Information Security Engineer (m/f/d)

northerndata

Frankfurt

Vor Ort

EUR 70.000 - 100.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

northerndata seeks an Information Security Engineer to support governance and operational security across the organization. You will maintain the ISMS, coordinate security governance and documentation, and assist with audit activities in collaboration with Compliance, IT, Legal and HR.

The role covers ISMS improvement, policy lifecycle management, risk assessments, KPI reporting and security technologies, plus hands-on support for vulnerability management, incident response and security

Qualifikationen

  • Bachelor's degree in information security, Cyber Security, Computer Science or related discipline.
  • 5-7 years' experience in Information Security, GRC, Security Operations.
  • Solid understanding of ISMS and security governance frameworks (e.g. ISO/IEC 27001).
  • Experience with risk management methodologies and conducting information security risk assessments.
  • Familiarity with security compliance frameworks and regulatory requirements (e.g. NIS2, SOC 2, CIS Controls, GDPR).
  • Experience managing documentation, registers and workflows across enterprise collaboration platforms (e.g. SharePoint, Confluence, Jira).
  • Experience with Data Loss Prevention (DLP), information protection, and data classification solutions.
  • Experience with data analysis, reporting, dashboard development and KPI measurement.
  • Experience working in cross-functional environments with Infrastructure, IT, Platform Engineering, Compliance and Legal teams.
  • Familiarity with Vulnerability management processes and vulnerability assessment tools.
  • Security testing methodologies and tools (e.g. vulnerability scanning, security validation, or penetration testing support).
  • Familiarity with Security monitoring, SIEM platforms, and incident detection concepts.
  • Familiarity with Endpoint Detection and Response (EDR) and endpoint security technologies.

Aufgaben

  • Maintain and support the continual improvement of the ISO/IEC 27001 Information Security Management System (ISMS).
  • Own the lifecycle of security policies, standards, procedures and guidelines, including drafting, review cycles, approvals and publication via SharePoint and Confluence.
  • Administer Information Security documentation repositories, knowledge bases and workflow platforms (SharePoint, Confluence, Jira), including version control, review schedules and follow-up on overdue actions.
  • Own and maintain Information Security registers, including the Asset Register, Risk Register, Exception Register and Action Tracker, ensuring data quality and timely updates.
  • Support enterprise information asset management and data classification, including governance of data loss prevention (DLP) and sensitivity labelling technologies.
  • Lead audit preparation, evidence collection and logistics for internal and external audits; track findings, observations and corrective actions through to closure.
  • Support Information Security risk assessments, treatment plans and periodic reviews across the business.
  • Prepare Information Security metrics, dashboards, KPIs and management reports.
  • Coordinate Information Security projects, tracking scope, milestones, risks, dependencies, actions and deliverables.
  • Partner closely with Compliance, Legal, IT, Engineering, HR and business stakeholders on governance matters.

Kenntnisse

ISMS
ISO27001
GRC
Security Operations
Data Loss Prevention
Data Classification
Vulnerability Management
SIEM
EDR
Incident Response
Security Testing
Documentation
SharePoint
Confluence
Jira
Stakeholder Collaboration
Risk Assessments
IAM basics
Networking basics
Cloud security basics
Automation scripting

Ausbildung

Bachelor's degree in information security

Tools

SharePoint
Confluence
Jira

Jobbeschreibung

Job Description

The Information Security Engineer supports the Information Security function by delivering governance, and operational security services across the organization. The role is responsible for maintaining the Information Security Management System (ISMS), coordinating security governance and documentation, supporting audit activities, managing security-related projects, and assisting with the implementation and operation of securitAy controls and technologies. The position works closely with Compliance, IT, Engineering, Legal, HR and business stakeholders to strengthen the organization's overall security posture.

