SPREAD builds engineering intelligence for the world's most complex products. Our AI-native platform gives automotive OEMs, defense primes, and industrial manufacturers a single source of product truth so engineering…
More details and full description
Skills mentioned
CRM software
Work eligibility
Add your citizenship to check
Germany · EU · Guidance only, not legal advice. Check official sources for your situation.
Full description
Short Description
SPREAD builds engineering intelligence for the world's most complex products. Our AI-native platform gives automotive OEMs, defense primes, and industrial manufacturers a single source of product truth so engineering teams can make confident product decisions, fast. We work with companies like Volkswagen, BMW, Mercedes, Bosch, and Rheinmetall. Backed by HV Capital, DTCP, La Famiglia, and Salesforce.
You'll own SPREAD's information security and compliance program, from ISO 27001, SOC 2, and TISAX audit cycles through to the risk register, policies, and vendor assessments that back them. You set the security requirements across the company and check that day-to-day operations meet them. You work closely with the GTM team on customer security questionnaires and with leadership on ISMS reporting each cycle, and you'll grow the scope of what you own as the program matures.
Your Mission
• Own audit cycles end-to-end for ISO 27001, SOC 2, and TISAX, expanding scope as certifications mature.
• Answer security questionnaires for customers and OEMs alongside the GTM team, turning fast and accurate answers into a real edge in deals.
• Present ISMS status, risk posture, and audit results to leadership every cycle.
• Maintain and evolve risk registers, security policies, and vendor security assessments as the company grows.
• Run security awareness training and phishing simulations across the organization.
• Set the security requirements for identity, device, and endpoint management, and audit that IT operations meet them.
• Build and maintain the evidence base behind every control, closing gaps before an auditor finds them.
• Automate repetitive compliance and evidence-collection work with platforms like Vanta.
Your Experience
• 3 to 5 years in information security, GRC, or compliance operations, with direct experience supporting a complete ISO 27001 or SOC 2 audit cycle.
• Current or recent experience in a small, close-knit security or compliance function, not a large corporate GRC team where your scope was narrowly defined.
• Working knowledge of identity, endpoint, and M365-style device management, strong enough to set requirements and judge whether IT operations meets them.
• Comfort owning a risk register, a policy set, and vendor security assessments end-to-end.
• Fluent German, and willingness/eligibility to undergo a German Ü2 security clearance (SÜG).
• Bonus: Direct exposure to TISAX or the automotive OEM security ecosystem.
• Bonus: Scripting or automation skills and the instinct to remove repetitive work.
• Bonus: Vanta or similar compliance platform experience.
Why SPREAD?
• You're joining a security program that's already protecting deals with some of the biggest names in automotive, with a clear path to owning it fully.
• High ownership and measurable impact. You connect your work directly to the success of the organization.
• A senior team that values craft, speed, and accountability over process and hierarchy.
• Strong overall package including attractive compensation, VSO and an annual learning budget.
• Mobility and wellbeing support through a Deutschlandticket mobility budget, bike-leasing and an Urban Sports partnership.
• Time off and flexibility with 30 vacation days, and one paid volunteering day per year.
Contact
Dmytro İefymenko
Köpenicker Str. 40c | 10179 Berlin
Stay connected—follow us on for the latest insights and updates
Find Jobs in Germany on Arbeitnow
Helsing ist ein Unternehmen für KI im Verteidigungsbereich. Unsere Mission ist es, unsere Demokratien zu schützen. Unser Ziel ist technologische Führungsfähigkeit, damit offene Gesellschaften auch in Zukunft souveräne…
Anerkannte Qualifikationen oder Zertifizierungen im Bereich Objektschutz, physische Sicherheit oder Krisenmanagement; · preferred
Berufserfahrung im Verteidigungs-, Nachrichtendienst-, Behörden- oder sicherheitskritischen Technologieumfeld; · preferred
Erfahrung mit modernen Gefahrenmelde-, Videoüberwachungs- und Alarmmanagementsystemen. · preferred
Unsere Arbeit hat Bedeutung. Bei Helsing leistest du einen direkten Beitrag zum Schutz demokratischer Staaten – in einem Umfeld, in dem ethische und geopolitische Fragen gleichermaßen eine wichtige Rolle spielen. · preferred
Helsing is a defence AI company. Our mission is to protect our democracies. We aim to achieve technological leadership, so that open societies can continue to make sovereign decisions and control their ethical standards.
Hold recognised certifications in physical security or crisis management · preferred
Possess prior experience working within the defence, intelligence, or secure technology sectors · preferred
Demonstrate familiarity with advanced hazard detection and alarm management software · preferred
Helsing’s work is important. You’ll be directly contributing to the protection of democratic countries while balancing both ethical and geopolitical concerns · preferred