Information Security Officer
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Information Security Officer leading Vektor Group’s BSI-based ISMS, ISO 27001 certification, and NIS-2 compliance. Securing AI platforms built for defence and government customers.
Responsibilities:
- Own the Vektor Group's information security strategy, programme, and posture from strategy through hands-on execution
- Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3, including structure analysis, protection needs assessment, modelling, and risk analysis
- Create and maintain the group-level security policy framework and processes, coordinating company-specific additions
- Prepare and accompany ISO 27001 certification, conduct internal audits, and work with external auditors
- Implement NIS-2 obligations, including reporting processes, evidence management, and corrective action tracking
- Manage technical and organizational risk and report to executive management
- Steer external consultants and service providers within the security programme
- Build and run security awareness training and sensitization programmes
- Own incident response planning and coordinate incidents with IT, Legal, and leadership
- Assess third-party and vendor risk and conduct security assessments for new tools and partners
- Collaborate with the Director of Internal IT on access governance, endpoint security, and identity, and with platform engineering on product security
- Support sales and customer trust processes, including security questionnaires, due diligence, and customer audits
- Track regulatory requirements such as the EU AI Act and Cyber Resilience Act and derive required actions
Requirements:
- Several years of experience as an ISB or in comparable responsibility for information security
- Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
- Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
- Solid risk management: assess, prioritize, and communicate risk clearly to technical and non-technical audiences
- Willingness to work hands-on during the build-up phase
- Confident interaction with executive management, auditors, and customers
- German at C1 or above
- English at B2 or above
- Nice to have: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM certifications
- Nice to have: experience with security governance across multiple legal entities or jurisdictions
- Nice to have: experience in regulated environments such as defence, government, or critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
- Nice to have: practical NIS-2 implementation experience
- Nice to have: experience with sales-adjacent security processes, pre-sales, and customer audits
Benefits:
- International team with colleagues across Germany and other locations
- Startup environment with real ownership, flat hierarchies, and fast decisions
- Competitive compensation aligned with experience and responsibility
- Individual learning and growth opportunities beyond your role


















