International multi-site organisation | Germany / DACH region
The opportunity
This regional role is accountable for implementing, maintaining and continuously improving information-security standards, policies, processes and procedures across the DACH region. You will help translate an international security strategy and roadmap into practical adoption and measurable impact within local business units.
Working closely with regional management, IT leaders and Security Champions, you will establish effective security governance, advise senior stakeholders and drive measurable risk reduction. The role combines governance and stakeholder leadership with a willingness to engage directly in operational and engineering matters.
What you will do
- Translate group-level information-security strategy and standards into regional governance structures, security calendars, roadmaps and implementation plans.
- Establish, chair and coordinate information-security management forums with business-unit management, IT leadership and Security Champions.
- Support management teams in evaluating security performance, overseeing compliance and ensuring appropriate resources are available for continual improvement.
- Act as the primary regional contact for information-security matters and provide clear, pragmatic and business-focused advice to senior stakeholders.
- Ensure security policies, standards, processes and procedures are documented, implemented, communicated and maintained across the region.
- Monitor compliance, identify control gaps and drive appropriate remediation across local business units.
- Define and report meaningful security KPIs, control effectiveness, material risks, incidents, exceptions and remediation progress.
- Lead information-security risk assessments, define pragmatic mitigation plans and ensure timely follow-up of material risks and control gaps.
- Coordinate regional adoption of security services, including detection and response, vulnerability management, security monitoring and incident-response capabilities.
- Support the coordination, investigation and follow-up of security incidents, security requests and crisis-management activities.
- Drive vulnerability assessments, penetration testing and red-team exercises, and promote secure practices throughout the software-development lifecycle.
- Support third-party cyber-risk management, including supplier assessments, contractual security requirements and risk treatment plans.
- Drive regional security initiatives with clear owners, milestones, dependencies and measurable outcomes.
- Prioritise improvements across identity and access management, privileged access, MFA, vulnerability and patch management, endpoints, networks, cloud security, backup and recovery, and end-of-life remediation.
- Promote security awareness and enable Security Champions to build a sustainable culture of accountability and secure behaviour.
What you bring
- A strong understanding of information-security governance, risk, controls, compliance, incident response, vulnerability management and security monitoring.
- Hands-on security experience and a willingness to engage in security operations and engineering activities when required.
- The ability to translate international security strategy and standards into pragmatic regional and business-unit implementation plans.
- Excellent analytical and communication skills, with the ability to explain risks, priorities and required actions clearly to senior stakeholders.
- Strong organisational skills, attention to detail and the ability to manage multiple initiatives, timelines and dependencies across business units.
- The ability to influence effectively in a federated organisation and build trust with management, IT leaders, Security Champions and central functions.
- An action-oriented, results-driven approach, with a strong sense of urgency and commitment to thorough execution.
- Sound judgement, discretion and respect for confidentiality.
Experience and qualifications
- At least five years of experience in a complex information-security role, ideally within an international or multi-site organisation.
- Demonstrable experience spanning security governance as well as operational security delivery.
- Experience with security risk assessments, compliance oversight, control monitoring and remediation programmes.
- Practical exposure to incident response, vulnerability management, penetration testing, security monitoring and third-party cyber risk.
- Experience coordinating stakeholders and initiatives across multiple business units or countries.
- Professional fluency in German and English, with strong written and verbal communication skills.
Working arrangement
The role is based in eg. Dortmund or Hamburg region and requires fluency in German and has responsibility across the DACH region. Travelling to the opco's in the region is required. Further organisational and location details are shared during the recruitment process.