InfoSec & Risk Manager — ISO 27001, DORA, Audits

Qwist Group

United States

Hybrid

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Impact & Ownership
Flexibility: Hybrid across Berlin &amp
Personal growth
Pioneering spirit

Job summary

Qwist Group is seeking an Information Security Manager to own the ISMS under ISO 27001 and lead the ICT Risk Management Function under DORA. You will work closely with Engineering and Platform to embed security into development and serve as the central point for audits.

You will drive risk assessment, incident classification, third‑party risk oversight, and business continuity planning, reporting to the Management Board and collaborating with the Chief Legal Officer.

Qualifications

  • Degree or qualification in information security, CS, law/compliance or equivalent.
  • Hands-on ISO 27001 ISMS ownership including documentation and controls.
  • Experience collaborating with software engineering, product or DevOps teams.
  • Knowledge of DORA; exposure to MaRisk or similar frameworks welcome.
  • Strong analytical thinking and ability to manage multiple topics and stakeholders.
  • Proficient in German and English, with technical and non-technical audiences.

Responsibilities

  • Hold the ICT Risk Management Function under DORA and classify ICT incidents.
  • Develop and operate the ISO 27001 ISMS and lead certification and surveillance audits.
  • Own audit evidence for DORA and ISO 27001; coordinate with internal and external audits.
  • Embed security into development with Engineering, Platform and DevOps.
  • Support business continuity and disaster recovery planning with testing.
  • Assess and classify ICT services under DORA and oversee third parties.
  • Lead security operations including penetration testing and incident response.

Skills

Security mindset
Analytical thinking
Stakeholder management
German & English communication

Education

Degree in information security, CS, law/compliance

Job description

Qwist Group is seeking an Information Security Manager to own the ISMS under ISO 27001 and lead the ICT Risk Management Function under DORA. You will work closely with Engineering and Platform to embed security into development and serve as the central point for audits.

You will drive risk assessment, incident classification, third‑party risk oversight, and business continuity planning, reporting to the Management Board and collaborating with the Chief Legal Officer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Governance Lead - ISO 27001 & DORA
Security Governance Lead - ISO 27001 & DORA

Alan • United States

Remote
USD 150,000 - 230,000
Senior GRC ISMS Security Analyst - ISO 27001 & IAM Lead
Senior GRC ISMS Security Analyst - ISO 27001 & IAM Lead

Dorsey & Whitney LLP • Washington

On-site
USD 114,000 - 148,000
Comprehensive medical insurance
Dental insurance
Vision insurance
+2
Senior Risk & Controls Manager (ISO27001/SOC2)
Senior Risk & Controls Manager (ISO27001/SOC2)

HireHi • United States

Remote
USD 150,000 - 206,000
Remote Infosec & GRC Leader - ISO27001 & Risk
Remote Infosec & GRC Leader - ISO27001 & Risk

Avantdigitalnow • San Francisco (CA)

Remote
USD 95,000 - 130,000
ISO 27001 InfoSec & Risk Leader
ISO 27001 InfoSec & Risk Leader

Colonial Group • Houston (TX)

On-site
USD 120,000 - 160,000
Senior Information Security Leader – ISO 27001 & GRC
Senior Information Security Leader – ISO 27001 & GRC

PS • El Segundo (CA)

Hybrid
USD 170,000 - 190,000
Medical benefits
Dental insurance
Vision insurance
+8
Information Security Officer: Risk & ISMS Leader
Information Security Officer: Risk & ISMS Leader

Toreon BV • Town of Belgium (WI)

On-site
USD 90,000 - 130,000
Infosec or GRC Leader
Infosec or GRC Leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 95,000 - 130,000
InfoSec Leader - ISO 27001/SOC 2 (SaaS)
InfoSec Leader - ISO 27001/SOC 2 (SaaS)

Staffbase • United States

Remote
USD 140,000 - 210,000
31 vacation days
Flexible working time
LTIP
Remote ISO 27001 Security Specialist — Controls Lead
Remote ISO 27001 Security Specialist — Controls Lead

GCS Recruitment • United States

Remote
USD 80,321 - 120,482