Information Security Officer

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Information Security Officer leading Vektor Group’s BSI-based ISMS, ISO 27001 certification, and NIS-2 compliance. Securing AI platforms built for defence and government customers.

Responsibilities:

  • Own the Vektor Group's information security strategy, programme, and posture from strategy through hands-on execution
  • Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3, including structure analysis, protection needs assessment, modelling, and risk analysis
  • Create and maintain the group-level security policy framework and processes, coordinating company-specific additions
  • Prepare and accompany ISO 27001 certification, conduct internal audits, and work with external auditors
  • Implement NIS-2 obligations, including reporting processes, evidence management, and corrective action tracking
  • Manage technical and organizational risk and report to executive management
  • Steer external consultants and service providers within the security programme
  • Build and run security awareness training and sensitization programmes
  • Own incident response planning and coordinate incidents with IT, Legal, and leadership
  • Assess third-party and vendor risk and conduct security assessments for new tools and partners
  • Collaborate with the Director of Internal IT on access governance, endpoint security, and identity, and with platform engineering on product security
  • Support sales and customer trust processes, including security questionnaires, due diligence, and customer audits
  • Track regulatory requirements such as the EU AI Act and Cyber Resilience Act and derive required actions

Requirements:

  • Several years of experience as an ISB or in comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
  • Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
  • Solid risk management: assess, prioritize, and communicate risk clearly to technical and non-technical audiences
  • Willingness to work hands-on during the build-up phase
  • Confident interaction with executive management, auditors, and customers
  • German at C1 or above
  • English at B2 or above
  • Nice to have: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM certifications
  • Nice to have: experience with security governance across multiple legal entities or jurisdictions
  • Nice to have: experience in regulated environments such as defence, government, or critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
  • Nice to have: practical NIS-2 implementation experience
  • Nice to have: experience with sales-adjacent security processes, pre-sales, and customer audits

Benefits:

  • International team with colleagues across Germany and other locations
  • Startup environment with real ownership, flat hierarchies, and fast decisions
  • Competitive compensation aligned with experience and responsibility
  • Individual learning and growth opportunities beyond your role