VIA HealthTech
VIA HealthTech

IT Security & Compliance Lead

Berlin, Germany (hybrid)
Employee
IT Security

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Tasks

We are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA.

This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build.

Your goal is to make VIA more secure while helping the team move faster, not slower.

You own IT security and compliance end-to-end. In practice, that means:

  • Cloud security, hands-on: IAM, network, encryption, logging, monitoring, detection
  • Product security together with engineering: web, desktop, mobile, backend, AI systems
  • DevSecOps: embedding security into the development lifecycle, threat modeling, vulnerability management
  • Compliance end-to-end: ISO27001 and, most importantly, C5 — audits, evidence, risk management, corrective actions, auditor communication, internal training
  • Coordinating external security work: penetration tests, security reviews, vendor assessments
  • Internal IT security: you own design and baseline — identity, MDM, device policies, access model, on-/offboarding

Requirements

Required:

  • You have built and hardened cloud security yourself (eg. AWS, GCP) — IAM, network, encryption, logging, detection — and you work in infrastructure-as-code: you change Terraform yourself, you don't file tickets for it
  • DevSecOps and application security: secure SDLC, threat modeling, vulnerability management
  • You have carried an ISO27001 certification or C5 attestation end-to-end at least once, including audit ownership and auditor communication. C5 matters most to us, but ISO27001 or SOC 2 at that level transfers well. You can design and implement controls, not just document them.
  • You work directly with engineers on technical security topics and can push back on architecture
  • Pragmatic judgment and strong operational ownership in a small, async-first team

Nice to have:

  • Healthcare, or another environment handling highly sensitive data
  • Experience setting up security in an early-stage or fast-growing companyWhat matters beyond the checklist

Where this role can grow

  • Cloud infrastructure: taking on more platform ownership alongside security
  • AI security: building this from scratch — agent permissions, tool access boundaries, data flows to model providers, threat modeling for LLM systems in a clinical context. Very few people have done this yet.
  • Medical Device Regulation: as our product evolves, MDR becomes relevant. The natural entry point is the cybersecurity and software lifecycle side (Annex I 17.2, IEC 62304), which overlaps directly with the security work you'd already own.

What matters beyond the checklist

ISO27001 and C5 are in place and yours to own. That means maintaining them, keeping Vanta current, and updating controls and policies as we grow. What we don't need is someone to collect evidence. We need someone who decides what a control should actually be, builds it, and can tell whether it works.

We are a 10-person startup. This role needs breadth, ownership, and hands-on execution. You will move between cloud security architecture, product reviews, audit evidence, and access policies, sometimes in the same week. We are not looking for someone who only writes policies, but for someone who builds and operates the security foundation VIA needs as it scales.

Benefits

  • Office in Berlin Mitte, flexible hours
  • Direct access to founders, CTO, and the full multidisciplinary team
  • Broad ownership over a core company function
  • Equity participation
  • No micromanagement — results over hours logged
  • Work at the intersection of AI, healthcare, software, and security
Updated: 17 hours ago
Job ID: 16519530
Report issue

VIA HealthTech

1-10 employees
Software Development
  1. IT Security & Compliance Lead