The opportunity
DeepL is a global AI product and research company focused on building secure, intelligent solutions to complex business problems. Over 200,000 business customers and millions of individuals across 228 global markets today trust DeepL's Language AI platform for human-like…
What you'll do
Own and continuously improve our Information Security Management System: (ISMS), keeping it aligned with ISO 27001, SOC 2 Type II, and, where relevant, HIPAA and BSI C5
Maintain and mature our risk register, policy library, vendor/third-party: risk assessments, and control monitoring
Act as a hands-on participant in audits, working directly with auditors,: control owners, and leadership to prepare, execute, and close out certification and attestation cycles efficiently rather than through brute force
Build and refine evidence collection processes using automation and GRC: tooling (e.g. Vanta or similar), reducing manual overhead and audit fatigue across the company
Design and roll out a model where product and engineering teams own their: evidence throughout the control lifecycle, rather than compliance chasing people down before every audit
Assess risk pragmatically: identify real security and compliance exposure, size it accurately, and make calculated calls that unblock product and engineering teams
What they're looking for
- Partner with engineering, product, IT, People, and Legal to embed security: and compliance requirements into existing workflows rather than bolting them on afterward
- Track regulatory and customer-driven compliance requirements: new customer security questionnaires, evolving frameworks — and translate them into practical, actionable controls
- Report on the state of the security and compliance program to stakeholders: and leadership, including audit readiness, open risks, and remediation progress
- years of experience in information security, GRC, or compliance roles,: ideally at a SaaS company, and ideally at scaleup pace and scale