Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- 90.000 to 130.000€ gross/year
- Location
- Frankfurt
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will develop security strategies and resilience programs, lead a team, conduct risk assessments, and support the implementation of security programs and disaster recovery for strategic clients.
Your role in the team
- As an Information Security Manager (m/f/d), based in Germany, you will lead our team of GRC or Incident Readiness consultants while actively contributing to client projects as well as participating in pre-sales activities for strategic clients.
- Your role will be key in enhancing our clients' cybersecurity posture by creating and driving security and resilience strategies and their programs throughout the company.
- Perform technical account management duties for specific top-tier, strategic clients.
- Führen und Leiten eines Teams von GRC- oder Resilienzberaterinnen und -beratern, um qualitativ hochwertige Dienstleistungen für Kunden zu erbringen.
- Enge Zusammenarbeit mit Kunden, um deren Geschäftsziele, Risiken und einzigartige Sicherheitsanforderungen zu verstehen.
- Assessing the security maturity or resilience maturity of clients (using ISO, BSI or NIST standards) to identify gaps and areas for improvement.
- Developing and implementing a fit-for-purpose security program (that aligns with industry standards) or helping the customers to develop and implement resilience programs (BCM and DRP programs).
- Driving the security program at clients, where you also act as the security champion, spreading the 'gospel' on security.
- Conducting risk assessments, identifying potential vulnerabilities, and recommending risk mitigation strategies.
- Überwachung und Unterstützung bei der Umsetzung des Sicherheitsprogramms, einschließlich Richtlinien, Verfahren und Kontrollen.
- or overseeing and supporting with the implementation of Business Continuity Management Systems and Disaster Recovery Programs.
- