Information Security Manager – Governance & Awareness (w/m/d)
HybridBorken, North Rhine-Westphalia, Germany
Job Summary
Analyze regulatory and normative requirements from frameworks like NIS-2, BSIG, KRITIS, and TKG to establish a foundation for organizational and technical measures. Develop and optimize Information Security Management System (ISMS) structures, policies, standards, and governance mechanisms to ensure effective security control. Plan and accompany internal, external, and certification-relevant audits while tracking findings and improvement actions. Create and manage targeted training, communication, and security awareness formats to foster a sustainable security culture. Generate metrics and reports to provide transparency on ISMS effectiveness for management and stakeholders.
Required Qualifications
- Abgeschlossenes Studium der Informationssicherheit, Informatik, Wirtschaftsinformatik, des Wirtschaftsrechts oder einem vergleichbaren Fachgebiet
- Mehrjährige Berufserfahrung im Bereich der Informationssicherheit
- Praxis auf dem Gebiet der Vorbereitung, Koordination und Begleitung interner und externer Audits sowie der Nachverfolgung von Feststellungen
- Erfahrung in der Konzeption, Planung und Steuerung zielgruppengerechter Security-Awareness-Kampagnen oder Schulungsformate
- Kommunikationstalent mit einer strukturierten Arbeitsweise
- Sehr gute Deutschkenntnisse
Desired Qualifications
- vorzugsweise in der Betreuung, Pflege und Weiterentwicklung zertifizierter Informationssicherheitsmanagementsysteme nach ISO/IEC 27001
- Fundierte Kenntnisse rechtlicher und regulatorischer Anforderungen sowie deren Umsetzung in ein Informationssicherheitsmanagementsystem
- Kenntnisse von NIS-2, KRITIS, TKG oder DORA
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.