Information Security Officer (ISO)

Information Security Officer (ISO)

Lausanne Vollzeit 63000 - 77000 € / Jahr (geschätzt) Kein Homeoffice möglich
C

Auf einen Blick

  • Aufgaben: Gestalte und implementiere Sicherheitsprogramme für innovative Technologien.
  • Unternehmen: Corintis, ein führendes Startup in der Mikrofluidik-Technologie.
  • Vorteile: Attraktives Gehalt, flexible Arbeitszeiten und ein freundliches Team.
  • Weitere Informationen: Wachstumschancen in einem internationalen Umfeld mit über 25 Nationalitäten.
  • Warum dieser Job: Sei Teil eines dynamischen Teams, das die Zukunft der Rechenzentren gestaltet.
  • Qualifikationen: Mindestens 5 Jahre Erfahrung in der Informationssicherheit und GRC-Kenntnisse.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

ABOUT CORINTIS

Corintis offers innovative microfluidic cooling technologies for AI chips/GPUs and CPUs used in data centers.

Working with many of the world’s largest tech companies, our solutions improve compute sustainability and tackle the excessive electricity consumption associated with data center cooling, which consumes more electricity than New York and London combined.

Ranked as the No.1 Engineering startup in Switzerland for 2025, Corintis offers a friendly and team-oriented workplace, bringing together over 105 people from over 25 nationalities to solve the most significant computing challenges of tomorrow.

Based on the EPFL campus near Lausanne, we are closely connected to the local ecosystem and are located a few minutes walk from Lake Geneva.

THE ROLE

The Information Security Officer (ISO) partners closely with the Head of IT Security & Compliance to shape and execute Corintis’ information security program.

The ISO plays a key role in Governance, Risk, and Compliance (GRC) management, developing and implementing security requirements and controls that align with business goals, customer expectations, and applicable compliance standards.

This role is responsible for performing risk assessments, conducting gap analyses, and contributing to metrics and key performance indicators (KPIs) that measure the maturity and effectiveness of Corintis’ security posture.

As a champion of proactive risk management and a strong security culture, the ISO ensures that information security best practices are integrated across all areas of the organization.

KEY RESPONSIBILITIES

  • GOVERNANCE
  • Partner with the Head of IT Security & Compliance to define and execute Corintis’ information security program.
  • Support the development and continuous improvement of the company’s security framework.
  • Define and track Key Performance Indicators (KPIs) to evaluate the maturity and effectiveness of the security program.
  • Prepare and present risk, compliance, and performance reports to senior leadership and relevant committees.
  • Support ongoing compliance with key standards such as ISO 27001, SOC 2, and GDPR.
  • Collaborate across functions—particularly with R&D, Customer Success, IT, and Operations.
  • Continuously review, refine, and strengthen existing governance and security practices.
  • RISK MANAGEMENT
  • Lead and perform regular risk assessments, compliance gap analyses, and internal audits to identify security weaknesses and recommend remediation.
  • Support customer and third‑party due diligence activities.
  • Maintain the corporate risk register, documenting identified risks, mitigation strategies, and resolution progress.
  • Ensure executive visibility of key risks and risk trends through structured reporting and stakeholder communication.
  • COMPLIANCE MANAGEMENT
  • Monitor and evaluate the security compliance of business operations.
  • Design and implement pragmatic, fit‑for‑purpose security controls.
  • Oversee the operation and continuous improvement of Corintis’ Information Security Management System (ISMS).
  • Track relevant standards and evolving customer, industry, and regulatory requirements.
  • TRAINING AND AWARENESS
  • Partner with legal, privacy, and compliance teams to manage contractual and regulatory aspects of information security.
  • Serve as a visible advocate for information security across the organization, fostering a culture of accountability and awareness.
  • Contribute to the company’s ongoing security awareness initiatives, including training sessions and targeted communications.
  • Promote a risk‑conscious mindset across all departments to ensure security principles are applied consistently throughout the business.
  • INCIDENT MANAGEMENT
  • Support the incident response process, coordinating with internal and external stakeholders.
  • Participate in post‑incident reviews to identify lessons learned and propose continuous improvements to processes and controls.
  • Provide leadership with timely reports on incident trends, risk metrics, and recommendations to enhance organizational resilience.

