IT Security & Compliance Program Lead (m/f/d)

Edri

Essen

Hybrid

EUR 90,000 - 130,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid working
Workation within EU
Competitive salary with performance‑or
Bonus
Company pension
Training budget 5000 EUR per year
Onboarding with hardware

Job summary

E.ON Drive Infrastructure seeks a senior information security governance, risk and compliance professional to lead a cross-country program from Germany, with milestones per market and regular reviews for managing directors.

You will own incident reporting, security policies, supplier assessments and the risk register, collaborating with Legal, Data Protection, Procurement and business leaders across our country organizations.

Qualifications

  • 5–8 years in information security governance, risk and compliance across multiple entities/countries
  • Background in IT operations, infrastructure, security operations or IT auditing
  • Experience assessing suppliers with SOC 2 or ISO 27001 evidence and evaluating responses
  • Ability to decide quickly if an incident is reportable with incomplete information
  • End-to-end compliance program leadership with senior stakeholders
  • Ability to explain obligations to managing directors clearly and concisely
  • Hands-on experience implementing NIS2, KRITIS or similar regulation across several countries
  • Fluent English; German a strong advantage for working with authorities
  • Based in Germany, ideally near Essen, with some travel
  • Experience in energy/OT/IoT or business continuity a plus

Responsibilities

  • Run IT security and compliance as one program across markets with milestones per country
  • Track cybersecurity regulations in each market and keep registrations current
  • Provide country managing directors with clear progress views
  • Maintain the risk register and report quarterly to management
  • Assess critical suppliers with procurement and security terms in contracts
  • Own incident reporting as escalation contact for the managed SOC
  • Own security policies and test key controls
  • Organize security training for management and awareness for all employees
  • Provide security evidence for tenders and audits
  • Scope and steer external specialists for penetration tests
  • Act as IT contact for business continuity and crisis management
  • Collaborate with Legal, Data Protection, Procurement, Product Owners and leaders across countries

Skills

Information security governance
Risk & compliance
Supplier assessment
Incident reporting
Policy ownership
Cross-country program
Stakeholder communication
Regulatory execution
English fluency

Education

ISO 27001 Lead Implementer/Auditor or equivalent
BSI IT-Grundschutz Practitioner or CISM/CISA (welcome)

Job description

Your mission
  • Run IT security and compliance as one program across all markets, with milestones per country
  • Track the cybersecurity regulation in each market and keep authority registrations current
  • Give every country managing director a clear, regular view of where they stand
  • Maintain the risk register and report to management quarterly
  • Assess our critical suppliers together with procurement and assess the security terms in their contracts
  • Own incident reporting as the escalation contact for our managed SOC
  • Own the security policies and test that key controls work
  • Organize security training for management and awareness for all employees
  • Provide the security evidence for tenders and audits
  • Scope and steer external specialists for penetration tests and technical work
  • Act as IT contact for business continuity and crisis management

This is a senior individual contributor role within our central IT team, offering significant ownership and accountability without direct people management responsibilities.
You will collaborate closely with Legal, Data Protection, Procurement, Product Owners, and business leaders across our country organizations. Security Operations, Workplace IT, and Data Protection are managed by dedicated specialist teams and partners.

Your profile
  • Five to eight years in information security governance, risk and compliance, ideally in a group with several legal entities or countries
  • Your career started in IT operations, infrastructure, security operations or IT audit, so you know how systems fail and how controls are bypassed in practice
  • You have assessed suppliers beyond the questionnaire: worked through SOC 2 or ISO 27001 evidence, followed up exceptions and judged whether a vendor's answer holds up
  • You can decide within hours, with incomplete information, whether an incident is reportable and to whom
  • You have run a compliance program end to end: plan, milestones, status reporting and closure, with senior stakeholders who were not security experts
  • You build trust with managing directors. You explain what an obligation means for them, what it costs and what you need, in a few minutes and without jargon
  • Hands‑on experience implementing NIS2, KRITIS or comparable cybersecurity regulation, ideally across several countries
  • ISO 27001 Lead Implementer or Lead Auditor, or BSI IT- Grundschutz Practitioner. CISM or CISA is welcome
  • Fluent English. German is a strong advantage for working with the BSI
  • Based in Germany, ideally within reach of Essen, with occasional travel to our markets
  • A plus: experience in energy, OT or IoT environments, or with business continuity
Why us?
  • People take centre stage: Become part of a dynamic, ambitious and agile team that develops solutions for the eMobility market and be part of our EDRI events or the next after-work event
  • With us, you get the best of both worlds - 100% start-up with the support of a large company
  • The freedom you need: We offer you hybrid working with flexible working hours
  • Workation: Enjoy the flexibility to work temporarily from abroad – within the EU
  • You will receive a competitive salary with a performance-related bonus
  • A company pension scheme is of course also one of the benefits with us
  • Sustainable learning opportunities: We support you with a training budget of 5,000 euros per year
  • You get everything you need to get started: onboarding with welcome gifts and all the hardware you need
Contact

Diversity counts at E.ON. We welcome all people and are convinced that differences make us stronger. Become part of our inclusive and diverse corporate culture! Seize the opportunity to become part of our E.ON Drive Infrastructure team and not only create prospects for the future of E.ON, but also for your own. We look forward to getting to know you! Laura Junior Recruiter

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security & Compliance Program Lead (m/f/d)
IT Security & Compliance Program Lead (m/f/d)

E.ON Drive Infrastructure GmbH • Essen

Hybrid
EUR 90,000 - 130,000
Hybrid working
Competitive salary with bonus
€5,000 training budget per year
+2
Information Security & Compliance Manager (m/f/d) E.ON Drive Infrastructure GmbH
Information Security & Compliance Manager (m/f/d) E.ON Drive Infrastructure GmbH

E.ON Energie Deutschland GmbH • Essen

Hybrid
EUR 90,000 - 130,000
HSE Officer (m/f/d)
HSE Officer (m/f/d)

E.ON Drive Infrastructure GmbH • Essen

Hybrid
EUR 65,000 - 100,000
Hybrid working
Flexible working hours
Travel across 11 countries
+4
HSE Officer (m/f/d)
HSE Officer (m/f/d)

Edri • Essen

Hybrid
EUR 90,000 - 120,000
Hybrid working
Training budget €5,000 per year
Company pension
+3
Senior Physical Security Specialist (f/m/d)
Senior Physical Security Specialist (f/m/d)

E.ON Digital Technology • Hannover

On-site
EUR 60,000 - 80,000
30 days of paid vacation
Company-sponsored health membership
Pension scheme
+1
Physical Security Specialist (f/m/d)
Physical Security Specialist (f/m/d)

E.ON Digital Technology • Hannover

On-site
EUR 60,000 - 80,000
30 days of paid vacation
Health membership
Company pension scheme
+2
Physical Security Specialist (f/m/d)
Physical Security Specialist (f/m/d)

E.ON Digital Technology • Essen

On-site
EUR 65,000 - 95,000
30 days vacation + holidays
Hybrid work
Company pension
+2
Senior Physical Security Specialist (f/m/d)
Senior Physical Security Specialist (f/m/d)

E.ON Digital Technology • Essen

On-site
EUR 70,000 - 90,000
30 days paid vacation
Health membership
Car and bike leasing offers
+1
Senior Crisis Management Specialist (f/m/d)
Senior Crisis Management Specialist (f/m/d)

E.ON Digital Technology • Hannover

On-site
EUR 70,000 - 90,000
30 days of paid vacation
Company-sponsored health membership
Flexible working hours
+2
Senior Crisis Management Specialist (f/m/d)
Senior Crisis Management Specialist (f/m/d)

Arbeitsagentur • Essen

On-site
EUR 90,000 - 120,000
30 days paid vacation
Sabbatical option
Hybrid work model
+5