Information Security Officer (m/f/d)

Idealworks

München

Hybrid

EUR 70.000 - 110.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid working model
30 vacation days
Bonus scheme
Annual personal development budget
Company pension scheme
Regular team events
Modern office in accessible location

Zusammenfassung

Idealworks Munich seeks a Security & Compliance Specialist with 4–6 years in information security to implement and maintain ISO 27001 and TISAX, manage audits, and drive risk and incident response. You will coordinate regulatory compliance, document controls, and support customer questionnaires in a fast-paced, international team.

The role offers a hybrid work model, a competitive bonus scheme, and a development budget to foster growth and expertise.

Qualifikationen

  • Bachelor's degree required in IT, CS, or related field.
  • 4–6 years in information security or IT governance.
  • Hands-on ISO 27001 implementation and audits.
  • Experience with TISAX requirements and automotive security standards.
  • Strong risk management, threat modelling and vulnerability management.
  • Experience with penetration testing tools and methodologies.
  • Knowledge of infrastructure hardening and application security practices.
  • Excellent problem-solving, analytical and communication skills.
  • English proficiency; German is a plus.

Aufgaben

  • Implement and maintain ISO 27001 and TISAX certifications.
  • Lead audit preparation and coordination.
  • Maintain SoA and evidence for controls.
  • Ensure regulatory and contractual security compliance.
  • Develop and maintain compliance documentation, policies, and procedures.
  • Lead security incident response and BCP/ continuity management.
  • Identify, assess, and track security risks.
  • Coordinate security questionnaires and RFP responses.
  • Act as security and compliance SME for customer-facing teams.

Kenntnisse

ISO 27001 implementation
TISAX experience
Risk management
Incident response
Audit coordination
Regulatory compliance
Penetration testing tools
Threat modelling
English proficiency
German language skills

Ausbildung

Bachelor’s degree in Information Technology, Computer Science, or a related field

Tools

Nessus
Burp Suite
OWASP ZAP
SIEM tools

Jobbeschreibung

Role Responsibilities: What you will do
Governance & Compliance
  • Implement and maintainISO 27001andTISAXcertifications.
  • Own all compliance-related activities, including but not limited to:
  • Internal and external audit preparation and coordination.
  • Maintaining theStatement of Applicability (SoA)and evidence for controls.
  • Ensuring adherence to regulatory and contractual security requirements.
  • Develop and maintain compliance documentation, policies, and procedures.
Incident & Continuity Management
  • Lead security incident response and ensure proper documentation.
  • Conduct root cause analysis and follow-up on corrective actions.
  • Own the end-to-end BCP process, including but not limited to:
  • Maintain BCP documentation and ensure readiness through periodic BCP drills and readiness assessments.
  • Launch BCP in case of major incidents or disruptions.
  • Coordinate communication with stakeholders during BCP activation.
Risk Management
  • Identify, assess, prioritize, and track security risks.
  • Monitor timely execution of mitigation plans.
  • Perform and review threat modelling for critical systems and processes.
Security Operations
  • Overseedata classificationand define retention periods.
  • Support infrastructure hardening and application security initiatives.
  • Maintain and enhance the security playbook AI model for incident response.
Testing & Assurance
  • Plan and coordinate penetration testingand vulnerability assessments.
  • Prioritize and follow up on mitigation of PEN test findings.
Customer & Stakeholder Support
  • Act as a security and compliance subject matter expert for customer‑facing teams.
  • Respond to security questionnaires and RFPs.
Role Requirements: What you need to succeed
  • Bachelor’s degree in Information Technology, Computer Science, or a related field.
  • 4 – 6 years work experience in information security, compliance, or IT governance.
  • Hands-on experience with ISO 27001 implementation and audits.
  • Ideally, you have experience in TISAX requirements and automotive security standards.
  • Strong understanding of risk management, threat modelling, and vulnerability management.
  • Experience with penetration testing tools and methodologies.
  • Knowledge of infrastructure hardening and application security best practices.
  • Deep understanding of regulatory frameworks and audit processes.
  • Experience maintaining compliance documentation and evidence.
  • Excellent problem‑solving and analytical skills.
  • Strong verbal and written communication skills in English, German is a plus.
  • Ability to work in a highly agile, fast‑paced environment.
Why idealworks
  • At idealworks, you will find an international working environment and become part of an experienced, open team where mutual trust counts. You will feel at home from the very first second!
  • Experience a first‑hand start‑up feeling and flat hierarchies with varied and responsible tasks that you work on independently.
  • Look forward to hybrid working model with 30 vacation days per year and various opportunities to balance your free time, family and job.
  • For your commitment to helping us achieve our mission, you will not only be rewarded with appreciation, but also with above‑average pay including a bonus scheme and an annual personal development budget.
  • We offer exciting corporate benefits, an attractive company pension scheme and regular team events.
  • Our modern office is easily accessible by public transport, bike and car and offers numerous catering options for relaxed lunch breaks with your team.
  • Driven by our unique corporate culture, the five values "passion for results", "wellbeing", "personal growth", "trust" and "being and acting as one team" determine our daily actions and cooperation.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

