Remote job
Information Security Officer
Job details
About this role
Role overview Own the information security strategy, programme, and posture of a multi-entity group that builds AI platforms for defence and government customers. The mandate centers on achieving ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance, from gap analysis and controls implementation through audit readiness and ongoing maintenance. The role is build-oriented: during the ramp-up phase the work is hands-on across operational security, IT support, and governance, supported by external consultants, with the balance gradually shifting toward strategy and governance as the ISMS matures.
Responsibilities - Build and operate the group-wide ISMS following BSI standards 200-1, 200-2, and 200-3, including structure analysis, protection needs assessment, modelling, and risk analysis. - Prepare, accompany, and maintain ISO 27001 certification; run internal audits and coordinate with external auditors. - Implement NIS-2 obligations, including reporting processes, evidence management, and corrective action tracking. - Create and maintain the group-level security policy framework and coordinate company-specific additions. - Own incident response planning and coordinate responses with IT, Legal, and leadership. - Manage risk across technical and organizational domains, including reporting to executive management. - Steer external consultants and service providers contributing to the security programme. - Build and run the security awareness programme covering training and sensitization. - Assess third-party and vendor risk and run security reviews for new tools and partners. - Support sales and customer trust processes, including security questionnaires, due diligence, and customer audits. - Track further regulatory requirements such as the EU AI Act and Cyber Resilience Act and derive required actions.
Requirements - Several years of experience as an Information Security Officer or in a comparable information security leadership role. - Proven practice with BSI IT-Grundschutz, including BSI standards 200-x and the Grundschutz-Kompendium, ideally with a completed certification procedure. - Experience building or leading ISO 27001 programmes, from gap analysis through to audit readiness. - Solid risk management skills with the ability to assess, prioritize, and communicate risk to both technical and non-technical audiences. - Willingness to work hands-on during the build-up phase, including operational security and direct IT support. - Confident interaction with executive management, auditors, and customers. - German at C1 or above and English at B2 or above.
Nice to have - Certifications such as IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM. - Experience with security governance across multiple legal entities or jurisdictions. - Background in regulated environments (defence, government, critical infrastructure) and familiarity with VS-NfD, Geheimschutz, or AQAP. - Practical NIS-2 implementation experience and pre-sales or customer audit experience.
Benefits and work setup - International team with colleagues across Germany and other locations. - Startup environment with real ownership, flat hierarchies, and fast decision-making. - Competitive compensation aligned with experience and responsibility. - Individual learning and growth opportunities beyond the core role.