--- title: 'ISO 27001 Internal Auditor at Secfix' canonical: 'https://feeny.ai/job/iso-27001-internal-auditor-secfix-europe-z079c8ge8wgz' type: 'job' last_seen: '2026-09-04' --- # ISO 27001 Internal Auditor at Secfix - **Company:** Secfix - **Location:** Europe - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-07-22 - **Last confirmed live:** 2026-09-04 - **Apply:** https://jobs.ashbyhq.com/secfix/c7dd08e6-3ea6-48e9-b155-b62f111ac051 ## Job description Remote (+/- 2hrs from Germany GMT+1). C2 or C1 English is essential At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work. Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader. We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital. ## About the Role We're hiring an ISO 27001 Internal Auditor to own our internal audits end to end. You stay independent from the implementation work. You audit what a customer has built, review their evidence on the Secfix platform, and give them a clear report before their external audit. You assess, you find what is missing, and you tell them in plain language exactly what to do about it. This is a hands-on individual contributor role with full ownership of a function customers trust us with. What You'll Do: You will own internal audits to make our customers ready for their certification. We give you full context and best practices, and you own how you deliver the results. You will: - Own internal audits for our customers end to end, from kickoff through to the final report they take into their external audit - Review and sample evidence on the Secfix platform and assess it against the relevant ISO 27001 controls - Run the customer calls and walk customers through your findings and any non-conformities - Catch the non-conformities that matter, including the easy ones, so nothing avoidable surfaces later in an external audit - Write findings a non-technical founder can act on: what is missing, why it matters, and what to do next - Keep several audits moving at once and keep every one on schedule - Stay neutral to the implementation and hold a clean line between auditing and helping - Learn our other frameworks (TISAX, ISO 42001) and help build a repeatable audit structure for them - Help improve framework content on the platform, including evidence examples and guidance - Share structured product feedback when you spot recurring issues in the platform About You: - 2 - 3 years of information security experience - Hands-on ISO 27001 internal audit experience, with at least 10+ internal audits you have personally run - A PECB ISO 27001 Lead Auditor certification or a direct equivalent - Direct experience auditing inside a modern GRC platform - Clear, concrete written and spoken English, with the ability to explain complex requirements simply - Bachelor‘s Degree in Computer Science, Information Technology, Software Engineering or related field Nice-to-have: - Experience auditing or implementing TISAX, ISO 42001, NIS2 or SOC 2 - Experience at an early-stage startup (Seed to Series B) - Exposure to a modern SaaS product and cross-functional work with product teams ## What we offer - Remote Work: 100% remote work with a virtual office in Gather. - Competitive Salary: Industry-competitive local salaries.We pay local rates that are at or above the market. We share this philosophy with GitLab. - Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success. - Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors. - Development Budget: €1,000 annual personal development budget. - Home office Budget: Home office budget and access to co-working spaces. - Holidays: 26 days holiday + local public holidays. - Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Alicante!). - Company Events: Company-wide events to build relationships and have some fun! - Tech Equipment: Latest tech equipment (MacBook, monitors, headphones). Interview Process: - 45 min - Intro call with Talent team - Take-home Assessment - 1.5hr Assessment review and interview with Compliance Team - 45 min - Final Founder Interview with CTO Please note: We are an equal-opportunity employer and a remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here https://www.notion.so/Remote-Culture-93bf571583904c5e814b7afd83c240f2?pvs=21. ## About Secfix ## Company Overview - **One-liner**: Secfix is Europe’s end-to-end security compliance platform that automates certifications (ISO 27001, SOC 2, NIS2, TISAX, GDPR) for SMBs and mid-market companies. - **Entity Type**: Private (Series A) - **Headquarters**: Munich, Germany (Salvatorplatz 3, 80333) - **Founded**: 2021 - **Founders**: Grigory Emelianov (CEO), Branko Džakula (CTO), Fabiola Munguia (CISO) ## Core Business - **Primary Industry**: Security compliance automation / IT services and consulting - **Target Customers**: B2B – SMB and mid-market companies across Europe, including regulated industries (finance, energy, automotive) - **Mission**: “On a mission to help companies build trust & accelerate growth” by making certifications fast, transparent, and repeatable. ## Products & Services - **Compliance Automation Platform** (SaaS): Automates