INFORMATION SECURITY MANAGER
Orcristtechnologies
mid
Sign in to applyFree account, takes a minute.
Job description
<h2><strong>The Role</strong></h2>
<p>As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.</p>
<p>We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.</p>
<h2><strong>Your Responsibilities</strong></h2>
<ul>
<li>Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis</li>
<li>Create and maintain the security policy framework and processes at group level; coordinate company-specific additions</li>
<li>Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors</li>
<li>Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking</li>
<li>Manage risk across technical and organizational domains, including reporting to executive management</li>
<li>Steer external consultants and service providers within the running programme</li>
<li>Build and run the security awareness programme: training and sensitization</li>
<li>Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership</li>
<li>Assess third-party and vendor risk, run security assessments for new tools and partners</li>
<li>Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)</li>
<li>Support sales and customer trust processes: security questionnaires, due diligence, customer audits</li>
<li>Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action</li>
</ul>
<h2><strong>What You Bring</strong></h2>
<ul>
<li>Several years of experience as an ISB or in comparable responsibility for information security</li>
<li>Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure</li>
<li>Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness</li>
<li>Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences</li>
<li>Willingness to work hands-on during the build-up phase</li>
<li>Confident interaction with executive management, auditors, and customers</li>
<li>German at C1 or above, English at B2 or above</li>
</ul>
<h2><strong>Nice to Have</strong></h2>
<ul>
<li>Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM</li>
<li>Experience with security governance across multiple legal entities or jurisdictions</li>
<li>Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP</li>
<li>Practical NIS-2 implementation experience</li>
<li>Experience with sales-adjacent security processes (pre-sales, customer audits)</li>
</ul>
<h2><strong>What We Offer</strong></h2>
<ul>
<li>International team with colleagues across Germany and other locations.</li>
<li>Startup environment with real ownership, flat hierarchies, and fast decisions.</li>
<li>Competitive compensation aligned with experience and responsibility.</li>
<li>Individual learning and growth opportunities beyond your role.</li>
</ul>
Skills
BSI IT-GrundschutzISO 27001NIS-2Risk ManagementIncident ResponseThird-Party Risk AssessmentSecurity Awareness TrainingSecurity Policy DevelopmentInternal AuditsExternal Auditors CoordinationIT-Grundschutz-PraktikerIT-Grundschutz-BeraterISO 27001 Lead ImplementerISO 27001 Lead AuditorCISSPCISMVS-NfDGeheimschutzAQAPEU AI ActCyber Resilience Act