- Further development of the Information Security Management System (ISMS), including risk analyses, policies, audits and certifications
- Advising business units and development teams on information security and secure development topics
- Supporting security-related projects
- Managing vulnerability management, security assessments and the handling of security incidents
- Supporting Sales and Customer Success with security questionnaires, customer audits and other information security requirements
- Coordinating data protection-related matters as the interface to the external Data Protection Officer
- Prospective responsibility for other related management systems
- Further development of security awareness and an ingrained security culture
Requirements
- Several years of professional experience in information security, IT security or compliance
- Experience in establishing or further developing an Information Security Management System, ideally according to ISO 27001
- Understanding of modern software development processes
- Interest in embedding information security early in product development
- Structured working style
- Strong communication skills and the ability to engage diverse stakeholders in information security
- Experience with BSI C5 or NIS2 desirable
- Certification such as ISO 27001 Lead Implementer, Lead Auditor, CISM or a comparable qualification desirable
- Fluent German, at least C1
Core Competencies
Demonstrates expertise in developing and managing Information Security Management Systems (ISMS) in alignment with ISO 27001, while effectively engaging stakeholders and embedding security practices in product development. Proficient in conducting risk analyses, security assessments, and fostering a security-aware culture within organizations.
Highest-signal resume keywords
- Information Security Management System Development
- ISO 27001 Implementation
- Risk Analysis
- Security Assessments
- Fluent German (C1)
ATS Optimization Keywords
Hard Skills
- Information Security
- IT Security
- Compliance
- Vulnerability Management
- Security Incident Handling
- Security Audits
- Data Protection Coordination
- Security Awareness Development
- Modern Software Development Processes
Soft Skills
- Strong Communication Skills
- Stakeholder Engagement
- Structured Working Style
Certifications & Qualifications
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- CISM
Tools & Technologies