Information Security Responsible / IT Security Manager

AO Foundation

Schweiz

Hybrid

CHF 180,000 - 280,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible working hours
Pension scheme
Supplementary vacation days
International team

Job summary

AO Foundation in Davos, Switzerland seeks an Information Security Responsible (ISR) and IT Security Manager to shape security strategy, governance, and risk oversight at executive level. The role translates strategy into structure, processes, and controls in collaboration with IT leadership and stakeholders.

Reporting to Head of IT with potential CEO alignment in conflicts of interest, the position emphasizes security leadership, incident management, and budget responsibility, with 3 days/week

Qualifications

  • Executive-level information security leadership and governance.
  • Strong technical cyber security expertise across frameworks and IAM.
  • Experience with risk assessment, audit, and incident response.
  • Excellent communication with executive management and stakeholders.
  • Ability to develop and evolve security programs and policies.

Responsibilities

  • Define the information security strategy and governance model.
  • Oversee risk, compliance, and control oversight across the organization.
  • Lead cyber security operations and incident response.
  • Oversee security architecture, patch management, and monitoring.
  • Continuously improve security controls and processes.
  • Coordinate with IT leadership and stakeholders.

Skills

Executive leadership
Information security strategy
Security governance & policy
Risk management & compliance
Communication with executives

Education

Master’s degree in CS/IT/Cyber security
Certifications in information security (CISSP/CISM etc.)

Tools

Security monitoring tools
Vulnerability management tools
Threat analysis tools

Job description

The AO is a medically guided, not-for-profit organization, a global network of surgeons, and the world's leading education, innovation, and research organization specializing in the surgical treatment of trauma and musculoskeletal disorders. We are home to people from all over the world, from different backgrounds, with diverse talents and specialist areas. What binds us together is our passion for excellence, our dedication to our mission of improving patient care, and our understanding that we are stronger together: we are one AO.
For more information, visit: https://www.aofoundation.org/

As part of the AO’s support units, our IT department offers information technology services to maintain and oversee computer infrastructure across the AO Foundation.

Workload percentage / Pensum: 100%

Short Description

Purpose of the Role:


This combined role covers both strategic information security leadership and operational IT security management. As Information Security Responsible (ISR), the position holder defines the security strategy, owns governance and risk oversight, and ensures compliance with agreed information security requirements at an executive level comparable to a CISO function. As IT Security Manager, the position holder translates this strategy into effective structures, processes, controls, and operational security practices in close collaboration with the Head of Infrastructure, Head of IT, the IT Management Team, and relevant stakeholders.

Reporting line: Direct report to Head of IT, line to CEO in case of conflicts of interest in relation to the role of Information Security Responsible

Place of work: Davos, 3 days per week in office

Main Responsibilities
  • Strategic security leadership and governance: Define, align, and maintain the information security strategy, policies, standards, ISMS, and governance model in line with organizational objectives, regulatory requirements, and stakeholder expectations.
  • Risk, compliance, and control oversight: Identify, assess, and manage information security risks; ensure agreed security controls are implemented, monitored, audited, and continuously improved.
  • Security operations and incident management: Lead and coordinate cyber security operations, incident response, threat analysis, threat hunting, remediation activities, lessons learned, and operational security reporting.
  • Security architecture and technical control management: Oversee secure configuration, hardening, patch management, monitoring, and security architecture in collaboration with IT leadership, infrastructure, enterprise architecture, and operational IT teams.
  • Business continuity, crisis, and stakeholder communication: Contribute to business continuity and crisis management for IT security matters, including preparation, testing, communication, post-incident reviews, and management reporting.
  • Awareness, training, and collaboration: Promote security awareness and training in coordination with HR and management, and ensure effective collaboration across IT, business stakeholders, governance bodies, and external partners.
  • Vendor management and budget responsibility: Support IT partner and third-party security management, contribute to vendor security assessments, and develop, monitor, and report on the central IT security budget.
Main Requirements

Core Skills / Competencies:

  • Executive-level information security leadership with the ability to act as knowledge owner, advisor, and thought leader for security governance, risk, and compliance.
  • Strong technical cyber security expertise across security frameworks, security architecture, network security, identity and access management, monitoring, encryption, vulnerability management, and threat detection.
  • Proven capability in risk assessment, audit, incident response, crisis management, and continuous improvement of security controls and processes.
  • Excellent communication, negotiation, and stakeholder management skills, including the ability to work effectively with executive management, governance bodies, IT teams, business stakeholders, and external partners.
  • Strong analytical, problem-solving, project management, and collaboration skills with a pragmatic, solution-oriented, and supportive working style.

Educational Requirements:

  • Master’s degree or equivalent qualification in computer science, information technology, cyber security, information security, or a related field.
  • Relevant professional certifications or additional education in information security, cyber security, governance, risk, compliance, data protection, and applicable standards and regulations, including GDPR/DSGVO.

Job Experience:

  • Minimum 10 years of experience in information security and cyber security, preferably including leadership or management responsibility.
  • Demonstrated experience in developing and implementing information security strategies, governance models, security programs, policies, standards, and operational security processes.
  • Hands-on experience with cyber security operations, incident response, threat analysis, security monitoring, vulnerability management, and related commercial security tools.
  • Experience working with corporate governance, data protection, compliance, audit, vendor management, and cross-functional stakeholder structures.
  • Previous work experience in Switzerland is a strong asset.

Language Skills:

  • Proficient in German and English, both written and orally

We offer

  • An interesting and varied job in an exciting and innovative organization
  • The opportunity to be part of a highly committed international team
  • Modern infrastructure
  • High degree of flexibility regarding working hours and location (depending on operational requirements)
  • Generous package of social benefits, including supplementary vacation days and pension scheme contributions
  • Internal skills training opportunities and support for continued education
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Security Engineer (ID2140)
Senior IT Security Engineer (ID2140)

AO Foundation • Switzerland

On-site
CHF 120,000 - 160,000
Flexible hours
Hybrid work
Pension and vacation benefits
+1
Assistant to Head IT / Team Assistant, 80% (ID2170)
Assistant to Head IT / Team Assistant, 80% (ID2170)

Liechtenstein Business • Davos

On-site
CHF 90,000 - 120,000
Information Security Leader & IT Security Manager
Information Security Leader & IT Security Manager

AO Foundation • Switzerland

Hybrid
CHF 180,000 - 280,000
Flexible working hours
Pension scheme
Supplementary vacation days
+1
Communications Specialist (JR2195)
Communications Specialist (JR2195)

AO Foundation • Davos

Hybrid
CHF 120,000 - 180,000
Flexible hours
Hybrid work option
Pension scheme
+2
Communications Specialist
Communications Specialist

AO Foundation • Davos

On-site
CHF 90,000 - 130,000
Generous social benefits
Pension scheme contributions
Internal skills training opportunities
+1
Senior Specialist, IT
Senior Specialist, IT

Universität Basel • Basel

On-site
CHF 110,000 - 140,000
Head of Information Security
Head of Information Security

PHOENIQS • Basel

On-site
CHF 120,000 - 150,000
Leadership role with end-to-end ownership of information security
Opportunities for long-term development
High visibility within senior management
Communications Specialist (JR2195)
Communications Specialist (JR2195)

Liechtenstein Business • Davos

Hybrid
CHF 110,000 - 170,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

AO Foundation • Davos

On-site
CHF 140,000 - 170,000
Supplementary vacation days
Pension scheme contributions
Social benefits package
Information Security Officer
Information Security Officer

Die Schweizerische Post AG • Bern

On-site
CHF 120,000 - 160,000