Your personal AI career agent
Head of Security Certification Management(m/w/x)
Building Compliance-as-Code culture for SMB digitalization services, leading 10+ direct and 50+ indirect GRC team. Senior Tech Leadership, 5+ years GRC/Security, and 3-year GRC roadmap definition required. Hybrid work, flexible hours, subsidized canteen.
Requirements
- Senior Tech Leadership
- 5+ years in GRC/Security
- Ideally experience in Hosting, SaaS, or Cloud sectors
- Understanding of operational vs. paper ISMS
- Ability to define 3-year GRC maturity roadmap
- Moving organization from reactive to proactive GRC
- Hands-on experience with ISO 27001, NIS2 & BCM
- Ability to map frameworks to avoid double work
- Successful navigation of ISO27001/KRITIS audits
- Preparation or implementation of NIS2 strategies
- Preference for GRC tools (e.g., Auditboard) over Excel
- Understanding of using APIs to pull compliance evidence from Jira
- Vision for AI enhancing GRC best practices
- Familiarity with AI tools and applications
- People Management Experience
- Ability to build network in 10+ locations
- Experience reporting to all management levels
Tasks
- Build a Compliance-as-Code culture.
- Drive the organization to proactive, risk-driven compliance.
- Mentor a distributed GRC team.
- Lead a distributed GRC team of 10+ direct FTEs.
- Lead an indirect organization of 50+ people.
- Transition the team to automated, data-driven oversight.
- Design the end-to-end ISMS lifecycle.
- Implement the end-to-end ISMS lifecycle.
- Continuously improve the end-to-end ISMS lifecycle.
- Lead the team to architect a unified IMS.
- Bridge ISMS, Risk Management, and BCM within the IMS.
- Act as the primary interface for the BSI.
- Implement NIS2 across international brands and products.
- Implement KRITIS across international brands and products.
- Drive ISO27001 re-certifications.
- Drive TKG and BSIG (KRITIS) audits.
- Move towards continuous compliance.
- Develop real-time dashboards for executive reporting.
- Refine vendor risk management.
- Meet NIS2 and CRA requirements for vendor risk.
- Integrate ML algorithms with Development teams.
- Leverage AI tools for customer-facing operations.
- Leverage AI tools for internal workflows.
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Native
- English – Business Fluent
Tools & Technologies
- ISO 27001
- NIS2
- BCM
- KRITIS
- Auditboard
- Excel
- APIs
- Jira
- Artificial Intelligence
Benefits
Flexible Working
- Hybrid working model
- Home office option
- Flexible working hours
Free or Subsidized Food
- Subsidized canteen
Snacks & Drinks
- Free drinks
Modern Office
- Modern office space
Parking & Commuter Benefits
- Good transport connections
Corporate Discounts
- Employee discounts
Team Events
- Employee events
Learning & Development
- Workshops
- Training opportunities
- Development opportunities
Healthcare & Fitness
- Sports courses
- Health courses
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
Not a perfect match?
- IONOS SEFull-timeWith HomeofficeManagementBerlin
- IONOS DE
Head of Service & Security Management - Cloud(m/w/x)
Full-timeWith HomeofficeManagementBerlin - IONOS SE
Cloud Security Manager - Cyber Security(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - Moss
Information Security GRC Lead(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - Delivery Hero
Senior Manager, Infrastructure Security(m/w/x)
Full-timeWith HomeofficeSeniorBerlin
Head of Security Certification Management(m/w/x)
Building Compliance-as-Code culture for SMB digitalization services, leading 10+ direct and 50+ indirect GRC team. Senior Tech Leadership, 5+ years GRC/Security, and 3-year GRC roadmap definition required. Hybrid work, flexible hours, subsidized canteen.
Requirements
- Senior Tech Leadership
- 5+ years in GRC/Security
- Ideally experience in Hosting, SaaS, or Cloud sectors
- Understanding of operational vs. paper ISMS
- Ability to define 3-year GRC maturity roadmap
- Moving organization from reactive to proactive GRC
- Hands-on experience with ISO 27001, NIS2 & BCM
- Ability to map frameworks to avoid double work
- Successful navigation of ISO27001/KRITIS audits
- Preparation or implementation of NIS2 strategies
- Preference for GRC tools (e.g., Auditboard) over Excel
- Understanding of using APIs to pull compliance evidence from Jira
- Vision for AI enhancing GRC best practices
- Familiarity with AI tools and applications
- People Management Experience
- Ability to build network in 10+ locations
- Experience reporting to all management levels
Tasks
- Build a Compliance-as-Code culture.
- Drive the organization to proactive, risk-driven compliance.
- Mentor a distributed GRC team.
- Lead a distributed GRC team of 10+ direct FTEs.
- Lead an indirect organization of 50+ people.
- Transition the team to automated, data-driven oversight.
- Design the end-to-end ISMS lifecycle.
- Implement the end-to-end ISMS lifecycle.
- Continuously improve the end-to-end ISMS lifecycle.
- Lead the team to architect a unified IMS.
- Bridge ISMS, Risk Management, and BCM within the IMS.
- Act as the primary interface for the BSI.
- Implement NIS2 across international brands and products.
- Implement KRITIS across international brands and products.
- Drive ISO27001 re-certifications.
- Drive TKG and BSIG (KRITIS) audits.
- Move towards continuous compliance.
- Develop real-time dashboards for executive reporting.
- Refine vendor risk management.
- Meet NIS2 and CRA requirements for vendor risk.
- Integrate ML algorithms with Development teams.
- Leverage AI tools for customer-facing operations.
- Leverage AI tools for internal workflows.
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Native
- English – Business Fluent
Tools & Technologies
- ISO 27001
- NIS2
- BCM
- KRITIS
- Auditboard
- Excel
- APIs
- Jira
- Artificial Intelligence
Benefits
Flexible Working
- Hybrid working model
- Home office option
- Flexible working hours
Free or Subsidized Food
- Subsidized canteen
Snacks & Drinks
- Free drinks
Modern Office
- Modern office space
Parking & Commuter Benefits
- Good transport connections
Corporate Discounts
- Employee discounts
Team Events
- Employee events
Learning & Development
- Workshops
- Training opportunities
- Development opportunities
Healthcare & Fitness
- Sports courses
- Health courses
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
About the Company
IONOS SE
Industry
IT
Description
The company is the leading European digitalization partner for small and medium-sized businesses, offering a range of cloud and hosting services.
Not a perfect match?
- IONOS SE
Head of Service & Security Management - Cloud(m/w/x)
Full-timeWith HomeofficeManagementBerlin - IONOS DE
Head of Service & Security Management - Cloud(m/w/x)
Full-timeWith HomeofficeManagementBerlin - IONOS SE
Cloud Security Manager - Cyber Security(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - Moss
Information Security GRC Lead(m/w/x)
Full-timeWith HomeofficeExperiencedBerlin - Delivery Hero
Senior Manager, Infrastructure Security(m/w/x)
Full-timeWith HomeofficeSeniorBerlin