Remote job
Gruppen Informationssicherheitsbeauftragter (m/f/d)
Job details
About this role
Role overview
A data-intelligence company serving defence, law enforcement, and enterprise customers is hiring a Group Information Security Officer to lead information security across the organisation. The platform processes petabyte-scale data with sub-second queries and ships as a Kubernetes-based B2B SaaS or self-hosted solution, including air-gapped deployments. The role is strategic and hands-on during the build-up phase, transitioning toward governance as the security organisation matures.
Responsibilities
- Build and continuously evolve a group-wide ISMS aligned with BSI IT-Grundschutz, including structural analysis, protection needs assessment, modelling, and risk analysis. - Prepare and steer ISO 27001 certification, run internal audits, and coordinate external auditors. - Translate NIS-2 obligations into operational processes, including reporting, evidence collection, and remediation tracking. - Own the group security policy and process framework and coordinate entity-specific addenda. - Manage third-party and vendor risk, including security assessments for new tools, partners, and service providers. - Plan and evolve incident response, coordinating with IT, legal, and leadership during live incidents. - Build a security awareness programme covering training and ongoing sensitisation. - Monitor additional regulatory regimes such as the EU AI Act and Cyber Resilience Act and turn them into concrete actions.
Requirements
- Several years of experience as an Information Security Officer or in a comparable accountable information-security role. - Deep practical experience with BSI IT-Grundschutz, particularly the 200-x standards and the Grundschutz Compendium, ideally including a completed certification cycle. - Track record building or steering ISO 27001 programmes from gap analysis through audit readiness. - Strong risk management skills with the ability to communicate clearly to both technical and non-technical stakeholders. - Willingness to operate hands-on during the build phase and pick up operational work beyond pure governance. - German at C1 or above and English at B2 or above.
Nice to have
- Certifications such as IT-Grundschutz Praktiker/Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM. - Security governance experience spanning multiple legal entities or jurisdictions. - Background in regulated sectors such as defence, public sector, or critical infrastructure, with familiarity in VS-NfD, classification handling, or AQAP. - Practical experience implementing NIS-2. - Exposure to customer-facing security processes, including pre-sales support, security questionnaires, and customer audits.
Benefits and work setup
- Remote-first across Germany with regular team meetups in Berlin and other offsite locations. - Flexible hours, a personal home-office budget, 30 days of vacation, and performance bonuses tied to agreed objectives. - Investment in personal and professional growth, plus team events and a welcome package on joining. - Mission-driven work tied to public safety and national security outcomes.