Your personal AI career agent
IT Compliance & Information Security Manager(m/w/x)
Developing and operating an ISMS for a European SaaS provider, translating ISO 27001, NIS2, and DORA guidelines into processes. Practical ISMS experience according to ISO/IEC 27001 required. Hybrid work, job ticket, and jobrad leasing.
Requirements
- Professional experience in information security, IT compliance, IT risk management, IT audit, or GRC
- Practical experience with ISMS according to ISO/IEC 27001
- Good understanding of DORA, NIS2, GDPR, and comparable frameworks
- Experience in preparing for and supporting audits and reviews
- Ability to translate regulatory requirements into pragmatic processes, controls, and measures
- Strong communication skills in German and English
- Structured, well-documented, and implementation-oriented approach
- High degree of personal responsibility
- Certifications like ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or comparable qualifications are desirable
Tasks
- Manage and develop Information Security Management System (ISMS)
- Ensure compliance with regulatory, legal, and customer requirements
- Coordinate documentation and audits for ISMS
- Translate ISO 27001, NIS2, DORA, SOC/audit, and AI governance guidelines into processes
- Operate and enhance ISMS based on ISO/IEC 27001
- Develop robust policies, standards, controls, and evidence
- Analyze new regulatory requirements
- Translate regulatory requirements into concrete measures and roadmaps
- Coordinate internal and external audits and certifications
- Prepare supporting documentation for audits
- Serve as primary point of contact for auditors, customers, and management
- Conduct risk analyses and assess control gaps
- Track measures to sustainable implementation
- Collaborate with Engineering, Cloud Operations, Legal, Data Protection, and Product teams
- Maintain and improve IT-related internal control system
- Perform documentation, effectiveness checks, and exception handling
- Provide management reporting
- Evaluate service providers and cloud providers for compliance and security
- Plan and coordinate awareness and training initiatives
- Support structured classification of AI use cases and systems
- Ensure compliance with EU AI Act requirements
Work Experience
- approx. 1 - 4 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Business Fluent
- English – Business Fluent
Tools & Technologies
- ISO/IEC 27001
- DORA
- NIS2
- GDPR
Benefits
Flexible Working
- Hybrid work model
Modern Equipment
- Modern tools and equipment
Parking & Commuter Benefits
- Free parking
Public Transport Subsidies
- Job Ticket
Company Bike
- JobRad leasing
Healthcare & Fitness
- Urban Sports membership
Snacks & Drinks
- Fresh fruit
- Drinks
Free or Subsidized Food
- Meal subsidies
Mentorship & Coaching
- Structured onboarding
Learning & Development
- Training programs
- Language courses
Informal Culture
- Friendly team spirit
Other Benefits
- Clear structures
Team Events
- Regular team events
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
Not a perfect match?
- dgrp Diconium Group GmbHFull-timeWith HomeofficeManagementStuttgart
- CANCOM
Information Security Manager(m/w/x)
Full-timeWith HomeofficeManagementMünchen, Berlin, Frankfurt am Main, Langenfeld (Rheinland), Leipzig, Stuttgart, Hannover, Aachen, Hamburg, Köln - Flip App
GRC Analyst(m/w/x)
Full-timeWith HomeofficeExperiencedStuttgart, Berlin - Flip GmbH
GRC Analyst(m/w/x)
Full-timeWith HomeofficeExperiencedStuttgart, Berlin - Creditplus Bank
Senior IT Security Manager(m/w/x)
Full-timeWith HomeofficeSeniorStuttgart
IT Compliance & Information Security Manager(m/w/x)
Developing and operating an ISMS for a European SaaS provider, translating ISO 27001, NIS2, and DORA guidelines into processes. Practical ISMS experience according to ISO/IEC 27001 required. Hybrid work, job ticket, and jobrad leasing.
Requirements
- Professional experience in information security, IT compliance, IT risk management, IT audit, or GRC
- Practical experience with ISMS according to ISO/IEC 27001
- Good understanding of DORA, NIS2, GDPR, and comparable frameworks
- Experience in preparing for and supporting audits and reviews
- Ability to translate regulatory requirements into pragmatic processes, controls, and measures
- Strong communication skills in German and English
- Structured, well-documented, and implementation-oriented approach
- High degree of personal responsibility
- Certifications like ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or comparable qualifications are desirable
Tasks
- Manage and develop Information Security Management System (ISMS)
- Ensure compliance with regulatory, legal, and customer requirements
- Coordinate documentation and audits for ISMS
- Translate ISO 27001, NIS2, DORA, SOC/audit, and AI governance guidelines into processes
- Operate and enhance ISMS based on ISO/IEC 27001
- Develop robust policies, standards, controls, and evidence
- Analyze new regulatory requirements
- Translate regulatory requirements into concrete measures and roadmaps
- Coordinate internal and external audits and certifications
- Prepare supporting documentation for audits
- Serve as primary point of contact for auditors, customers, and management
- Conduct risk analyses and assess control gaps
- Track measures to sustainable implementation
- Collaborate with Engineering, Cloud Operations, Legal, Data Protection, and Product teams
- Maintain and improve IT-related internal control system
- Perform documentation, effectiveness checks, and exception handling
- Provide management reporting
- Evaluate service providers and cloud providers for compliance and security
- Plan and coordinate awareness and training initiatives
- Support structured classification of AI use cases and systems
- Ensure compliance with EU AI Act requirements
Work Experience
- approx. 1 - 4 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- German – Business Fluent
- English – Business Fluent
Tools & Technologies
- ISO/IEC 27001
- DORA
- NIS2
- GDPR
Benefits
Flexible Working
- Hybrid work model
Modern Equipment
- Modern tools and equipment
Parking & Commuter Benefits
- Free parking
Public Transport Subsidies
- Job Ticket
Company Bike
- JobRad leasing
Healthcare & Fitness
- Urban Sports membership
Snacks & Drinks
- Fresh fruit
- Drinks
Free or Subsidized Food
- Meal subsidies
Mentorship & Coaching
- Structured onboarding
Learning & Development
- Training programs
- Language courses
Informal Culture
- Friendly team spirit
Other Benefits
- Clear structures
Team Events
- Regular team events
Like this job?
BetaYour Career Agent finds similar jobs for you every day.
About the Company
Onventis
Industry
IT
Description
Das Unternehmen ist seit 2000 Cloud-Pionier für die digitale Transformation von Einkaufs- und Finanzprozessen.
Not a perfect match?
- dgrp Diconium Group GmbH
Information Security Manager(m/w/x)
Full-timeWith HomeofficeManagementStuttgart - CANCOM
Information Security Manager(m/w/x)
Full-timeWith HomeofficeManagementMünchen, Berlin, Frankfurt am Main, Langenfeld (Rheinland), Leipzig, Stuttgart, Hannover, Aachen, Hamburg, Köln - Flip App
GRC Analyst(m/w/x)
Full-timeWith HomeofficeExperiencedStuttgart, Berlin - Flip GmbH
GRC Analyst(m/w/x)
Full-timeWith HomeofficeExperiencedStuttgart, Berlin - Creditplus Bank
Senior IT Security Manager(m/w/x)
Full-timeWith HomeofficeSeniorStuttgart