Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Bremen
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will implement and enhance information security, conduct risk assessments, and create policies and audit plans for national and international locations.
Your role in the team
- In this central role, you are responsible for the practical implementation, operation, and continuous development of information security in the German parent company as well as our international subsidiaries.
- You manage, maintain, and develop our group-wide Information Security Management System (ISMS) in accordance with ISO/IEC 27001 on an operational level.
- You implement legal and regulatory requirements — particularly concerning the NIS2 Directive and KRITIS regulations — and monitor their compliance.
- You independently conduct information security risk assessments and develop appropriate risk treatment plans for critical business processes and IT infrastructures.
- You plan, coordinate, and oversee internal audits at our national and international locations and support external certification audits.
- You create, update, and establish technical and organizational security policies, standard documents, and audit checklists.
- You support the Security Incident Management operationally in analyzing and resolving security incidents.
- You advise our specialist departments, IT administration, as well as the contacts in our international subsidiaries on all matters of information security.
This text has been machine translated. Show original
Our expectations of you
Education
- You have successfully completed a degree in (Business) Informatics, IT Security, or a comparable technical qualification with comprehensive further training in the field of information security.
Qualifications
- You bring comprehensive and practical knowledge of ISO/IEC 27001 (including the current controls according to ISO/IEC 27002), the NIS2 Directive, and common best practices for critical infrastructures.
- Ideally, you hold certifications in the field of information security, such as ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, or CISM.
- You are characterized by strong analytical skills, a structured and self-reliant work approach, as well as the necessary assertiveness in implementing technical and organizational measures.
- You have fluent German and English skills, both written and spoken, enabling you to communicate confidently with our international locations.
Experience
- You have several years of practical experience in operational information security management - ideally in an internationally oriented company.
This text has been machine translated. Show original
What we offer
- You work 38.5 hours per week with us and receive 30 days of vacation - giving you plenty of time for your private life.
- To help you look to the future with peace of mind, we also provide for your retirement and contribute with a 20 percent subsidy to your company pension scheme.
- Do you also want to work remotely from home? With us, you have the opportunity to do so within the framework of our Flex-Office concept.
- With your personal annual health budget of 300 euros, you can have expenses reimbursed, for example, for glasses, medications, or a professional dental cleaning.
- Swimming, bouldering, dancing - with our corporate fitness program, you can train affordably nationwide in 1,000 studios and sports facilities.
- Feel free to bring your dog to the office—if your colleagues agree. Four-legged friends that enable quiet work are welcome here.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Topics that you deal with on the job
Job Locations
This is your employer
Deutsche Windtechnik AG
We at Deutsche Windtechnik are Europe's largest independent service provider for the technical maintenance of wind turbines. With our team of more than 1,000 employees, we guarantee trouble-free operation of wind farms.
Description
- Founding year
- 2007
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Power Sector, Economy