Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Part Time/Full Time
- Contract Type
- Permanent employment
- Location
- Dusseldorf
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you design the information security risk management, optimize training materials, collaborate closely with ISOs, and ensure risk treatment and quality assurance in individual data processing.
Your role in the team
- Conceptualization, technical leadership, and operation of the group-wide Information Security (IS) Risk Management (RM) for the companies of the ERGO Group as part of the 2nd Line of Defense (LoD) Information Security Team.
- Design and optimization of training materials for the stakeholders of the IS RM process, collaboration with the ISOs within the framework of the IS RM process, and professional management of the structure and protection requirement analysis.
- Formulation and linking of controls, measures, and policies based on technical expertise to meet ERGO information security requirements, including the creation and delivery of management-appropriate and high-quality presentations.
- Coordination, management, and supervision of the determination of risk mitigation measures for information security risks, as well as participation in the preparation of the information security risk reporting.
- Ensuring appropriate assessment and management of information security risks within the ERGO Group.
- Consideration of the requirements for Individual Data Processing (IDV) from the relevant regulatory requirements (e.g., DORA, VAIT) and continuous development of IDV guidelines (such as policies, methodology, and controls).
- Quality assurance of the IDV vulnerability analysis.
This text has been machine translated. Show original
Our expectations of you
Education
- Completed university degree (preferably in Computer Science). Alternatively, a completed vocational training with an IT background and relevant further education.
Qualifications
- Specific expertise in relevant security standards and a certification (e.g., ISO 27001 Lead Implementer / Auditor, CISA, CISM, CISSP) are desirable.
- Strong analytical skills, a structured and results-oriented work approach, high quality standards, and a sense of responsibility for work outcomes.
- Targeted communication and confident presentation of complex issues at all hierarchical levels, high willingness to cooperate, enjoyment of teamwork, as well as good written and spoken English skills.
Experience
- Several years of professional experience, ideally in the field of information security.
- Experience regarding regulatory requirements such as DORA, VAIT, and BSI-Kritis V.
This text has been machine translated. Show original
What we offer
- Flexible working hours, development opportunities, fair compensation, and even free hot drinks and water.
- Mobile working is possible up to 50 percent of the monthly working hours and offers you a high degree of flexibility.
- We offer you the support you need to realize your full potential and to balance your work and private life effectively.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
More net
Topics that you deal with on the job
Job Locations
This is your employer
ERGO Group AG
ERGO is one of the leading insurance groups in Germany and Europe. The group is represented in around 30 countries worldwide and focuses on the regions of Europe and Asia. ERGO offers a comprehensive range of insurance, pension and service products. In its home market of Germany, ERGO is one of the leading providers across all lines of business.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance