EnglishWillDo

Lead, IT Operations, Cyber Security and Compliance - All Genders

Doodle · Berlin-Kreuzberg, Germany

No German requiredPosted 5 days ago
Apply for this job

You apply on the site where the job is posted. I never handle applications.

Lead, IT Operations, Cyber Security and Compliance

Own the Trust Foundation Behind Every Doodle Product

Doodle is a B2B SaaS platform used by millions of professionals to coordinate meetings and collaboration. As we grow, trust has become one of our most valuable products. Every enterprise deal, every AI feature, every new hire depends on a secure, compliant, well run IT foundation.

You are more than an IT and Security lead. You own the governance, compliance, and operational backbone that lets Doodle move fast without breaking trust. Working closely with the CEO, CFO, PeopleOps, and external partners, you will run our security stack, our compliance programmes, and our AI governance framework, and you will lead the IT team that keeps Doodle running day to day.

What You Will Do

As Lead, IT Operations, Cyber Security and Compliance, you will own security, compliance, and IT operations across Doodle.

AI Governance

  • Design and own Doodle's AI governance framework.
  • Cover agentic AI security controls, EU AI Act assessment, and MCP and Cursor risk management for external contributors.
  • Build out policy, the risk register, and technical enforcement through our SSE platform, currently evaluating Netskope.

Board & Leadership

  • Author board level cybersecurity posture presentations using the NIST CSF 2.0 framework.
  • Translate technical risk into business language for the CEO and CFO.

Compliance Programmes

  • Own and drive SOC 2 Type II, HIPAA, ISO 27001, and ISO 42001 programmes at the same time.
  • Serve as Privacy Officer, managing GDPR and Swiss FADP obligations, the DPA portfolio, and the external DPO relationship.

Security Stack

  • Operate and evolve Doodle's full security toolset: SentinelOne and CrowdStrike for EDR, Jamf Pro for MDM, Okta and JumpCloud for IAM and SSO, Proofpoint PPS for email security (extending to Slack), and KnowBe4 for security awareness.
  • Led the EDR migration from CyberReason.
  • Operate Netskope as our CASB and SSE layer.

Vendor & Risk

  • Run a structured vendor due diligence programme: SOC 2 reviews, security questionnaires, code of conduct sign offs.
  • Support enterprise customers across government, energy, and healthcare.
  • Maintain a live risk register in Linear across 10+ active items.

IT Operations

  • Lead a lean IT team supporting 100+ headcount across Berlin, remote EU, and our contractor base.
  • Own the full lifecycle: onboarding and offboarding, access provisioning through Okta, a SaaS portfolio of around 30 tools, device management, and the service desk.
  • Maintain a compliance audit trail for SOC 2 throughout.

Process & Tooling

  • Built and automated a joint IT and PeopleOps onboarding workflow, from email to Linear ticketing with an NDA hard gate, cutting ad hoc access requests and strengthening contractor governance.
  • Evaluated and drove CLM tooling selection between Juro and Ironclad to enable self serve enterprise contract acceptance.

Our Ideal Candidate

We are looking for a leader who combines deep security and compliance expertise with the operational instincts to run IT for a fast moving SaaS business.

Security & Compliance Expertise

  • Proven experience owning multi framework compliance programmes such as SOC 2, ISO 27001, ISO 42001, or HIPAA.
  • Experience serving as a Privacy Officer or managing GDPR/FADP obligations directly.
  • Strong understanding of EDR, MDM, IAM/SSO, and CASB/SSE tooling in a live production environment.

Governance & Risk

  • Experience building AI governance frameworks, including emerging regulation such as the EU AI Act.
  • Comfortable running a live risk register and structured vendor due diligence process.
  • Able to assess and manage risk from external contributors and third party tools.

IT Operations Leadership

  • Experience leading a lean IT team supporting 100+ employees across multiple locations.
  • Hands on with the full employee lifecycle: onboarding, offboarding, access provisioning, device management, and service desk.
  • Comfortable owning a SaaS portfolio and driving tooling decisions such as CLM platform selection.

Communication & Stakeholder Management

  • Able to translate technical risk into business language for CEO and CFO audiences.
  • Comfortable presenting security posture at board level.
  • Strong cross functional partner to PeopleOps, Legal, and external DPO relationships.

Nice to Have

  • Experience supporting enterprise customers in regulated verticals such as government, energy, or healthcare.
  • Experience with Netskope or similar SSE platforms.
  • Experience automating IT workflows using tools such as Linear.
  • Background in a high growth B2B SaaS environment.

Hiring Journey

  • Initial Application Review + BRYQ Assessment
  • Hiring Manager Interview
  • Technical Assessment
  • Cross Functional Technical Interview
  • Executive Interview + HR Interview

So, Get in Touch!

At Doodle, we are committed to providing an environment of mutual trust and respect, where equal employment opportunities are available to all applicants and teammates without regard to age, race, color, disability, religion, gender, or sexual orientation. Diversity and inclusion are important to us because the best products are built by teams with different experiences, perspectives, and backgrounds.

IMPORTANT NOTICE: Please note that we can only consider your application if you are based and have the right to work in Germany. At this time, we are unable to sponsor visas for this position or support relocation.