REQUIREMENTS

  • At least 5 years of experience in Information Security, with a strong background in GRC within technology‑driven or regulated environments.
  • Proven track record in conducting information security risk assessments, implementing risk mitigation strategies, and driving continuous improvement in security posture.
  • Demonstrated expertise in performing compliance gap analyses and developing measurable security KPIs and OKRs.
  • Hands‑on experience implementing and maintaining security standards such as ISO 27001, SOC 2 Type II, CIS Controls v8.1, and GDPR.
  • Solid understanding of business continuity and disaster recovery management.
  • Pragmatic approach to risk management, balancing security needs with operational efficiency.
  • Familiarity with modern GRC platforms such as Drata or Vanta for compliance automation and reporting.
  • Well‑rounded knowledge of information security beyond GRC.
  • Highly organized, capable of working independently, and experienced in applying project management methodologies.
  • Skilled at managing multiple priorities in a dynamic, fast‑paced, and agile environment.
  • Excellent communication and interpersonal skills, with the ability to engage confidently with auditors, customers, and cross‑functional teams.
  • Relevant professional certifications such as CRISC, CISM, CISSP, ISO 27001 Lead Implementer, or ISO 22301 Lead Implementer are strongly preferred.
  • THIS IS A GREAT FIT IF YOU
  • Enjoy working in a fast‑paced, innovation‑driven environment.
  • Are motivated by building and improving security programs from the ground up.
  • Bring a pragmatic mindset to security and compliance.
  • Take ownership of projects and enjoy shaping processes rather than simply maintaining them.
  • Value transparency, teamwork, and open communication across diverse technical and non‑technical teams.
  • Are curious by nature and committed to continuous learning.
  • THIS WON’T BE THE RIGHT ROLE FOR YOU IF
  • You prefer working in a large, highly structured organization with well‑established security frameworks already in place.
  • You’re looking for a role focused solely on policy writing or compliance checklists.
  • You are not comfortable navigating ambiguity or adapting priorities as the organization and its customer landscape evolve.
  • You would rather work fully remotely without regular in‑person collaboration.
  • You seek roles where customer interaction is minimal.
  • #J-18808-Ljbffr

Information Security Officer (ISO) Arbeitgeber: Corintis

Corintis ist ein hervorragender Arbeitgeber, der innovative Lösungen im Bereich der Mikrofluidik für KI-Chips und CPUs anbietet. Mit einem freundlichen und teamorientierten Arbeitsumfeld auf dem EPFL-Campus in St. Sulpice fördert das Unternehmen die Zusammenarbeit von über 85 Mitarbeitern aus mehr als 35 Nationalitäten und bietet zahlreiche Möglichkeiten zur beruflichen Weiterentwicklung. Die enge Anbindung an das lokale Ökosystem und die Auszeichnung als Nr. 1 Engineering-Startup in der Schweiz für 2025 machen Corintis zu einem attraktiven Arbeitsplatz für alle, die an bedeutenden technologischen Herausforderungen mitwirken möchten.

C

Kontaktdaten:

Corintis Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Information Security Officer (ISO) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Corintis kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Corintis zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Corintis.

Wir glauben, dass du diese Fähigkeiten brauchst, um Information Security Officer (ISO) mit Bravour zu bestehen

Governance, Risk, and Compliance (GRC)
Risikobewertung
Compliance-Gap-Analysen
ISO 27001
SOC 2
GDPR
Information Security Management System (ISMS)

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Corintis vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Corintis könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Corintis sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Corintis auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!