Information Security Manager – Governance & Awareness (w/m/d)
HybridDüsseldorf, North Rhine-Westphalia, Germany
Job Summary
Analyze regulatory and normative requirements from frameworks like NIS-2, BSIG, KRITIS, and TKG to establish the foundation for targeted organizational and technical measures. Develop and optimize Information Security Management System (ISMS) structures, policies, standards, and governance structures to ensure effective security control. Plan and accompany internal and external audits, ensuring structured execution and sustainable follow-up of findings. Create and manage targeted training, communication, and security awareness formats to strengthen the security culture. Collaborate with relevant stakeholders, auditors, and business units to ensure the effective implementation of information security requirements.
Required Qualifications
- Abgeschlossenes Studium der Informationssicherheit, Informatik, Wirtschaftsinformatik, des Wirtschaftsrechts oder einem vergleichbaren Fachgebiet
- Mehrjährige Berufserfahrung im Bereich der Informationssicherheit
- Praxis auf dem Gebiet der Vorbereitung, Koordination und Begleitung interner und externer Audits sowie der Nachverfolgung von Feststellungen
- Erfahrung in der Konzeption, Planung und Steuerung zielgruppengerechter Security-Awareness-Kampagnen oder Schulungsformate
- Kommunikationstalent mit einer strukturierten Arbeitsweise
- Sehr gute Deutschkenntnisse
Desired Qualifications
- vorzugsweise in der Betreuung, Pflege und Weiterentwicklung zertifizierter Informationssicherheitsmanagementsysteme nach ISO/IEC 27001
- Fundierte Kenntnisse rechtlicher und regulatorischer Anforderungen sowie deren Umsetzung in ein Informationssicherheitsmanagementsystem
- Kenntnisse von NIS-2, KRITIS, TKG oder DORA
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.