IDEALworks GmbH • München

Hybrid
EUR 70.000 - 90.000
30 vacation days
Bonus scheme
Company pension scheme
+1
Information Security Officer (m/w/d)
Information Security Officer (m/w/d)

Xecuro • Bonn

Vor Ort
EUR 60.000 - 80.000
Toller Teamspirit
Flexible Arbeitsmodelle und 30 Tage Urlaub
Moderne Arbeitsausstattung
+4
Information Security Specialist (m/f/d)
Information Security Specialist (m/f/d)

And E • Ismaning

Vor Ort
EUR 70.000 - 110.000
32 days annual leave
Flexible working hours
Home office policy
Information Security Consultant - ISM (all genders)
Information Security Consultant - ISM (all genders)

DATAGROUP Service Hub GmbH • Deutschland

Hybrid
EUR 60.000 - 80.000
Flexible Arbeitszeiten
Homeoffice-Möglichkeiten
Karriereförderung durch Schulungen
+5
Information Security Officer (m/w/d)
Information Security Officer (m/w/d)

Xecuro GmbH • Deutschland

Vor Ort
EUR 50.000 - 70.000
30 Tage Urlaub im Jahr
Modernes Arbeitsumfeld
Individuelle Weiterbildungsmöglichkeiten
+1
Information security officer / Data Governance Manager (m/w/d)
Information security officer / Data Governance Manager (m/w/d)

Gwp • Oberpöring (VGem)

Vor Ort
EUR 65.000 - 90.000
Mentoring & Onboarding
Weiterentwicklung
30 Tage Jahresurlaub
+6
Information Security Specialist (m/w/d)
Information Security Specialist (m/w/d)

Aioi Nissay Dowa Europe • Deutschland

Hybrid
EUR 70.000 - 110.000
32 days leave per year
Flexible working hours
Home office ~60%
+3
Chief Information Security Officer / CISO (m/w/x)
Chief Information Security Officer / CISO (m/w/x)

BOGE KOMPRESSOREN Otto Boge GmbH & Co. KG • Bielefeld

Vor Ort
EUR 120.000 - 180.000
Attraktives Gehalt
Flexible Arbeitszeiten
Zusätzliche Urlaubstage
+13
Information Security Consultant (m/w/d)
Information Security Consultant (m/w/d)

Schönbrunn TASC GmbH • Leonberg

Vor Ort
EUR 50.000 - 70.000
30 Tage Urlaub
Flexible Arbeitszeitmodelle
Fortbildungsmöglichkeiten
+1
Mitarbeiter (m/w/d) Informationssicherheit & Compliance
Mitarbeiter (m/w/d) Informationssicherheit & Compliance

Acn Group • Deutschland

Vor Ort
USD 60.000 - 80.000
Betriebliche Altersvorsorge
Fahrtkostenzuschuss
5.000 € jährliches Weiterbildungsbudget
+1