Information Security Officer (m/f/d)

IDEALworks GmbH

München

Vor Ort

EUR 70.000 - 90.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

30 vacation days
Bonus scheme
Company pension scheme
Team events

Zusammenfassung

A tech-focused company in Germany is seeking a Governance and Compliance Specialist to manage ISO 27001 and TISAX certifications. Responsibilities include leading security incident responses, managing compliance documentation, and identifying security risks. Candidates should have a Bachelor's degree in IT, extensive experience in information security, and strong analytical and communication skills. The role offers a hybrid working model with competitive benefits, located in Munich.

Qualifikationen

  • 4 – 6 years of experience in information security, compliance, or IT governance.
  • Hands-on experience with ISO 27001 implementation and audits.
  • Strong understanding of risk management and threat modelling.
  • Experience with penetration testing tools and methodologies.

Aufgaben

  • Implement and maintain ISO 27001 and TISAX certifications.
  • Lead security incident response and ensure proper documentation.
  • Identify, assess, prioritize, and track security risks.
  • Plan and coordinate penetration testing and vulnerability assessments.

Kenntnisse

ISO 27001
TISAX
Risk management
Threat modelling
Vulnerability management
Penetration testing
Analytical skills
Problem-solving
Communication skills

Ausbildung

Bachelor's degree in Information Technology or Computer Science

Jobbeschreibung

The Role: What to expect
Role Requirements: What you need to succeed
  • Bachelor’s degree in Information Technology, Computer Science, or a related field.
  • 4 – 6 years work experience in information security, compliance, or IT governance.
  • Hands‑on experience with ISO 27001 implementation and audits.
  • Ideally, you have experience in TISAX requirements and automotive security standards.
  • Strong understanding of risk management, threat modelling, and vulnerability management.
  • Experience with penetration testing tools and methodologies.
  • Knowledge of infrastructure hardening and application security best practices.
  • Deep understanding of regulatory frameworks and audit processes.
  • Experience maintaining compliance documentation and evidence.
  • Excellent problem‑solving and analytical skills.
  • Strong verbal and written communication skills in English, German is a plus.
  • Ability to work in a highly agile, fast‑paced environment.
Why idealworks
  • At idealworks, you will find an international working environment and become part of an experienced, open team where mutual trust counts. You will feel at home from the very first second!
  • Experience a first‑hand start‑up feeling and flat hierarchies with varied and responsible tasks that you work on independently.
  • Look forward to hybrid working model with 30 vacation days per year and various opportunities to balance your free time, family and job.
  • For your commitment to helping us achieve our mission, you will not only be rewarded with appreciation, but also with above‑average pay including a bonus scheme and an annual personal development budget.
  • We offer exciting corporate benefits, an attractive company pension scheme and regular team events.
  • Our modern office is easily accessible by public transport, bike and car and offers numerous catering options for relaxed lunch breaks with your team.
  • Driven by our unique corporate culture, the five values “passion for results”, “wellbeing”, “personal growth”, “trust” and “being and acting as one team” determine our daily actions and cooperation.
Role Responsibilities: What you will do
Governance & Compliance
  • Implement and maintainISO 27001andTISAXcertifications.
  • Own all compliance‑related activities, including but not limited to:
    • Internal and external audit preparation and coordination.
    • Maintaining theStatement of Applicability (SoA)and evidence for controls.
    • Ensuring adherence to regulatory and contractual security requirements.
  • Develop and maintain compliance documentation, policies, and procedures.
Incident & Continuity Management
  • Lead security incident response and ensure proper documentation.
  • Conduct root cause analysis and follow‑up on corrective actions.
  • Own the end‑to‑end BCP process, including but not limited to:
    • Maintain BCP documentation and ensure readiness through periodic BCP drills and readiness assessments.
    • Launch BCP in case of major incidents or disruptions.
    • Coordinate communication with stakeholders during BCP activation.
Risk Management
  • Identify, assess, prioritize, and track security risks.
  • Monitor timely execution of mitigation plans.
  • Perform and review threat modelling for critical systems and processes.
Security Operations
  • Overseedata classificationand define retention periods.
  • Support infrastructure hardening and application security initiatives.
  • Maintain and enhance the security playbook AI model for incident response.
Testing & Assurance
  • Plan and coordinate penetration testingand vulnerability assessments.
  • Prioritize and follow up on mitigation of PEN test findings.
Customer & Stakeholder Support
  • Act as a security and compliance subject matter expert for customer‑facing teams.
  • Respond to security questionnaires and RFPs.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

Idealworks • München

Hybrid
EUR 90.000 - 130.000
30 vacation days
Bonus scheme
Attractive company pension scheme
+2
Information Security Officer (m/w/d) – ISO27001
Information Security Officer (m/w/d) – ISO27001

AfB gGmbH • Ettlingen

Vor Ort
EUR 45.000 - 55.000
Unbefristete Anstellung
Firmenevents
BusinessBike
+4
Information Security Expert – m/f/d
Information Security Expert – m/f/d

Jobtailor • Erfurt

Vor Ort
EUR 60.000 - 85.000
IT Security Consultant (w/m/d) Fokus auf ISO 27001, ISMS und TISAX
IT Security Consultant (w/m/d) Fokus auf ISO 27001, ISMS und TISAX

Staatliches Schulamt Südthüringen • Deutschland

Vor Ort
EUR 60.000 - 90.000
Information Security & Compliance Officer (f/m/d)
Information Security & Compliance Officer (f/m/d)

United States Digital Space LLC • Berlin

Vor Ort
EUR 65.000 - 90.000
30 vacation days
Deutschlandticket mobility budget
Urban Sports partnership
+1
Information Security Professional (m/w/d)
Information Security Professional (m/w/d)

Rosenberger Hochfrequenztechnik GmbH & Co. KG • Fürst

Vor Ort
EUR 60.000 - 80.000
(Senior) Information Security Officer (German)
(Senior) Information Security Officer (German)

United States Digital Space LLC • München

Vor Ort
EUR 90.000 - 130.000
Information Security Officer (m/w/d)
Information Security Officer (m/w/d)

Xecuro • Bonn

Vor Ort
EUR 60.000 - 80.000
Toller Teamspirit
Flexible Arbeitsmodelle und 30 Tage Urlaub
Moderne Arbeitsausstattung
+4
IT-Security Governance Specialist (m/w/d) - J34485
IT-Security Governance Specialist (m/w/d) - J34485

Exclusive Associates • Wiesbaden

Vor Ort
EUR 48.000 - 62.000
Flexible Arbeitszeiten zur besseren Vi
Mobilitätsangebote und Pendelunterstüt
Attraktive Urlaubsregelungen für Erhol
+3
Information Security Officer – Information Security Representative
Information Security Officer – Information Security Representative

Jobtailor • Landshut

Vor Ort
EUR 70.000 - 110.000