Information Security Manager (f/m/d) Senior Level
On-siteBerlin, State of Berlin, Germany
Job Summary
Develop and improve the information security strategy across diverse topics, including designing the Information Security Management System (ISMS) for sustainable enhancement. Execute governance tasks such as creating and managing policies, refining processes, and strengthening the security framework while managing requirements aligned with ISO 27001, NIST CSF, KRITIS, and ISO 27017 standards. Lead risk management activities involving identification, assessment, and evaluation of security risks, and support audit preparations and maturity assessments for ISO 27001 and TISAX. Communicate and collaborate with stakeholders across engineering, product, and legal units to strengthen security culture, data compliance, and knowledge management. Support incident management and due diligence activities including supplier and product evaluations.
Required Qualifications
- Fundierte Kenntnisse im Informations Security Management und in ISMS-Frameworks (z. B. ISO 27001, NIST usw.)
- Gutes Verständnis für Geschäftsprozesse und Organisationsstrukturen
- Erfahrung in der Informationssicherheits-Governance, einschließlich der Erstellung, Optimierung und Implementierung von Prozessen und Richtlinien sowie der Durchführung von Kontrollen
- Erfahrung im Risikomanagement
- Allgemeine Kenntnisse in der Cloud-Sicherheit (GCP und Office 365)
- Sicherer Umgang mit Lean- und Agile-Methoden
- Starke Kommunikations- und Teamfähigkeiten
- Grundkenntnisse in Operational Excellence und Reifegradmodellen
- Sehr gutes Englisch und Deutsch in Wort und Schrift
- Kenntnisse in Datenschutz- und Datenkonformitätsthemen (z. B. DSGVO, CCPA)
- Ausgeprägte analytische Fähigkeiten und hohe Verantwortungsbereitschaft
- Schnelle Auffassungsgabe und die Fähigkeit, dich rasch in neue Themen einzuarbeiten und relevante Informationen herauszufiltern
- Neugierige, analytische Denkweise sowie eine klare, präzise Kommunikation
- Proaktive Arbeitsweise und Freude an der Zusammenarbeit im Team
- Mobilität
Desired Qualifications
- Gutes Verständnis für Geschäftsprozesse und Organisationsstrukturen – idealerweise in der Softwareentwicklungsbranche
- Große Begeisterung für Informationssicherheit und intrinsische Motivation – du lernst gerne dazu und bleibst neugierig
- Zertifizierungen im Informationssicherheitsmanagement (z. B. CISM, ISO 27001 Lead Auditor)
- Zertifizierungen im Datenschutz (z. B. CIPM, CIPP/E)
- Zertifizierungen in der Cloud-Sicherheit (z. B. GCP Cloud Engineer/Security, Microsoft 365 Security usw.)
- Erfahrung mit Terraform
- Erfahrung im Anforderungsmanagement
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.