Auf einen Blick
- Aufgaben: Plane und führe Sicherheitsprüfungen durch, um die Effektivität von Sicherheitskontrollen zu bewerten.
- Unternehmen: METRO AG, ein führendes Unternehmen im Bereich Informationssicherheit.
- Vorteile: Flexible Arbeitszeiten, 30 Urlaubstage, Gesundheitsangebote und Weiterbildungsmöglichkeiten.
- Weitere Informationen: Dynamisches Arbeitsumfeld mit vielen Entwicklungsmöglichkeiten und Campus-Events.
- Warum dieser Job: Gestalte die Sicherheitslandschaft eines multinationalen Unternehmens aktiv mit und entwickle deine Karriere.
- Qualifikationen: Masterabschluss in Informationssicherheit oder verwandtem Bereich, 3 Jahre Erfahrung in der Cybersicherheit.
Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.
- Information Security Assurance Expert (all genders)
- Full-time
- Purpose of the Role
To plan, execute, and support independent information security assurance activities across METRO AG and its operating entities.
The role provides structured, judgment-driven assessment of the effectiveness, maturity, and alignment of security controls against internal policies, regulatory requirements, and recognized frameworks - enabling informed risk decisions and continuous improvement of the organization’s security posture.
Key Responsibilities
- Plan and perform information security assurance reviews, including control design and effectiveness assessments, thematic reviews, and targeted evaluations across IT and OT environments.
- Assess the design adequacy and operational effectiveness of security controls based on frameworks such as ISO/IEC 2701 0, ISO/IEC42001, the NIST Cybersecurity Framework and the NIST AI Risk Management Framework.
- Identify and document control gaps, non-conformities, and risk exposures with proportionate, actionable recommendations.
- Provide subject-matter support to internal and external audit functions as required.
- Collaborate with risk, compliance, and IT teams to track remediation of identified control gaps and ensure timely closure.
- Prepare clear, concise, and well-evidenced assurance reports and recommendations for senior stakeholders.
- Provide guidance to entities and departments in preparing for assurance assessments and building control maturity.
- Support the continuous improvement of the IS assurance program, including methodology, tooling, and automation.
Qualifications
- Master’s degree in Information Security, Computer Science, or a related field.
- Minimum 3 years of experience in cybersecurity assurance, control assessment, or information security governance.
- Professional certifications preferred (e. g. CISA, CRISC, ISO 27001/ 42001Lead Auditor, ISO 27001/ 42001Lead Implementer, CISSP).
- Solid understanding of cybersecurity controls, governance frameworks, and assurance and assessment methodologies.
- Familiarity with regulatory and compliance requirements (e. g. ISO/IEC 27001, NIS 2, GDPR, EU AI Act).
- Strong communication and reporting skills, with the ability to explain technical issues to non-technical stakeholders.
- Experience working in complex, multinational environments is a plus.
- Fluent English required; additional languages are a plus.
Benefits
- Work-life balance: Flexible working hours in agreement with your line manager, 30 days of holidays.
- Training: A comprehensive training offer via our own training centre or externally.
- Well-being: Health days with lots of health checks and information about your well-being, company medical care including a range of preventive services, such as flu shots, OTHEB employee assistance program.
- Exciting life on campus: Free gym and sports classes, Rioba coffee bar, canteen with discounted meals for employees, many campus events.
- Discounts: Discounted job ticket as well as discounts in our wholesale stores and at many partner companies.
- Comfort: Good transport connections, free parking spaces, Job Bike.
- Company pension plan: You will receive a contribution to your company pension.
- Family driven: Three daycare centres for children on campus, support of holiday camps for children of employees.
- #J-18808-Ljbffr
Wir glauben, dass du diese Fähigkeiten brauchst, um Information Security Assurance Expert (all genders) mit Bravour zu bestehen
Information Security Assurance
Control Assessment
ISO/IEC 27001
NIST Cybersecurity Framework
Risk Management
Audit Support
Communication Skills