Back to jobs

INFORMATION SECURITY MANAGER

Orcristtechnologies
mid
Sign in to applyFree account, takes a minute.

Job description

<h2><strong>The Role</strong></h2> <p>As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.</p> <p>We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.</p> <h2><strong>Your Responsibilities</strong></h2> <ul> <li>Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis</li> <li>Create and maintain the security policy framework and processes at group level; coordinate company-specific additions</li> <li>Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors</li> <li>Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking</li> <li>Manage risk across technical and organizational domains, including reporting to executive management</li> <li>Steer external consultants and service providers within the running programme</li> <li>Build and run the security awareness programme: training and sensitization</li> <li>Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership</li> <li>Assess third-party and vendor risk, run security assessments for new tools and partners</li> <li>Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)</li> <li>Support sales and customer trust processes: security questionnaires, due diligence, customer audits</li> <li>Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action</li> </ul> <h2><strong>What You Bring</strong></h2> <ul> <li>Several years of experience as an ISB or in comparable responsibility for information security</li> <li>Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure</li> <li>Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness</li> <li>Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences</li> <li>Willingness to work hands-on during the build-up phase</li> <li>Confident interaction with executive management, auditors, and customers</li> <li>German at C1 or above, English at B2 or above</li> </ul> <h2><strong>Nice to Have</strong></h2> <ul> <li>Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM</li> <li>Experience with security governance across multiple legal entities or jurisdictions</li> <li>Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP</li> <li>Practical NIS-2 implementation experience</li> <li>Experience with sales-adjacent security processes (pre-sales, customer audits)</li> </ul> <h2><strong>What We Offer</strong></h2> <ul> <li>International team with colleagues across Germany and other locations.</li> <li>Startup environment with real ownership, flat hierarchies, and fast decisions.</li> <li>Competitive compensation aligned with experience and responsibility.</li> <li>Individual learning and growth opportunities beyond your role.</li> </ul>

Skills

BSI IT-GrundschutzISO 27001NIS-2Risk ManagementIncident ResponseThird-Party Risk AssessmentSecurity Awareness TrainingSecurity Policy DevelopmentInternal AuditsExternal Auditors CoordinationIT-Grundschutz-PraktikerIT-Grundschutz-BeraterISO 27001 Lead ImplementerISO 27001 Lead AuditorCISSPCISMVS-NfDGeheimschutzAQAPEU AI ActCyber Resilience Act