IT Compliance & Information Security Manager (m/f/d) in Ludwigsburg

IT Compliance & Information Security Manager (m/f/d) in Ludwigsburg

Ludwigsburg Vollzeit Kein Homeoffice möglich
O

Overview

In this role you will own and evolve the ISMS to meet regulatory and customer requirements for a modern SaaS business. You will translate complex standards (ISO 27001, NIS2, DORA, GDPR) into actionable controls and roadmaps, coordinating audits and governance across engineering, legal, and product teams. You help ensure trust, resilience, and secure use of AI within Onventis. You will be a bridge between compliance, security, and business units, shaping how we operate securely at scale.

Leistungen / Benefits

  • Hybrid work model
  • Free parking
  • Job Ticket
  • JobRad leasing
  • Urban Sports membership
  • fruit, drinks, and meal subsidies","Structured onboarding and training programs","Language courses","Regular team events"),

Verantwortungsbereiche

  • Operate and advance the ISMS based on ISO/IEC 27001 with robust policies, controls and evidence
  • Translate new regulatory requirements into measures, roadmaps and controls (NIS2, DORA, data protection, IT governance, AI-related)
  • Coordinate audits, certifications, and customer reviews; serve as main contact for auditors, customers, and management
  • Conduct risk analyses, identify control gaps, and drive remediation with Engineering, Cloud Operations, Legal, Data Protection, and Product teams
  • Maintain IT-related internal controls, documentation, effectiveness checks, and reporting
  • Evaluate service providers and cloud solutions for compliance, risk, and security throughout their lifecycle
  • Plan and execute awareness, training, and communication to embed regulatory and security requirements
  • Support AI use-case classification and ensure EU AI Act obligations are addressed

Zentrale Anforderungen

  • Several years of experience in information security, IT compliance, IT risk management, IT audit, or GRC in a tech environment
  • Practical ISMS experience per ISO/IEC 27001; familiarity with DORA, NIS2, GDPR
  • Experience preparing for and supporting internal and external audits
  • Ability to translate regulatory requirements into pragmatic SaaS processes and controls
  • Strong German and English communication for cross-functional collaboration
  • Structured, implementation-oriented work style with personal responsibility
  • Certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CISSP are desirable
  • Effective communication
  • Structured, documentation-oriented
  • Cross-functional collaboration
  • ISO/IEC 27001 ISMS
  • Regulatory frameworks: DORA, NIS2, GDPR
  • IT governance and risk management

IT Compliance & Information Security Manager (m/f/d) in Ludwigsburg Arbeitgeber: Onventis

Onventis ist ein hervorragender Arbeitgeber, der eine leistungsorientierte Kultur fördert und seinen Mitarbeitern die Möglichkeit bietet, in einem dynamischen Umfeld zu wachsen. Mit flexiblen Arbeitsmodellen, umfangreichen Gesundheits- und Wellnessangeboten sowie klaren Karriereentwicklungsmöglichkeiten schaffen wir ein unterstützendes Arbeitsumfeld, in dem Teamgeist und Innovation im Mittelpunkt stehen. Bei Onventis haben Sie die Chance, an bedeutenden SaaS-Produkten zu arbeiten und Teil eines engagierten Teams zu werden, das die digitale Transformation im Einkauf vorantreibt.

O

Kontaktdaten:

Onventis Recruiting-Team