IT Security & Compliance Program Lead (m/f/d)

E.ON Drive Infrastructure GmbH

United States

Hybrid

USD 123,000 - 179,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Training budget
Company pension

Job summary

E.ON Drive Infrastructure GmbH seeks a senior information security governance lead to run risk, compliance and supplier security across markets. You will partner with Legal, Data Protection, Procurement and business leaders, manage incident reporting, maintain the risk register and support audits.

You will drive NIS2, ISO 27001 and related controls, organize security training, and provide evidence for tenders and audits.

Qualifications

  • Experience leading information security governance, risk and compliance programs across multiple entities.
  • Proven ability to drive regulatory programs (NIS2, ISO 27001) and supplier security.
  • Fluent English; German is a strong advantage for working with local entities.

Responsibilities

  • Run IT security governance and compliance as a unified program across markets.
  • Maintain risk registers, report quarterly to management, and oversee incident escalation.
  • Coordinate security policies, training, audits and supplier assessments with cross-functional teams.

Skills

Information security governance
Risk management
Regulatory compliance
ISO 27001
CISM/CISA welcome
Fluent English

Education

ISO 27001 Lead Implementer
Lead Auditor
BSI IT-Grundschutz Practitioner
CISM or CISA

Job description

Your mission

Run IT security and compliance as one program across all markets, with milestones per country Track the cybersecurity regulation in each market and keep authority registrations current Give every country managing director a clear, regular view of where they stand Maintain the risk register and report to management quarterly Assess our critical suppliers together with procurement and assess the security terms in their contracts Own incident reporting as the escalation contact for our managed SOC Own the security policies and test that key controls work Organize security training for management and awareness for all employees Provide the security evidence for tenders and audits Scope and steer external specialists for penetration tests and technical work Act as IT contact for business continuity and crisis management This is a senior individual contributor role within our central IT team, offering significant ownership and accountability without direct people management responsibilities.
You will collaborate closely with Legal, Data Protection, Procurement, Product Owners, and business leaders across our country organizations. Security Operations, Workplace IT, and Data Protection are managed by dedicated specialist teams and partners.

Your profile

Five to eight years in information security governance, risk and compliance, ideally in a group with several legal entities or countries Your career started in IT operations, infrastructure, security operations or IT audit, so you know how systems fail and how controls are bypassed in practice You have assessed suppliers beyond the questionnaire: worked through SOC 2 or ISO 27001 evidence, followed up exceptions and judged whether a vendor's answer holds up You can decide within hours, with incomplete information, whether an incident is reportable and to whom You have run a compliance program end to end: plan, milestones, status reporting and closure, with senior stakeholders who were not security experts You build trust with managing directors. You explain what an obligation means for them, what it costs and what you need, in a few minutes and without jargon Hands‑on experience implementing NIS2, KRITIS or comparable cybersecurity regulation, ideally across several countries ISO 27001 Lead Implementer or Lead Auditor, or BSI IT‑Grundschutz Practitioner. CISM or CISA is welcome Fluent English. German is a strong advantage for working with the BSI Based in Germany, ideally within reach of Essen, with occasional travel to our markets A plus: experience in energy, OT or IoT environments, or with business continuity

Why us?

People take centre stage: Become part of a dynamic, ambitious and agile team that develops solutions for the eMobility market and be part of our EDRI events or the next after‑work event With us, you get the best of both worlds - 100% start-up with the support of a large company The freedom you need: We offer you hybrid working with flexible working hours Workation: Enjoy the flexibility to work temporarily from abroad – within the EU You will receive a competitive salary with a performance‑related bonus A company pension scheme is of course also one of the benefits with us Sustainable learning opportunities: We support you with a training budget of 5,000 euros per year You get everything you need to get started: onboarding with welcome gifts and all the hardware you need

Contact

Diversity counts at E.ON. We welcome all people and are convinced that differences make us stronger. Become part of our inclusive and diverse corporate culture!
Seize the opportunity to become part of our E.ON Drive Infrastructure team and not only create prospects for the future of E.ON, but also for your own.
We look forward to getting to know you!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global IT Security & Compliance Program Lead
Global IT Security & Compliance Program Lead

E.ON Drive Infrastructure GmbH • United States

Hybrid
USD 123,000 - 179,000
Hybrid work model
Training budget
Company pension
Head of Security (f/m/d)
Head of Security (f/m/d)

1KOMMA5° • United States

Remote
USD 134,000 - 202,000
Remote work Germany-wide
Flexible Arbeitszeiten
Jobbike Leasing
Senior Information Security Specialist
Senior Information Security Specialist

Daikin Group • Town of Belgium (WI)

On-site
USD 120,000 - 170,000
Competitive salary
Training and support
Benefits package
+1
Senior IT Security Engineer (m/f/d)
Senior IT Security Engineer (m/f/d)

EMnify GmbH • United States

Remote
USD 100,000 - 140,000
Regular company events
30 days holidays
Free in-house German lessons
+5
Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 180,000 - 240,000
Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
+6
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist Group • United States

Hybrid
USD 120,000 - 180,000
Impact & Ownership
Flexibility: Hybrid across Berlin &amp
Personal growth
+1
Internship Global Product Management (m/f/d)
Internship Global Product Management (m/f/d)

1KOMMA5° • United States

Remote
USD 90,000 - 130,000
Remote work Germany-wide
Offices in Hamburg/Berlin/Munich
EGYM Wellpass
Governance, Risk & Assurance Manager (m/f/d)
Governance, Risk & Assurance Manager (m/f/d)

Fujitsu Limited • Augsburg (IL)

On-site
USD 101,000 - 135,000
Flexible working hours
30 days annual leave
Health and well-being programs
+2
Global Information Security Lead 100% (f/m/d)
Global Information Security Lead 100% (f/m/d)

Screening Eagle Technologies AG • Indiana (PA)

On-site
USD 90,000 - 120,000
Competitive remuneration package
Team building events
Opportunities for professional development
+1
Staff Security Engineer - Detection & Response (w/m/d)
Staff Security Engineer - Detection & Response (w/m/d)

JTL-Software GmbH • United States

Remote
USD 135,000 - 203,000
Meal allowance
Home office setup
Wellpass
+4