Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Pulsnitz
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will enhance the information security management system, advise executives, derive security requirements, accompany audits and certifications, while assessing security incidents and designing awareness training.
Job Technologies
Your role in the team
- As an Information Security Officer, you will play a central role in the further development of our Information Security Management System and ensure that security requirements are implemented effectively, verifiably, and transparently.
- You manage and develop the information security management system of secupay AG, including policies, standards, procedures, roles, and control frameworks.
- You advise the Executive Board, management, departments, IT, and Security Office/SOC on information security and secure systems, applications, processes, and service providers.
- They derive security requirements from DORA, ZAG-MaRisk, BaFin and EBA guidelines, GDPR, ISO/IEC 27001, TISAX, and PCI DSS, and monitor their implementation.
- They accompany audits, assessments, management reviews, certifications, and inspections, including verifiable evidence.
- They assess security incidents, vulnerabilities, threats, and testing results, and support emergency management, recovery, and digital operational resilience.
- They design awareness and training programs and work closely with ICT risk management, IT compliance, data protection, outsourcing management, audit, and other control functions.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- As a passionate security expert, you are well-versed in the regulations and can translate them into practice.
- You work independently and responsibly, but can also motivate and inspire others to achieve common goals.
- You have very good knowledge in information security management as well as in ISO/IEC 27001 and PCI DSS.
- You are familiar with relevant regulatory requirements, especially DORA, ZAG-MaRisk, GDPR, BaFin, and EBA guidelines.
- You have knowledge of modern IT infrastructures, network and security architectures, as well as SIEM, EDR, monitoring, and vulnerability management solutions.
- You work analytically, carefully, independently, and communicate confidently with management, IT, business units, auditors, and service providers.
- You are proficient in German and English.
- Ideally, you are a certified Information Security Officer.
- Ideally, you have already worked with Jira and Confluence.
Experience
- You bring several years of relevant professional experience in the field of information security.
- You have experience in audit, certification, assessment, and evidence processes.
- Ideally, you have experience in establishing or further developing an ISMS.
This text has been machine translated. Show original
What we offer
- Trust! Work hours can be designed independently.
- It's all about the mix! Mobile working, also possible long-term, with on-site presence only for audits, important meetings, or after coordination.
- Lifelong learning! Needs-based certifications and further training.
- Culture! Appreciative collaboration, open communication, and dynamic teams.
- Work-Life Balance! 30 days of basic vacation.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Topics You Will Work On
Job Locations
About Your Employer
secupay AG
We are the specialist for individual, automated payment and loyalty solutions for all sales channels. Perfectly tailored and cross-channel optimized. Around 15 million users have already carried out secure and easy payments with secupay.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance