Logo Staatliche Kunstsammlungen Dresden

Chief Information Security Officer

New

Job

  • Level
    Lead
  • Location
    Dresden
  • Working Model
    Hybrid, Onsite
  • Job Field
    IT, Security
  • Employment Type
    Part Time/Full Time
  • Contract Type
    Temporary employment

Job Summary

In this challenging role, you will develop a comprehensive information security strategy, lead a CISO team, and oversee technical security measures and incident response in a critical environment.

Job Technologies

Your role in the team

  • Strategic Security Management
  • Development and responsibility for the comprehensive information security strategy of SKD
  • Development and continuous improvement of an Information Security Management System (ISMS) based on ISO 27001 and BSI Basic Protection (risk analyses, policies, controls)
  • Direct reporting line to the management/board of directors, primary contact for all strategic security issues
  • Building and leading the CISO team
  • Building a specialized CISO team with clear roles in governance/risk management, technical security/hardening, incident response/crisis management, identity and access management, as well as monitoring/threat detection.
  • Definition of responsibilities, processes, and interfaces with the IT department and external service providers, clear separation of operations and security with close collaboration
  • Technical Security Responsibility
  • Overall responsibility for vulnerability and patch management with a focus on exposed systems and 'Crown Jewels' (AD, Hypervisor, Backups)
  • Design, selection, and management of MDR/SOC and security monitoring solutions (Endpoints, network components, AD logs, virtualization, backup)
  • Specification of hardening and configuration standards for servers, clients, networks, and security-critical systems
  • Incident Response, Crisis Management, and Compliance
  • Development and operation of a professional incident response and crisis management process, including runbooks, emergency manual, exercises, and specific ransomware playbooks
  • Management of external service providers (IT service providers, hosting providers, MDR providers) regarding security requirements, SLAs, reporting, and clear division of responsibilities
  • Close collaboration with Data Protection (GDPR), Legal Department, Business Units, and Authorities (e.g., Ministry of Culture, possibly BSI/LAND-CERT) to ensure compliance with all regulatory requirements.
  • Transformation to Modern Cloud Security Architecture
  • Development of a medium- to long-term roadmap that gradually transitions the existing on-premises infrastructure into a modern, cloud-based security architecture (Zero Trust, Cloud Identity, secure SaaS usage, cloud backups)
  • Targeted development of cloud security competencies within the CISO team (e.g., Microsoft 365/Azure Security, Cloud IAM, Conditional Access, Defender/CASB), securing hybrid scenarios, and gradually migrating workloads securely to the cloud.
  • Security Culture and Awareness
  • Establishment of a sustainable security culture through awareness programs, training, and clear policies for employees, managers, and IT staff
  • Embedding information security as an integral part of everyday work in all museums and administrative areas

This text has been machine translated. Show original

Our expectations of you

Education

  • Completed degree in Computer Science, Business Informatics, or a comparable qualification

Qualifications

  • Desirable: Certifications in the field of information security (e.g., CISSP, CISM, CISA, ISO-27001 Lead Implementer, or equivalent)
  • Proven experience in defending against or managing complex cyberattacks, particularly ransomware incidents
  • Deep understanding of network and DMZ design, firewall concepts, micro-segmentation, VPN architectures, and prevention of lateral movement
  • In-depth knowledge of Microsoft environments (Active Directory hardening, Windows Server security, Privileged Access Management, separation of admin and user accounts)
  • Strong knowledge of backup and recovery concepts (ransomware-resistant backups, immutable/offline backups, recovery testing)
  • Practical experience in operating MDR/XDR, SIEM, and log management, including correlation of endpoint, network, AD, hypervisor, and backup events
  • Knowledge in Cloud Security (Microsoft 365, Azure Security, ideally fundamentals in AWS/GCP)
  • Ideally familiar with topics such as Cloud Security Posture Management (CSPM), Cloud Access Security Broker (CASB), and DevSecOps approaches
  • Ability to prepare complex technical issues in an understandable way for non-technical stakeholders (museum management, administration, committees) and to create robust decision-making templates
  • High level of personal responsibility, assertiveness, and diplomatic skills in dealing with various stakeholders (management, IT, service providers, authorities)
  • Structured, analytical working style, strong risk awareness, and pragmatic prioritization
  • Ability to build, lead, and develop teams
  • Very good spoken and written German skills; English skills are an advantage

Experience

  • At least 7 years of professional experience in information security, including a minimum of 3 years in a leadership role.
  • Ideally experience in a public institution, a cultural or scientific organization, or a comparable critical environment
  • Experience in building and leading security teams as well as managing external service providers in the field of information security
  • Experience with virtualization (ESXi/vCenter security, hypervisor hardening, secure management)
  • Experience in Vulnerability Management
  • Experience and clear ideas about modern, identity-centric, and Zero Trust architectures
  • Experience with Cloud Identity and Access Management (e.g., Entra ID, Conditional Access, MFA) as well as secure hybrid scenarios and cloud migration
  • Resilience and proven experience in managing security incidents under time pressure
  • Experience in change management and transformation processes during ongoing operations

This text has been machine translated. Show original

What we offer

  • A responsible leadership position with direct reporting line to management in one of Germany's most significant cultural institutions.
  • The opportunity to rebuild and professionalize SKD's information security from the ground up after a significant security incident
  • Budget and mandate to establish an in-house CISO team with clearly defined competencies
  • Design freedom for the development of a modern, future-proof security architecture (On-Prem and Cloud)
  • Close collaboration with executive management, IT leadership, specialist departments, and external experts
  • Employment contract according to the collective agreement for the public service of the federal states (TV-L)
  • 30 days of vacation, days off on December 24th and December 31st, as well as an annual bonus
  • Flexible working hours and the possibility of remote work according to the service agreement
  • Company pension scheme through the Pension Institution of the Federal and State Governments (VBL)
  • Job Ticket or subsidy for Germany Ticket
  • Free admission to the SKD Museums and Collections for all employees
  • Numerous attractive in-museum events + special exhibitions
  • A wide range of training and development opportunities
  • Career development opportunities within the departments/museums and across the entire SKD network
  • Health Promotion Offers
  • Other benefits with local providers

This text has been machine translated. Show original

Benefits

Health, Fitness & Fun

Topics You Will Work On

Job Locations

  • Location Dresden

    Sachsen

    Germany

About Your Employer

Staatliche Kunstsammlungen Dresden

Staatliche Kunstsammlungen Dresden

Der Verbund der Staatlichen Kunstsammlungen Dresden umfasst 15 Museen, die zu den bedeutendsten der Welt zählen. Zusammen mit vier Institutionen repräsentiert er eine thematische Vielfalt, die in ihrer Art international einzigartig ist.

Description

  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Other Sectors
Logo Staatliche Kunstsammlungen Dresden

Chief Information Security Officer

Location
Dresden
Working Model
Hybrid, Onsite
Diversity
Open for all genders

More Jobs