VIA HealthTech

IT Security & Compliance Manager (Part-Time)

Berlin, Germany full-time Mid Salary not listed
full-time Mid level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Aufgaben

We are looking for a hands-on IT Security & Compliance Manager to own our IT Compliance, ISMS, and our IT security setup end-to-end.

This is a broad role in a small team. You will not only maintain policies but also implement systems, configure tools, run audits, and work directly with engineering to make security a practical part of how we build.

In practice, that means:

Compliance end-to-end: ISO27001 and, most importantly, C5: Audits, evidence, risk management, corrective actions, auditor communication, internal training

Controls: deciding what a control should be, building it, and verifying that it works

Vanta: keeping it current and accurate as we grow

Internal IT security: you own design and baseline like identity, MDM, device policies, endpoint hardening, access model, on-/offboarding

SaaS security administration: configuration, permissions, access reviews across our tool landscape

Coordinating external security work: penetration tests, security reviews, vendor and subprocessor assessments

Security documentation auditors and customers rely on: TOMs, VVT, AVVs with vendors

Qualifikation

Required:

You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.

You have owned internal IT security hands-on — identity, MDM, endpoint baselines, SaaS administration, access model — and you configure systems yourself

You work directly with engineers on technical security topics and can judge whether a control is effective in a cloud-native, infrastructure-as-code environment

Pragmatic judgment and strong operational ownership in a small, async-first team

German at working level and fluent English — auditors and clinical customers are in German, our team works in English

Nice to have:

Healthcare, or another environment handling highly sensitive data

Experience setting up IT and security in an early-stage or fast-growing company

German data protection practice: AVV, VVT, TOM, DPIA. We have an external Datenschutzbeauftragter for the legal depth, so this is useful but not required.

What matters beyond the checklist:

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.

We are not looking for someone who only writes policies, but for someone who builds and operates the security and compliance foundation VIA needs as it scales.

The role is part-time given the small team size, but workloads may vary (eg. increased when building certain security features or during the audit periods).

Benefits

Office in Berlin Mitte, flexible hours

Direct access to founders, CTO, and the full multidisciplinary team

Broad ownership over a core company function

Equity participation

No micromanagement — results over hours logged

Work at the intersection of AI, healthcare, software, and security

Find Jobs in Germany on Arbeitnow

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT Administration Writing Security Compliance Manager Mid level

Likely questions

  1. Tell us about work you have done that is close to the IT Security & Compliance Manager (Part-Time) role.
  2. How would you approach your first 30 days at VIA HealthTech?
  3. Which of Administration, Writing and Security have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Administration, Writing and Security.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the IT Security & Compliance Manager (Part-Time) role because I can bring practical experience in Administration, Writing and Security, learn the team quickly, and contribute to the outcomes VIA HealthTech needs from this hire.

Related jobs.

More roles from this company or category.