Security & Compliance Engineer gGmbH/Non-Profit - (m/f/d)
The DO School Fellowships gGmbH
·Today
- Location
- Berlin, Berlin
- Type
- Full-time, Temporary
- Department
- Engineering
- Source
- Personio
Description
Your mission
The Security & Compliance Engineer owns the security, compliance, and integration of our tool ecosystem: CRM, community/LMS, data, and collaboration platforms. This is a hands-on technical role: you write scripts, work with APIs, and reason about system and security architecture to harden, connect, and automate the platforms we already run (HubSpot, Hivebrite, Notion, Looker Studio/Tableau, Slack, and others). You won't be building new consumer-facing or product software from scratch. The engineering is applied to keeping our existing technology ecosystem secure, compliant, integrated, and reliable as we grow.
Key Responsibilities
Security & Compliance Engineering: Design and implement secure configurations, access controls and SSO, secrets management, and data protection controls across our tool stack. Ensure compliance with data protection requirements (e.g. GDPR), own audit readiness, and lead vendor/security reviews for new tools.
AI Governance & Compliance: Oversee the secure and compliant use of AI tools (e.g. Claude, Gemini) across the organization, ensuring use cases align with the EU AI Act and internal data protection standards, classifying and documenting AI workflows, and advising teams on safe, approved use of AI in their day-to-day work.
Tool & Systems Integration: Build and maintain API-based integrations and automations between HubSpot, Notion, Hivebrite (or similar LMS/Community platforms), Looker Studio/Tableau, Slack, and other operational platforms, using scripting and automation tools (e.g. Python, Zapier/Make, native APIs).
Monitoring & Incident Response: Set up monitoring, logging, and alerting across systems; lead investigation and resolution of security and technical incidents, and drive down recurring risk.
Process Optimization & Automation: Identify manual, recurring workflows and replace them with automated, auditable solutions.
Cross-Team Collaboration & Documentation: Work closely with marketing, business development, and leadership to translate operational needs into secure technical solutions, and keep architecture, security, and compliance documentation up to date.
Your profile
Real engineering background: comfortable writing code/scripts (e.g. Python, JavaScript/TypeScript), working with REST APIs, and reasoning about system architecture, applied here to integration and security work rather than product development.
Strong grounding in security fundamentals: access management and authentication, secrets and vulnerability management, and data protection regulations (e.g. GDPR).
Practical experience working with AI tools like Claude and Gemini, and a solid understanding of the EU AI Act and AI governance principles (risk classification, disclosure requirements, data handling), able to translate that into workable guardrails for the team, not just theory.
Hands-on experience with HubSpot (CRM and automation), Notion, and LMS/Community platforms (e.g. Hivebrite, Circle), or the ability to quickly get fluent in a new SaaS platform's APIs and admin console.
Experience with automation and workflow tooling (e.g. Zapier, Make, native integrations) and data analysis.
Proactive and pragmatic: comfortable owning technical decisions with minimal supervision, while communicating clearly with non-technical stakeholders.
Excellent written and verbal communication in English, German is a plus
Why us?
Why join The DO School Fellowships?
- We are a purposeful organization with a global reach working to make an impact, where purpose, passion, and your ideas matter.
- You will work with an entrepreneurial, creative, and international team as well as a global community of purposeful DOers from over 100 countries.
- We offer a competitive salary, benefits, team-building activities, professional development opportunities, and flexible and remote work modalities.
Benefits include:
- 30 days of paid leave annually (based on a five-day working week)
- Company pension scheme ("Betriebliche Altersvorsorge")
- Possibility for mobile work (up to 50% of the working time)
- Possibility for remote work, also outside of Germany, for up to six weeks in total annually
- Regular team offsites, team events and parties
- Employee Benefits like Urban Sports Club or shopping vouchers