool landscape
Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments
Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors
Qualifikation
Required
You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.
You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself
You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment
Pragmatic judgment and strong operational ownership in a small, async-first team
German at working level and fluent English — auditors and clinical customers are in German, our team works in English
Nice to have
Healthcare, or another environment handling highly sensitive data
Experience setting up IT and security in an early-stage or fast-growing company
German data protection practice: AVV, VVT, TOM, DPIA. We have an external Datenschutzbeauftragter for the legal depth, so this is useful but not required.
What matters beyond the checklist
We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.
We are not looking for someone who only writes policies, but for someone who builds and operates the security and compliance foundation VIA needs as it scales.
The role is part-time given the small team size, but workloads may vary (eg. increased when building certain security features or during the audit periods).
Benefits
Office in Berlin Mitte, flexible hours
Direct access to founders, CTO, and the full multidisciplinary team
Broad ownership over a core company function
Equity participation
No micromanagement — results over hours logged
Work at the intersection of AI, healthcare, software, and security
Find more English Speaking Jobs in Germany on Arbeitnow
Excerpt from the original listing. The full, current text lives at the source. Read and apply there →
The PivotHop read
- What a compliance officer actually earnsmedian, seniority, by country
- Compliance Officer career changes, measuredevery measured route out
- Lawyer → Compliance Officer60% readiness
- All open compliance officer rolesthe full board
Where these skills also reach
Adjacent occupations measured from the same postings — readiness is what a compliance officer’s profile already covers.
- 130 open auditor roles31% readiness from compliance officer
- 39 open environmental engineer roles26% readiness from compliance officer
- 500 open lawyer roles23% readiness from compliance officer
- 13 open actuary roles22% readiness from compliance officer
More compliance officer roles
- Credit Risk Manager, Portfolio ManagementMonzo · UK
- Payment Specialist - Compliance AnalystCheckout.com · London
- Group Tax Compliance OfficerVP Bank AG · Vaduz, FL, Switzerland
- Governance, Risk & Compliance ManagerRUAG AG · Bern, Bern, Switzerland
- Risk AnalystPavago · Pakistan
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.