Remote job
Information Security Manager - Risk Management (m/f/d)
Job details
About this role
Role overview The Information Security Manager – Risk Management owns end-to-end information security risk across a group of entities, running the risk programme from initial triage through to the quarterly executive report. The role combines scenario-based quantitative risk analysis, third-party/supplier security assessments, and hands-on support for the internal control framework and external audits. It sits within the CISO area and partners closely with Cloud Operations, Engineering, Legal, Data Protection, Sales, and Customer Success.
Responsibilities - Triage reported security concerns, frame risk scenarios with Risk Owners, and facilitate estimation workshops with cross-functional stakeholders. - Drive the quantitative security risk model: estimate frequencies and losses, assign confidence ratings, compute expected annual loss, and run plausibility checks for consistency and traceability. - Assess treatment efficiency, prepare treatment and acceptance decisions, consolidate the risk portfolio each quarter, and co-produce the C-Level risk report with the CISO. - Manage supplier security risk across the full lifecycle, from scoping and questionnaires through SOC 2 reports, ISO certificates, contract clauses, and annual reassessments, linking findings back to the group risk portfolio. - Maintain the internal control framework and support internal and external audits (e.g. ISO 27001, SOC 2 Type 2), responding to customer due-diligence, RFP, and questionnaire requests on risk and supply chain security. - Act as sparring partner to the CISO, evolve the risk methodology, train Risk and Business Owners, and champion an open risk-reporting culture.
Requirements - Completed degree in information security, computer science, business informatics, or a related field. - Several years of hands-on experience in information security risk management, ideally using a structured or quantitative framework. - Working knowledge of common control and audit standards such as ISO 27001 and SOC 2, plus third-party/supplier risk management processes. - Confidence facilitating risk workshops and translating technical findings into clear language for executives and business owners. - Strong analytical and documentation skills, with the ability to make figures consistent, comparable, and traceable. - Excellent communication and stakeholder-management skills across engineering, legal, and commercial teams.
Nice to have - Familiarity with BCM (business continuity management) practices. - Experience preparing or contributing to C-Level or board-level risk reports.
Benefits and work setup - Mobile work and flexible hours in an internationally distributed team. - Free in-office Fairtrade coffee, snacks, fresh fruit, and subsidised lunches. - Sustainable travel options including a leased e-bike, and free e-car charging on site. - Subsidised company pension plan and access to perks such as a wellness benefit, vouchers, or a subsidised public transport ticket. - Up to 30 days of work-from-abroad per year, plus a buddy programme for onboarding. - Regular team events, both virtual and on-site, and support for community and sustainability initiatives.