Information Security Manager (w/m/d)

JTL-Software GmbH

United States

Remote

USD 134,000 - 202,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote-first in Germany
Meal allowance
Home office setup support
Team events

Job summary

JTL-Software GmbH is seeking an experienced ISMS lead to own and defend ISO/IEC 27001:2022 across the organization. The role focuses on audits, policy development, risk management, and security awareness in a remote-first structure.

You will coordinate with security teams to maintain compliance, manage the risk register, and act as the primary contact for security assessments and due diligence from customers and investors. English fluency is required.

Qualifications

  • You have personally owned an ISO/IEC 27001 ISMS and defended it before an external auditor.
  • You have planned and run internal audits and driven findings to closure.
  • You have written policy and control frameworks and operated an ISMS for at least one year.
  • You have run a risk register with real treatment and acceptance decisions.
  • You are fluent in English, written and spoken.

Responsibilities

  • Run and maintain the ISO/IEC 27001:2022 ISMS: scope, Statement of Applicability, control ownership, management review.
  • Prepare for and defend certification, surveillance and recertification audits.
  • Keep the evidence base current and repeatable for audits.
  • Plan and run internal audits against the control set.
  • Write findings that are specific and drive closure with control owners.
  • Own the policy and standard framework: authorship, review, publication, versioning.
  • Run the cyber risk register: assessment, treatment plans, acceptance decisions.
  • Act as single point of contact for customer security assessments and due diligence.
  • Design and run the security awareness programme, including role-based training.

Skills

ISO27001 ownership
Internal audits
Policy framework
Risk management
Technical controls
Fluent English

Job description

Your mission

JTL-Software runs e-commerce software that our customers run their businesses on. Customers, partners and stakeholders trust in JTL to secure their information.
This role runs JTLs information security management system end to end: the ISO/IEC 27001:2022 ISMS, the internal audit programme, the policy and standard framework, the cyber risk register, and security awareness across the company. The goal is to demonstrate, that JTL successfully has established processes to continuously improve its security capabilities.
This is a hands‑on role in the security team without management responsibility.

ISMS ownership
  • Run and maintain the ISO/IEC 27001:2022 management system: scope, Statement of Applicability, control ownership, management review
  • Prepare for and defend certification, surveillance and recertification audits
  • Keep the evidence base current and collectible, and make it repeatable rather than a scramble before each audit
Internal audit
  • Plan and run the internal audit programme against the control set
  • Write findings that are specific enough to act on, and drive them to closure with the control owners
  • Provide factual assurance to the management team
Policy and standards
  • Own the policy and standard framework: authorship, review cycle, approval, publication, versioning
Risk management
  • Run the cyber risk register: assessment, treatment plans, acceptance decisions, review cadence
External assurance
  • Act as the single point of contact for customer security assessments, questionnaires and due diligence
  • Run the response cycle for our investor's portfolio-wide cyber assessment
  • Manage third-party and vendor security assessments, and the security half of the vendor onboarding process
Awareness and training
  • Design and run the security awareness programme, including role-based training
  • Measure whether it changed anything, and change it when it did not
Your profile
  • You have personally owned an ISO/IEC 27001 ISMS and defended it in front of an external auditor, through certification, recertification or surveillance. Only advising or having provided implementation guidance is not enough for this role.
  • You have planned and run internal audits, written the findings, and driven them to closure
  • You have written a policy and control framework and then operated an ISMS on it for at least a year
  • You have run a risk register where real treatment and acceptance decisions were made
  • technical literacy to look at control evidence from an engineer and tell whether it proves the control
  • Fluent English, written and spoken
Why us?
  • Remote-first within Germany, with the option to work remotely from eligible countries for up to 180 days per year
  • Meal allowance of up to €115 net per month
  • Ergonomic workspace allowance for your home office setup
  • Regular team events, company-wide gatherings, and summer and Christmas parties to stay connected as a remote-first company
  • EGYM Wellpass and JobRad subsidy
  • Financial benefits including capital-forming payments (Vermögenswirksame Leistungen) and a company pension scheme
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Engineer - Detection & Response (w/m/d)
Staff Security Engineer - Detection & Response (w/m/d)

JTL-Software GmbH • United States

Remote
USD 135,000 - 203,000
Meal allowance
Home office setup
Wellpass
+4
Senior Network & Infrastructure Engineer (f/m/d)
Senior Network & Infrastructure Engineer (f/m/d)

JTL-Software GmbH • United States

Remote
USD 78,000 - 101,000
Meal allowance
Ergonomic home office stipend
Team events
+3
ISMS Specialist: Security Assurance & Compliance
ISMS Specialist: Security Assurance & Compliance

JTL-Software GmbH • United States

Remote
USD 134,000 - 202,000
Remote-first in Germany
Meal allowance
Home office setup support
+1
Senior Product Designer (f/m/d)
Senior Product Designer (f/m/d)

JTL-Software GmbH • United States

Remote
USD 90,000 - 130,000
Meal allowance
Home-office stipend
Team events
+5
IT Security & Compliance Program Lead (m/f/d)
IT Security & Compliance Program Lead (m/f/d)

E.ON Drive Infrastructure GmbH • United States

Hybrid
USD 123,000 - 179,000
Hybrid work model
Training budget
Company pension
Information Security Lead
Information Security Lead

Secfix • United States

On-site
USD 180,000 - 240,000
Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
+6
Senior QA Engineer (w/m/d)
Senior QA Engineer (w/m/d)

JTL-Software GmbH • United States

Remote
USD 81,000 - 127,000
Meal allowance
Home office setup
Team events
+4
Information Security Consultant (m/w/d)
Information Security Consultant (m/w/d)

Heartland Solutions GmbH • United States

On-site
Confidential
100 % Remote-Arbeit
Optionale 4-Tage-Woche
Langfristige Entwicklungsperspektiven
Information Security, Compliance & IKS Manager (m/w/d) - ISO 27001 - Teilzeit
Information Security, Compliance & IKS Manager (m/w/d) - ISO 27001 - Teilzeit

Cloudiax AG • United States

On-site
USD 101,000 - 146,000
Remote-Arbeitsplatz
Gehalt & Boni
Urlaub 30 Tage
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist Group • United States

Hybrid
USD 120,000 - 180,000
Impact & Ownership
Flexibility: Hybrid across Berlin &amp
Personal growth
+1