Overview
As Information Security Manager, you will lead the ISO 27001:2022 ISMS and drive alignment with DORA across our ICT risk governance. You will partner with cross-functional teams to implement secure architectures, control lifecycles, and proactive threat responses, shaping a resilient security culture. You will translate regulatory requirements into practical security processes and ongoing improvements. This role offers opportunities to influence security at scale within a multinational, growth-focused organization.
Leistungen / Benefits
- established security culture
- growth and development opportunities
- 360T Academy
- multinational environment
- central location in Frankfurt
- regular performance appraisals
Verantwortungsbereiche
- Maintain and enhance ISO 27001:2022 ISMS and policy framework
- Oversee DORA compliance for ICT risk governance and third-party oversight
- Conduct risk analyses in line with regulations and Three-Lines-of-Defence model
- Advise product teams on secure architecture, zero-trust networking, and segregation of duties
- Define, monitor, and improve technical controls (vulnerability management, hardening baselines, privileged access)
- Manage tooling strategy for threat intelligence, security event monitoring, intrusion detection, and related platforms
- Lead the NIST-aligned incident lifecycle (prepare, detect, contain, eradicate, recover, lessons learned)
- Leverage threat intelligence and vulnerability reports to drive process and system improvements
- Coordinate regular cybersecurity exercises to test controls and incident response
Zentrale Anforderungen
- 3+ years in IT security
- University degree in computer science or comparable education
- Working knowledge of security certifications and maintaining compliance to international standards
- Experience in developing practical security processes, policies, and incident management
- Independent, responsible, and self-motivated with minimal supervision
- Willingness to learn new topics, technologies, and business cases
- Proficiency in English; German is a plus
- independence
- proactive learning
- strong communication
- ISO 27001 ISMS
- DORA ICT risk governance
- risk management frameworks