Auf einen Blick
- Aufgaben: Unterstütze die Informationssicherheit durch Governance und operative Sicherheitsdienste.
- Unternehmen: Innovatives Unternehmen, das sich auf nachhaltige HPC-Lösungen konzentriert.
- Vorteile: Flexibles Home Office, Wellness-Initiativen und ein unterstützendes Team.
- Weitere Informationen: Flache Hierarchien und die Möglichkeit, Prozesse und Kultur zu optimieren.
- Warum dieser Job: Gestalte aktiv die Zukunft der Datensicherheit und arbeite an nachhaltigen Lösungen.
- Qualifikationen: Abschluss in Informationssicherheit oder verwandtem Bereich, 5-7 Jahre Erfahrung.
Job DescriptionThe Information Security Engineer supports the Information Security function by delivering governance, and operational security services across the organization. The role is responsible for maintaining the Information Security Management System (ISMS), coordinating security governance and documentation, supporting audit activities, managing security-related projects, and assisting with the implementation and operation of securitAy controls and technologies. The position works closely with Compliance, IT, Engineering, Legal, HR and business stakeholders to strengthen the organization’s overall security posture.YOUR RESPONSIBILITIES:Information Security Governance (Approx. 60%)Maintain and support the continual improvement of the ISO/IEC 27001 Information Security Management System (ISMS).Own the lifecycle of security policies, standards, procedures and guidelines, including drafting, review cycles, approvals and publication via SharePoint and Confluence.Administer Information Security documentation repositories, knowledge bases and workflow platforms (SharePoint, Confluence, Jira), including version control, review schedules and follow-up on overdue actions.Own and maintain Information Security registers, including the Asset Register, Risk Register, Exception Register and Action Tracker, ensuring data quality and timely updates.Support enterprise information asset management and data classification, including governance of data loss prevention (DLP) and sensitivity labelling technologies.Lead audit preparation, evidence collection and logistics for internal and external audits; track findings, observations and corrective actions through to closure.Support Information Security risk assessments, treatment plans and periodic reviews across the business.Prepare Information Security metrics, dashboards, KPIs and management reports.Coordinate Information Security projects, tracking scope, milestones, risks, dependencies, actions and deliverables.Partner closely with Compliance, Legal, IT, Engineering, HR and business stakeholders on governance matters.Operational Security Support (Approx. 40%)Support the implementation, configuration, administration and continuous improvement of Information Security technologies and platforms.Support third-party security assessments, due diligence questionnaires and supplier assurance activities.Support vulnerability remediation tracking, escalating overdue items and reporting on remediation progress.Support security incident response activities, including documentation, coordination, evidence collection and post-incident improvement actions.Support security awareness and communication initiatives.Support security reporting, KPI tracking and management updates.Provide coordination and administrative support to other Information Security team members.YOUR QUALIFICATIONS:Bachelor’s degree in information security, Cyber Security, Computer Science or related discipline.5–7 years' experience in Information Security, GRC, Security Operations.Solid understanding of ISMS and security governance frameworks (e.g. ISO/IEC 27001).Experience with risk management methodologies and conducting information security risk assessments.Familiarity with security compliance frameworks and regulatory requirements (e.g. NIS2, SOC 2, CIS Controls, GDPR).Experience managing documentation, registers and workflows across enterprise collaboration platforms (e.g. SharePoint, Confluence, Jira).Experience with Data Loss Prevention (DLP), information protection, and data classification solutions.Experience with data analysis, reporting, dashboard development and KPI measurement.Experience working in cross-functional environments with Infrastructure, IT, Platform Engineering, Compliance and Legal teams.Familiarity with Vulnerability management processes and vulnerability assessment tools. Security testing methodologies and tools (e.g. vulnerability scanning, security validation, or penetration testing support).Familiarity with Security monitoring, SIEM platforms, and incident detection concepts.Familiarity with Endpoint Detection and Response (EDR) and endpoint security technologies.Nice to haveBasic Understanding of Identity and Access Management (IAM), authentication, and privileged access management concepts.Basic understanding of networking, TCP/IP, DNS, routing, switching, and network security principles.Basic understanding of web technologies and web application security concepts.Basic Understanding of Cloud security concepts and shared responsibility models.Scripting or automation fundamentals (e.g. PowerShell or Python) would be advantageous..WHAT WE OFFERWith us, you will work towards the future of HPC: From new, sustainable building methods for data centers to cooling concepts to software solutions for accelerated compute. Your approaches count: In official exchange formats or spontaneously at the coffee machine. At Northern Data, it's the best idea that counts - not the hierarchy. We’re looking forward to getting your inputs!You make the difference in the company: Unlike in established corporations, at Northern Data you will really help shape things. From implementing new departments, to optimizing processes and culture. Best-in-class partners: The best work with Northern Data. This means a knowledge and time advantage from which your career and our customers benefit equally.Green by heart: Sustainability is at the core of Northern Data. With us, you actively work on the carbon neutrality of datacenters worldwide. Beginning with our infrastructure and continuing with the solutions for our clients, we work towards a green future.Home Office facts: Work with our international and virtual team flexible from home. And of course, your hardware wishes will be fulfilled to make your ideas for next level HPC come true.Your wellness matters: At Northern Data we have regular wellbeing initiatives that are designed to promote wellness, diversity, inclusion, and much more, ensuring a supportive and enriching environment for our global team.SummaryLocation: FrankfurtType: Full time
Information Security Engineer (m/f/d) Arbeitgeber: Northern Data
Northern Data ist ein hervorragender Arbeitgeber, der Ihnen die Möglichkeit bietet, aktiv an der Gestaltung einer nachhaltigen Zukunft im Bereich Hochleistungsrechnen (HPC) mitzuwirken. Mit einem offenen und innovativen Arbeitsumfeld, in dem Ihre Ideen zählen, fördern wir nicht nur Ihre berufliche Entwicklung, sondern setzen auch auf eine starke Teamkultur, die Vielfalt und Wohlbefinden schätzt. Genießen Sie flexible Home-Office-Möglichkeiten und profitieren Sie von erstklassigen Partnerschaften, während Sie an der Kohlenstoffneutralität von Rechenzentren weltweit arbeiten.