VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients. We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification. We are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA. This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build. Your goal is to make VIA more secure while helping the team move faster, not slower. You own IT security and compliance end-to-end. In practice, that means: Cloud security, hands-on: IAM, network, encryption, logging, monitoring, detection Product security together with engineering: web, desktop, mobile, backend, AI systems DevSecOps: embedding security into the development lifecycle, threat modeling, vulnerability management Compliance end-to-end: ISO27001 and, most importantly, C5 — audits, evidence, risk management, corrective actions, auditor communication, internal training Coordinating external security work: penetration tests, security reviews, vendor assessments Internal IT security: you own design and baseline — identity, MDM, device policies, access model, on-/offboarding Required: You have built and hardened cloud security yourself (eg. AWS, GCP) — IAM, network, encryption, logging, detection — and you work in infrastructure-as-code: you change Terraform yourself, you don't file tickets for it DevSecOps and application security: secure SDLC, threat modeling, vulnerability management You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them. You work directly with engineers on technical security topics and can push back on architecture Pragmatic judgment and strong operational ownership in a small, async-first team Nice to have: Healthcare, or another environment handling highly sensitive data Experience setting up security in an early-stage or fast-growing company What matters beyond the checklist Where this role can grow Cloud infrastructure: taking on more platform ownership alongside security AI security: building this from scratch — agent permissions, tool access boundaries, data flows to model providers, threat modeling for LLM systems in a clinical context. Very few people have done this yet. Medical Device Regulation: as our product evolves, MDR becomes relevant. The natural entry point is the cybersecurity and software lifecycle side (Annex I 17.2, IEC 62304), which overlaps directly with the security work you'd already own. What matters beyond the checklist ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works. We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. You will move between cloud security architecture, product reviews, audit evidence, and access policies, sometimes in the same week. We are not looking for someone who only writes policies, but for someone who builds and operates the security foundation VIA needs as it scales. Office in Berlin Mitte, flexible hours Direct access to founders, CTO, and the full multidisciplinary team Broad ownership over a core company function Equity participation No micromanagement — results over hours logged Work at the intersection of AI, healthcare, software, and security
Lead Compliance
Damedic GmbH
Lead, IT Operations, Cyber Security and Compliance - All Genders
Doodle
EU Cybersecurity Governance, Risk and Compliance Lead (m/w/d)
Emerson
Head of / Lead Product Compliance & Quality (all genders)
Careersportal
Lead Security Compliance Analyst, (f/m/d)
Personio
COO (Chief Operating Officer) - Leading Compliance Service Provider
Schulz & Cie. Consulting GmbH