Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- 90.000 to 130.000€ gross/year
- Location
- Munich
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will lead a team of CISOaaS/GRC consultants and develop security programs for clients while assessing their security maturity and implementing risk mitigation strategies.
Your role in the team
- As an Information Security Manager (m/f/d), based in Germany, at NVISO, you will lead our team of CISOaaS or GRC consultants while actively contributing to client projects as well as participating in pre-sales activities for strategic clients.
- Your role will be key in enhancing our clients' cybersecurity posture by creating and driving security strategies and their programs throughout the company.
- Key responsibilities include, but are not limited to:
- Leading and managing a team of CISOaaS/GRC consultants to deliver high-quality services to clients;
- Enge Zusammenarbeit mit Kunden, um ihre Geschäftsziele, Risiken und ihre einzigartigen Sicherheitsanforderungen zu verstehen;
- Assessing the security maturity of clients (using ISO, BSI or NIST standards) to identify gaps and areas for improvement;
- Developing and implementing a fit-for-purpose security program (that aligns with industry standards);
- Driving the security program at clients, where you also act as the security champion, spreading the 'gospel' on security;
- Conducting risk assessments, identifying potential vulnerabilities, and recommending risk mitigation strategies;
- Überwachung und Unterstützung bei der Umsetzung des Sicherheitsprogramms, einschließlich Richtlinien, Verfahren und Kontrollen;
- Providing updates to management on the 'state of security' at their company;
- Holding steering committees at the customer with relevant stakeholders to guide & adapt the security program, where needed.
- Beteiligen Sie sich aktiv am Verkaufsprozess, indem Sie Statements of Work, Projektpläne, Anforderungsdefinitionen… für Projekte in Ihrem Team erstellen und präsentieren;
- Perform technical account management duties for specific top-tier, strategic clients.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelor's degree in Business Administration, Information Security, or a related field;
Qualifications
- You are eligible for NATO clearance.
- Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISO27001 Implementer/Auditor or equivalent are strongly preferred;
- In-depth knowledge of relevant industry standards and frameworks, such as ISO 27001, DORA, NIST, NIS-2, GDPR, etc.
- Vertrautheit mit Risikomanagement-Methoden und deren Anwendung im Bereich Cybersicherheit;
- Quickly grasping the complexity and the business reasons for a company to perform security and adapting your communication style and the security program to make it fit for the client;
- Excellent English and German written and verbal communication skills to effectively convey complex concepts to technical and non-technical stakeholders;
- Leadership skills to manage a team and collaborate with clients and cross-functional teams.
Experience
- Proven experience as a CISO and/or successful implementation of ISO27k or BSI Grundschutz at clients. This includes, but is not limited to: risk assessment, security roadmap development, CISOaaS, and policy formulation.
This text has been machine translated. Show original
What we offer
- At NVISO, we care.
- We are committed to offering you a highly competitive remuneration package including financial and non-financial components:
- A training budget of 10,000 EUR plus 10 days paid time off rolling over two years;
- Base salary range (depending on experience and skillset): 90,000 EUR p.a. - 130,000 EUR p.a.
- Working with and learning from the best people in the European cyber security 'scene'.
- We have several SANS instructors working for us and we are also represented at popular hacking conferences (BlackHat, BruCON, OWASP, etc.).
- In addition, our employees can take advantage of prestigious continuing education opportunities (GSE, GXPN, CISSP, OSCP, etc.);
- A forward-thinking and agile company that supports you in the creation and implementation of new initiatives;
- Unique team events (most recently e.g. Lisbon, Dubai, Malta, Lapland);
- A sophisticated coaching concept starting on day 1;
- 30 days of vacation;
- Flexible working hours and home office options (+ working abroad option within the EU);
- Cost absorption for Deutschlandticket and BahnCard50;
- Company bike leasing;
- Betriebliche Altersvorsorge;
- A cool office in the heart of Frankfurt and Munich (roof terrace, table tennis, PlayStation, BBQ).
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
NVISO
As a pure cyber security consulting firm, NVISO supports clients from the financial and technology sectors as well as government agencies with a dedicated team of over 200 professionals.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Consulting