🇩🇪 Berlin, Germany · 18h ago

IT Security & Compliance Lead

VIA HealthTech

LinkedInleadEnglish-friendly
VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.TasksWe are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA.This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build.Your goal is to make VIA more secure while helping the team move faster, not slower.You own IT security and compliance end-to-end. In practice, that means:Cloud security, hands-on: IAM, network, encryption, logging, monitoring, detectionProduct security together with engineering: web, desktop, mobile, backend, AI systemsDevSecOps: embedding security into the development lifecycle, threat modeling, vulnerability managementCompliance end-to-end: ISO27001 and, most importantly, C5 — audits, evidence, risk management, corrective actions, auditor communication, internal trainingCoordinating external security work: penetration tests, security reviews, vendor assessmentsInternal IT security: you own design and baseline — identity, MDM, device policies, access model, on-/offboardingRequirementsRequired:You have built and hardened cloud security yourself (eg. AWS, GCP) — IAM, network, encryption, logging, detection — and you work in infrastructure-as-code: you change Terraform yourself, you don't file tickets for itDevSecOps and application security: secure SDLC, threat modeling, vulnerability managementYou have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.You work directly with engineers on technical security topics and can push back on architecturePragmatic judgment and strong operational ownership in a small, async-first teamNice to have:Healthcare, or another environment handling highly sensitive dataExperience setting up security in an early-stage or fast-growing companyWhat matters beyond the checklistWhere this role can growCloud infrastructure: taking on more platform ownership alongside securityAI security: building this from scratch — agent permissions, tool access boundaries, data flows to model providers, threat modeling for LLM systems in a clinical context. Very few people have done this yet.Medical Device Regulation: as our product evolves, MDR becomes relevant. The natural entry point is the cybersecurity and software lifecycle side (Annex I 17.2, IEC 62304), which overlaps directly with the security work you'd already own.What matters beyond the checklistISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. You will move between cloud security architecture, product reviews, audit evidence, and access policies, sometimes in the same week. We are not looking for someone who only writes policies, but for someone who builds and operates the security foundation VIA needs as it scales.BenefitsOffice in Berlin Mitte, flexible hoursDirect access to founders, CTO, and the full multidisciplinary teamBroad ownership over a core company functionEquity participationNo micromanagement — results over hours loggedWork at the intersection of AI, healthcare, software, and security

Sourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.