YOUR RESPONSIBILITIES:
Information Security Governance (Approx. 60%)
  • Maintain and support the continual improvement of the ISO/IEC 27001 Information Security Management System (ISMS).
  • Own the lifecycle of security policies, standards, procedures and guidelines, including drafting, review cycles, approvals and publication via SharePoint and Confluence.
  • Administer Information Security documentation repositories, knowledge bases and workflow platforms (SharePoint, Confluence, Jira), including version control, review schedules and follow-up on overdue actions.
  • Own and maintain Information Security registers, including the Asset Register, Risk Register, Exception Register and Action Tracker, ensuring data quality and timely updates.
  • Support enterprise information asset management and data classification, including governance of data loss prevention (DLP) and sensitivity labelling technologies.
  • Lead audit preparation, evidence collection and logistics for internal and external audits; track findings, observations and corrective actions through to closure.
  • Support Information Security risk assessments, treatment plans and periodic reviews across the business.
  • Prepare Information Security metrics, dashboards, KPIs and management reports.
  • Coordinate Information Security projects, tracking scope, milestones, risks, dependencies, actions and deliverables.
  • Partner closely with Compliance, Legal, IT, Engineering, HR and business stakeholders on governance matters.
Operational Security Support (Approx. 40%)
  • Support the implementation, configuration, administration and continuous improvement of Information Security technologies and platforms.
  • Support third-party security assessments, due diligence questionnaires and supplier assurance activities.
  • Support vulnerability remediation tracking, escalating overdue items and reporting on remediation progress.
  • Support security incident response activities, including documentation, coordination, evidence collection and post-incident improvement actions.
  • Support security awareness and communication initiatives.
  • Support security reporting, KPI tracking and management updates.
  • Provide coordination and administrative support to other Information Security team members.
YOUR QUALIFICATIONS:
  • Bachelor's degree in information security, Cyber Security, Computer Science or related discipline.
  • 5-7 years' experience in Information Security, GRC, Security Operations.
  • Solid understanding of ISMS and security governance frameworks (e.g. ISO/IEC 27001).
  • Experience with risk management methodologies and conducting information security risk assessments.
  • Familiarity with security compliance frameworks and regulatory requirements (e.g. NIS2, SOC 2, CIS Controls, GDPR).
  • Experience managing documentation, registers and workflows across enterprise collaboration platforms (e.g. SharePoint, Confluence, Jira).
  • Experience with Data Loss Prevention (DLP), information protection, and data classification solutions.
  • Experience with data analysis, reporting, dashboard development and KPI measurement.
  • Experience working in cross-functional environments with Infrastructure, IT, Platform Engineering, Compliance and Legal teams.
  • Familiarity with Vulnerability management processes and vulnerability assessment tools.
  • Security testing methodologies and tools (e.g. vulnerability scanning, security validation, or penetration testing support).
  • Familiarity with Security monitoring, SIEM platforms, and incident detection concepts.
  • Familiarity with Endpoint Detection and Response (EDR) and endpoint security technologies.
Nice to have
  • Basic Understanding of Identity and Access Management (IAM), authentication, and privileged access management concepts.
  • Basic understanding of networking, TCP/IP, DNS, routing, switching, and network security principles.
  • Basic understanding of web technologies and web application security concepts.
  • Basic Understanding of Cloud security concepts and shared responsibility models.
  • Scripting or automation fundamentals (e.g. PowerShell or Python) would be advantageous.
WHAT WE OFFER

With us, you will work towards the future of HPC : From new, sustainable building methods for data centers to cooling concepts to software solutions for accelerated compute.

Your approaches count : In official exchange formats or spontaneously at the coffee machine. At Northern Data, it's t

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Engineer (m/f/d)
Information Security Engineer (m/f/d)

Northern Data AG • Frankfurt

Hybrid
EUR 85.000 - 120.000
Home office flexibility
Wellbeing initiatives
Sustainability focus
IT Administrator with Security Focus
IT Administrator with Security Focus

metamorphosis GmbH • Paderborn

Vor Ort
EUR 60.000 - 90.000
(Senior) Information Security Officer (German)
(Senior) Information Security Officer (German)

United States Digital Space LLC • München

Vor Ort
EUR 90.000 - 130.000
Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

IDEALworks GmbH • München

Hybrid
EUR 70.000 - 90.000
30 vacation days
Bonus scheme
Company pension scheme
+1
Senior IT Security Consultant (m/f/d) new
Senior IT Security Consultant (m/f/d) new

beON consult GmbH • Kiel

Vor Ort
EUR 60.000 - 90.000
Attractive financial compensation
Comprehensive development opportunities
Healthy work-life balance
+2
Information Security Engineer (m/f/d)
Information Security Engineer (m/f/d)

PSI Software - Scandinavia • Aschaffenburg

Hybrid
EUR 70.000 - 100.000
Development & Training
Mobile working
Team Events
Information Security Manager (f/m/d) - Senior
Information Security Manager (f/m/d) - Senior

PSI Software • Berlin

Vor Ort
EUR 90.000 - 130.000
Information Security Officer – Information Security Representative
Information Security Officer – Information Security Representative

Jobtailor • Landshut

Vor Ort
EUR 70.000 - 110.000
Senior Information Security Specialist (m/w/d)
Senior Information Security Specialist (m/w/d)

NVISO Security • Frankfurt

Vor Ort
EUR 70.000 - 90.000
Training budget of 10,000 EUR
30 days of vacation
Flexible working hours
+1
Information Security Officer
Information Security Officer

Iduet • Dortmund

Vor Ort
EUR 65.000 - 90.000