Information Security Lead (m/f/d)
This is a hybrid role sitting within our Infrastructure team. You'll own TeleClinic's information security strategy as our de facto CISO, while staying close enough to the engineering to make security real rather than documentary. You'll be the go-to person for all security-related topics, bridging engineering, operations, and leadership. Our ISO 27001 and ISO 9001 certifications are in place — your job is to keep them, extend them, and turn the ISMS into something the whole company actually uses. If you want your security work to have company-wide impact in a regulated healthcare environment, this role is for you.
What You'll Do
-
Own our ISO 27001 certification end to end — surveillance audits, re-certification, scope changes, and closing findings with our external auditor (our ISMS runs in Vanta).
-
Coordinate with our ISO 9001 programme so both audit cycles run as one, and help shape what we certify next (e.g. BSI C5).
-
Run and evolve the ISMS day to day: risk register, control ownership, evidence collection, and the internal audit programme.
-
Define and implement security policies, standards, and procedures across and with all teams.
-
Lead risk assessments, threat modelling, and vulnerability management.
-
Own third-party and vendor risk, from due diligence through to ongoing review.
-
Monitor the threat landscape and proactively address emerging risks relevant to a regulated healthcare environment.
-
Collaborate with product teams and infrastructure on architecture decisions with a security-first mindset.
-
Educate and upskill colleagues on security awareness and best practices.
-
Contribute hands-on to our Python/Django services where security work calls for it (tooling, automation, remediation).
What You Bring
-
Several years owning information security in a regulated or audited environment, including direct exposure to external auditors.
-
Hands-on experience with ISO 27001, ideally having led or significantly contributed to an implementation, re-certification, or surveillance cycle.
-
Solid understanding of network security, identity & access management, encryption, and secure SDLC.
-
Experience running third-party and vendor risk management.
-
Strong communicator who can translate complex security concepts to non-technical stakeholders.
-
Experience operating within an integrated management system (ISO 27001 alongside ISO 9001 or similar) is a strong plus.
-
Familiarity with healthcare data regulations (GDPR, potentially HIPAA, or German digital health regulations such as DiGA) is a strong plus.
-
Proven track record with cloud infrastructure (AWS, GCP, or Azure) and modern DevSecOps practices is a plus.
-
Python backend engineering experience is a plus.
-
Fluent in English; German is a plus.
Our salaries are determined based on objective and role-related criteria, aligned with the local market standards of your specific hiring country. Your dedicated recruiter will be happy to provide detailed information about the relevant salary bands prior to your first interview.
#LI-PS1
#LI-Remote