Job
- Level
- Experienced
- Job Field
- IT, System, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Dusseldorf
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will develop an effective information security management system, plan audits, and oversee the security posture in a cloud-based environment, including IT support and risk management.
Job Technologies
Your role in the team
- As an Information Security Manager (gn), you'll work at the intersection of governance, process management, and technical implementation all within ISO 27001: You'll translate security requirements into practical processes across a complex, cloud-native SaaS environment as well as maintain hardware, IT infrastructure and assets.
- In this cross-functional role your main responsibilities include:
- Owning and driving our information security management system (ISMS) to ensure it remains current, effective, and compliant with our ISO 27001 certified standards.
- Create and maintain all documentation required to live and sustain our ISO 27001 certification.
- Organize the preparation and execution of both internal and external audits and ensure audit-readiness at all times.
- Proactively plan and conduct regular management reviews for the ISMS.
- Design, implement, and continuously improve ISMS processes and controls across the organization.
- Handle the whole risk management including risk identification/assessment and treatment plans up to incident reporting, tracking, and following up.
- Oversee the security posture of our technical environment, including e.g. penetration testing, implementation of security controls etc.
- Partner closely with engineering, operations, and business stakeholders to embed security practices into day-to-day ways of working.
- Support and update local office infrastructure as needed.
- Set up and maintain hardware troubleshoot office surroundings (e.g. workstations, meeting room equipment, network devices), acting as first-line support for day-to-day tech issues.
- Manage basic user access and account provisioning/deprovisioning for internal systems, in line with security policies.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- A background in cybersecurity, information security management, or IT compliance.
- Strong stakeholder management and communication skills, with the ability to work effectively with both technical and non-technical audiences.
- A proactive, ownership-driven mindset whilst still keeping in touch with the team spirit.
- Comfortable switching between strategic/documentation-heavy security work and hands-on, practical IT support tasks.
- Fluent English (written and spoken) is a must, German language skills are a bonus.
- Located in Germany or the Netherlands with the right to work there and ability & willingness to travel to the Amsterdam location if required.
Experience
- Proven experience managing an ISO 27001 ISMS end-to-end, including certification and surveillance/recertification audits.
- Experience working in or with cloud-based SaaS environments - AWS and/or Kubernetes exposure is a strong plus.
- Some hands-on experience with internal IT support.
This text has been machine translated. Show original
What we offer
- An established company living the energy of the start-up spirit with a culture of trust and constructive growth feedback without the restraint of strict hierarchies.
- Based in locations in Amsterdam (NL) and Düsseldorf & Hannover (DE), we are an international corporate group offering flexible working hours and work models (including remote-first).
- Freedom to expand your professional knowledge. You can educate yourself in tech sessions, training courses, lectures and workshops to exchange knowledge.
- Elaborate team events.
- A technically diverse role with real ownership and responsibility.
- A collaborative team of highly skilled professionals.
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
Topics You Will Work On
Job Locations
About Your Employer
i-doit GmbH
i-doit GmbH, based in Düsseldorf, develops B2B software for the structured documentation and management of IT landscapes. The company offers solutions for IT documentation, CMDB, and related areas of IT management, serving both domestic and international clients.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication