Job Description: IT-Compliance and Information Security Manager
Company: COMLINE Computer + Softwarelösungen SE, Aachen, Germany
At COMLINE, our most valuable asset is our employees. We value performance and personality, regardless of age, origin, gender, religion, sexual orientation, or disability. Recognized as a GREAT PLACE TO WORK, our colleagues describe COMLINE as fair, sustainable, competent, and innovative. We operate in the medium-sized business sector, combining security, flexibility, and speed for our approximately 500 employees and our clients, who trust us with current IT topics. Through consulting and services in Cloud Management, Microsoft, Automation, IoT, SAP S/4 HANA, and Software Development, we make our clients' IT future-proof, giving them a competitive edge.
Role Overview:
You will report directly to our Executive Board and will be responsible for implementing, developing, and monitoring COMLINE's comprehensive IT compliance program. Additionally, you will lead the company's information security strategy.
Key Responsibilities:
- Lead and oversee the ISMS, including regular audits and evaluations (internal and external audits, e.g., ISO 27001).
- Establish new ISMS and harmonize existing systems, including certification projects (e.g., ISO 27001).
- Handle additional tasks within the IT compliance context, such as organizing measures according to AI-Act.
- Identify and assess IT risks, developing strategies for risk mitigation.
- Review and evaluate internal controls and risk management processes.
- Initiate and monitor corrective actions and improvements.
- Train and sensitize employees regarding IT compliance and information security.
- Create and maintain documentation and reports on IT compliance and security.
- Monitor changes in legal and regulatory requirements and assess their impact.
- Advise management on IT compliance and information security issues.
Qualifications:
- Degree in Computer Science, Information Technology, Business Administration, or a related field.
- Several years of leadership experience in IT compliance and/or information security.
- Strong knowledge of ISO 27001, including audit experience; familiarity with other standards is a plus.
- Professional certifications such as CISA, CIA, or ISO 27001 Lead Auditor are advantageous.
- Experience in establishing and operating information security management systems with certification goals.
- Deep understanding of information security principles and practices.
- Excellent analytical and problem-solving skills.
- Strong communication skills and ability to work independently and in teams.
- Fluent German and English language skills.
- Willingness to travel occasionally.
Benefits:
- 30 days of vacation annually.
- Flexible work arrangements, including remote work and trust-based working hours.
- Opportunities for development and comprehensive training programs.
- Benefits such as Jobrad, fitness center allowances, and IT@home program (access to the latest technology and work equipment).
- A family-oriented environment with a flat hierarchy and quick decision-making processes.
- Work at one of the top employers in the ITK industry.