Du entwickelst Sicherheitsrichtlinien und stellst die Einhaltung von Vorschriften wie GDPR und ISO 27001 sicher, während du auch Risikoanalysen durchführst.
Anforderungen
- •Degree in Information Security
- •8-10 years of experience
- •3-5 years leading teams
- •Proven information security governance experience
- •Familiarity with ISO 27001
- •Strong understanding of risk assessment methodologies
- •Excellent analytical and problem-solving skills
- •Ability to work independently and collaboratively
- •Relevant certifications like CISSP
- •Experience in third-party risk management
- •Knowledge of cloud security governance frameworks
- •Previous experience conducting security awareness programs
- •Familiarity with GRC tools
Deine Aufgaben
- •Information security policies entwickeln und umsetzen
- •Compliance mit GDPR, ISO 27001 und NIST sicherstellen
- •Risikoanalysen durchführen und Gegenmaßnahmen empfehlen
- •Mit internen Teams zur Ausrichtung der Sicherheitsrichtlinien zusammenarbeiten
- •Sicherheitsmetriken und Compliance-Status an das Management berichten
- •Schulungen zur Sensibilisierung für Sicherheit durchführen
- •Interne und externe Audits unterstützen und Dokumentation vorbereiten
- •Mit rechtlichen und Compliance-Teams zusammenarbeiten
Deine Vorteile
Flache Hierarchien
Mobiles Arbeiten
Original Beschreibung
Date:
May 6, 2025
Location:
Salzgitter, DE
Level of Experience:
Management
Job Function:
Information Technology
Job ID:
3702
# Manager of Information Security Governance (all genders)
| |
| --- |
| **About the Role** |
| * Developing, implementing, and maintaining information security policies, standards, and guidelines * Ensuring compliance with relevant regulations such as GDPR, ISO 27001, NIST, and other industry-specific frameworks * Conducting risk assessments to identify vulnerabilities and recommend appropriate mitigation strategies * Collaborating with internal teams to ensure alignment between security policies and business objectives * Monitoring and reporting on key security metrics and compliance posture to senior management * Providing security awareness training and workshops for employees to promote a culture of security * Supporting internal and external audits by preparing necessary documentation and responses * Working with legal and compliance teams to ensure regulatory requirements are met |
| **Key Responsibilities** |
| * Degree in Information Security, Cybersecurity, Computer Science, or a related field * 8-10 years of experience in an IT Security environment * 3-5 years of experience leading teams * Proven experience in information security governance, compliance, and risk management * Familiarity with industry frameworks such as ISO 27001, NIST, CIS Controls, and regulatory requirements like GDPR, SOX, or HIPAA * Strong understanding of risk assessment methodologies and compliance auditing * Excellent analytical, problem-solving, and stakeholder management skills * Ability to work independently and collaboratively in a fast-paced environment |
| **What you bring to the Team** |
| * Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor * Experience in third-party risk management and vendor assessments * Knowledge of cloud security governance (e.g., AWS, Azure security frameworks) * Previous experience conducting security awareness programs * Familiarity with GRC tools (Governance, Risk, and Compliance) |
| **Power Perks** |
| Flat hierarchies Mobile work options |
## Diversity, Equity and Inclusion
We believe that the best results are created in a diverse and inclusive environment.
Therefore, all qualified applications will be considered for employment regardless of age, race, religion, gender (identity), sexual orientation, national origin or disability.