Information Security Officer (m/w/d)
Location: ÖBB-Infrastruktur AG, Wien-Leopoldstadt, Wien 1020. Normalarbeitszeit: Gleitzeit (38,5 Std.). Req ID: req25354.
Responsibilities
- Set up measures to ensure integrity, confidentiality, and availability of information based on analysis and requirements, and actively develop the information security level within your area of responsibility.
- Plan, implement and operate the Information Security Management System (ISMS) for internal partners and support its continuous improvement.
- Assess IT projects, services, applications, architectures, configurations, access requirements, and security-relevant processes for protection needs, risks, compliance, and necessary security measures.
- Create reports, decision bases, and action recommendations on threats, measures, residual risks, and necessary information security measures for decision makers and the management.
- Develop concepts, policies, training materials and trainings, and support the sustainable embedding of information security in the organization.
- Plan, initiate, conduct and support internal and external audits, security assessments, and penetration tests in close coordination with relevant stakeholders.
- Assist with handling security incidents and lead or support projects or work packages focused on information security.
- Act as a central contact for information security in the supervised areas, participate in coordination and decision platforms, and support or represent the CISO in relevant committees when needed.
Qualifications
- Fundamental knowledge in information security and operational or development of an ISMS – preferably based on a completed technical university degree or equivalent professional experience.
- Multiple years of relevant professional experience in comparable functions, e.g., Information Security Management, IT security, IT operations, or audit environment.
- Knowledge of relevant norms, standards and regulatory requirements and confident application, especially ISO/IEC 27000 series (including ISO/IEC 27001:2022 and ISO/IEC 27002:2022), IEC 62443 series, BSI IT-Grundschutz (BSI 200-1 bis 200-3), GDPR, NIS-2 directive and Austrian NISG 2026, as well as relevant audit standards such as ISAE 3402.
- Ideally hold certifications in information security, e.g., CISA, CISM or CISSP.
- Analytical, structured and independent working style, decisive and solution-oriented, capable of building trust and acceptance with various stakeholders.
- Strong communication in technical and professional aspects, confident in moderation, team-oriented, and able to take responsibility even for non-complex projects.
- Good English language skills in spoken and written form.
Benefits
- International group environment with ongoing developmental and continuous learning opportunities.
- Role-specific certification support.
- Cafeteria with daily selection of hot lunch meals.
- Modern workplace with excellent public transport access.
- Several benefits including preferential rates for train travel & travel agencies, vacation homes and apartments in popular local vacation regions, and in-house car sharing.
- Flexible working hours, home office and provision of services such as a nearby kindergarten for children, and a nanny service.
- For the function “Expert Information Security Management” the minimum remuneration is €60,150.16 gross per year according to the collective agreement for railway companies. Additional remuneration may be possible depending on qualifications and experience; a comprehensive package including flexible working hours is indicated.
EEO Statement
Women are an indispensable part of our success and our company culture. Therefore we particularly welcome applications from women, who, when equally qualified, will be given priority when considering all applications.
We highlight that a criminal record check is required as part of the onboarding process.