Information Security Manager

DUDE CHEM

Berlin

Hybrid

EUR 90.000 - 130.000

Vollzeit

Vor 8 Tagen
Bewerbungsgenerator

Verschicke keinen generischen Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

International team
Flat hierarchies
Competitive compensation
Learning and growth opportunities

Zusammenfassung

Vektor Group seeks an experienced Group ISB leader to own the information security strategy, programme, and posture across the organisation. You will closely partner with the Director of Internal IT on technical controls and implementation.

Your mandate includes ISO 27001 certification with BSI IT-Grundschutz and NIS-2 compliance, from gap analysis to audit readiness, ongoing maintenance, and regulatory obligations across the group.

Qualifikationen

  • Several years of information security leadership experience.
  • Proven practice with BSI IT-Grundschutz and ISO 27001 programmes.
  • Experience building or leading ISO 27001 roadmaps to audit readiness.
  • Strong risk management and clear communication to technical and non-technical audiences.
  • Willingness to work hands-on during the build-up phase.
  • Fluent German (C1) and English (B2) or higher.

Aufgaben

  • Build and operate the group-wide ISMS following BSI standards.
  • Create and maintain security policy framework at group level.
  • Prepare ISO 27001 certification and coordinate audits.
  • Implement NIS-2 obligations: reporting, evidence, actions.
  • Manage risk across technical and organizational domains, reporting to executives.
  • Steer external consultants and service providers within the programme.
  • Develop security awareness training and programmes.
  • Own incident response planning and coordinate during incidents.
  • Assess third-party and vendor risk and perform security assessments.
  • Collaborate with IT leadership and product security, support customer trust processes.

Kenntnisse

InfoSec leadership
ISO 27001
BSI IT-Grundschutz
NIS-2 compliance
Risk management
Audits & certifications
Policy development
Incident response
Vendor risk assessment
Security awareness

Jobbeschreibung

The Role

As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.

We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.

Your Responsibilities
  • Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
  • Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
  • Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
  • Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
  • Manage risk across technical and organizational domains, including reporting to executive management
  • Steer external consultants and service providers within the running programme
  • Build and run the security awareness programme: training and sensitization
  • Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
  • Assess third-party and vendor risk, run security assessments for new tools and partners
  • Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
  • Support sales and customer trust processes: security questionnaires, due diligence, customer audits
  • Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action
What You Bring
  • Several years of experience as an ISB or in comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
  • Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
  • Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
  • Willingness to work hands-on during the build-up phase
  • Confident interaction with executive management, auditors, and customers
  • German at C1 or above, English at B2 or above
Nice to Have
  • Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM
  • Experience with security governance across multiple legal entities or jurisdictions
  • Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
  • Practical NIS-2 implementation experience
  • Experience with sales-adjacent security processes (pre-sales, customer audits)
What We Offer
  • International team with colleagues across Germany and other locations.
  • Startup environment with real ownership, flat hierarchies, and fast decisions.
  • Competitive compensation aligned with experience and responsibility.
  • Individual learning and growth opportunities beyond your role.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Officer
Information Security Officer

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 130.000
Information Security Officer
Information Security Officer

Orcrist Technologies • Deutschland

Vor Ort
EUR 90.000 - 140.000
International team
Startup environment
Competitive compensation
+1
Informationssicherheitsbeauftragter (ISB)
Informationssicherheitsbeauftragter (ISB)

DUDE CHEM • Berlin

Hybrid
EUR 110.000 - 140.000
Internationales Team in Deutschland
Remote-first in Deutschland
Wettbewerbsfähige Vergütung
+2
Senior Information Security Specialist (m/w/d)
Senior Information Security Specialist (m/w/d)

NVISO Security • Frankfurt

Vor Ort
EUR 70.000 - 90.000
Training budget of 10,000 EUR
30 days of vacation
Flexible working hours
+1
Information Security (Senior) Manager (m/w/d)
Information Security (Senior) Manager (m/w/d)

NVISO Security • Frankfurt

Vor Ort
EUR 90.000 - 115.000
Training budget of 10,000 EUR
30 days of vacation
Flexible working hours
+2
Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

Idealworks • München

Vor Ort
EUR 70.000 - 110.000
Hybrid working model
30 vacation days
Bonus scheme
+4
Information Security Manager – f/d/m
Information Security Manager – f/d/m

Jobtailor • Düsseldorf

Vor Ort
EUR 70.000 - 110.000
Principal Information Security Specialist (m/w/d)
Principal Information Security Specialist (m/w/d)

NVISO Security • München

Vor Ort
EUR 140.000 - 180.000
Training budget of 10,000 EUR
30 days of vacation
Flexible working hours
+3
Information Security / Resilience (Senior) Manager (m/w/d)
Information Security / Resilience (Senior) Manager (m/w/d)

NVISO Security • Frankfurt

Hybrid
EUR 90.000 - 130.000
Generous training budget
Competitive base salary 90k-130k
Flexible working hours and home office
+2
Junior Cyber Strategy & Architecture Consultant (m/w/d) - Focus GRC
Junior Cyber Strategy & Architecture Consultant (m/w/d) - Focus GRC

Meyandy LLC • Frankfurt

Hybrid
EUR 57.000 - 62.000
Training budget
Salary 57k–62k EUR gross
Flexible working hours
+4