Skip to main content
All positions

Open position

Trust & Security Lead (m/f/d)

Full-time · LeadershipStuttgart / HybridImmediately

BRANE is our AI appliance for enterprises: it sits on the customer's premises and decides, for every AI request, which data stays local and what may go to the cloud. Our customers buy security — and expect us to prove it. That is why this role exists: one person who owns trust end-to-end, from certification and regulatory reporting processes to representing us in front of IT-security gatekeepers and analysts. You are not starting from scratch: a complete ISMS document set — Statement of Applicability, risk register, policies and operating procedures — exists in draft, and the technical controls are implemented and tested. Your job is to turn it into a living, certifiable management system and to be the voice customers and auditors trust.

You report directly to the leadership team and work closely with engineering: technical security sits with the development team — your field is governance, evidence and external credibility, with enough technical depth to hold your own with engineers and auditors.

Your tasks

  • Own the ISO program end-to-end: take ISO/IEC 27001 to certification, with ISO/IEC 42001 (AI management system) as the next stage — from approving the prepared document set through internal audits and management reviews to a passed certification audit
  • Assume the Information Security Officer (ISB) function: approve policies and the Statement of Applicability, steer the risk register and risk owners, represent the ISMS to the certification body
  • Translate EU regulation into living processes: EU AI Act, Cyber Resilience Act (including vulnerability-reporting processes and on-call arrangements) and NIS2 — you keep us verifiably compliant and on top of deadlines
  • Scope, procure and steer external penetration tests; prioritise findings and drive them into the engineering roadmap; provide credible test evidence for customers and partners
  • Own the compliance documents in the product and for customers: review, maintain and polish DPAs, TOMs, DPIA templates, the sub-processor list and further evidence
  • Build outward trust: security/trust page, vendor questionnaires, tender and assessment responses; lead security conversations with our customers' data-protection, compliance and IT-security stakeholders and with analysts
  • Technically vouch for every security and certification claim on the website, in contracts and in sales material — we never say “certified” before it is true, and you are the guardian of that rule

Not part of the role: sales, hands-on pentesting, and code or architecture security — that is what the engineering team is for. You are governance, evidence and external credibility.

What you bring

  • You have taken at least one company through ISO 27001 certification in an accountable role (as ISO, lead implementer or program owner) — ideally in a software or product environment
  • Solid knowledge of NIS2 and the EU AI Act; experience with the Cyber Resilience Act and ISO/IEC 42001 is a strong plus
  • Experience procuring and steering external penetration tests and handling findings in a structured way
  • Willingness to carry formal responsibility: the security-officer function, signatures on policies, representing us to auditors
  • Confident presence in German and English — in front of CISOs, data protection officers, auditors and analysts
  • Pragmatism: you build the lightest management system that passes an audit and is actually lived day to day — no paper compliance

What we offer

  • At BRANE, compliance is part of the product, not overhead — security is what we sell
  • Visible deal impact: certification and evidence co-decide whether enterprise deals pass the security review
  • A building mandate with a head start: you set up the trust function from scratch — on a fully prepared ISMS foundation instead of a blank page
  • Short paths to engineering, legal and the leadership team; direct collaboration with the founding team

Apply now

Apply for this role.

Three short steps, no cover letter. We will get back to you as soon as possible.

Step 1 of 3

About you

Who are you?