evidence collection, policy management, risk assessments, and audit preparation for frameworks like ISO 27001, SOC 2, NIS2, DORA, TISAX, GDPR, ISO 42001, ISO 27701, ISO 9001, and ISO 27018. - **CISO-as-a-Service** (Service): Provides dedicated security expertise, continuous monitoring, incident management, and penetration testing. - **Risk Management** (SaaS feature): Automated risk assessments linked to pre-mapped controls, with guided questionnaires. - **Policy Management** (SaaS feature): 20+ customizable, audit-ready policy templates with acceptance tracking. - **Employee Compliance** (SaaS feature): Automated onboarding/offboarding, task reminders, and security training tracking. - **Vendor Management** (SaaS feature): Automatic vendor discovery via SSO, risk tracking, and assessment management. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total funding ~$15.8 M – $16.5 M (conflicting reports) with a $12 M Series A raised in February 2026 (led by Alstin Capital) - **Notable Investors**: Octopus Ventures (led Seed round), Alstin Capital (led Series A), other angel investors - **Growth Signals**: - Employee headcount: 30 (34.6% YoY growth) - Operating across 10 countries (Germany, UK, India, Poland, Austria, Montenegro, etc.) - Audit success rate and CSAT score both at 100% (company claim) - 90% automation for most frameworks - Active job postings grew 433% YoY ## Competitive Advantages - **Deep Europe focus**: Designed specifically for EU regulations (GDPR, NIS2, DORA, TISAX) with German-built technology and European cloud infrastructure. - **Automation + expertise combo**: Replaces slow manual compliance with AI-driven workflows, plus real CISO advisory. - **All-in-one platform**: Covers the full compliance lifecycle – from risk assessment to audit preparation and continuous monitoring – unlike point solutions. - **Proven track record**: 100% audit success rate and hundreds of customers across 15+ European countries including banks, energy companies, and multinationals. ## Strategic Focus - Continue expanding compliance framework coverage (e.g., EU AI Act, ISO 42001). - Deepen automation capabilities to reduce manual effort further. - Scale customer base beyond SMBs into larger mid-market and regulated enterprises. - Grow remote team across Europe while maintaining a “remote-first, async-friendly” culture. ## Why Work Here - **Culture**: “Remote by design” – async workflows, flexible hours, and a distributed team across Munich, Berlin, London, and other European cities. - **Values**: Extreme ownership, customer obsession, fast & reliable, trust through clarity, build smart & lean. - **Engineering environment**: Modern SaaS stack, ex-Amazon and MAN technical leadership, focus on automation and security. - **Growth trajectory**: Fast-growing private startup (revenue ~$1.1 M annually, headcount up 34% YoY) with aggressive hiring (16 open roles). - **Perks**: Work with top-tier investors, hands-on compliance experts, and a diverse team of auditors, engineers, and CSMs. ## Sources 1. [secfix.com – About Us](https://www.secfix.com/about-us) 2. [secfix.com – Homepage](https://www.secfix.com/) 3. [secfix.com – Jobs](https://jobs.ashbyhq.com/secfix) 4. [cbinsights.com – Secfix Company Profile](https://www.cbinsights.com/company/secfix) 5. [linkedin.com – Secfix Company Page](https://www.linkedin.com/company/secfix/) ## Other roles at Secfix - [Account Executive - Mid-Market (German-speaking)](https://feeny.ai/job/account-executive-mid-market-german-speaking-secfix-munich-7108a7573tzj) — Munich, Germany - [Business Development Representative - SMB (German-speaking)](https://feeny.ai/job/business-development-representative-smb-german-speaking-secfix-munich-1b4xqm2q76vx) — Munich, Germany - [Business Development Representative - Mid-Market (German-speaking)](https://feeny.ai/job/business-development-representative-mid-market-german-speaking-secfix-munich-zw7yj252hmxd) — Munich, Germany - [Account Executive - SMB (German-speaking)](https://feeny.ai/job/account-executive-smb-german-speaking-secfix-munich-pq0p1erp3y4j) — Munich, Germany - [Information Security Lead](https://feeny.ai/job/information-security-lead-secfix-europe-vx7b8n75c7ne) — Europe - [Product Support Specialist](https://feeny.ai/job/product-support-specialist-secfix-germany-austria-poland-united-kingdom-turkey-myz44jfd7mkm) — Germany / Austria / Poland / United Kingdom / Turkey - [Senior Product Designer](https://feeny.ai/job/senior-product-designer-secfix-europe-kwtwaq3pj9g2) — Europe - [ISO 27001 Internal Auditor (German-speaking)](https://feeny.ai/job/iso-27001-internal-auditor-german-speaking-secfix-europe-mwydygebye9x) — Europe - [Product Support Specialist (German-speaking)](https://feeny.ai/job/product-support-specialist-german-speaking-secfix-germany-austria-poland-united-ys9j4ypexp1g) — Germany / Austria / Poland / United Kingdom / Turkey - [Customer Success Manager, Mid-Market (German-speaking)](https://feeny.ai/job/customer-success-manager-mid-market-german-speaking-secfix-germany-austria-ec7vk8x8tzd0) — Germany / Austria / Poland / United Kingdom / Turkey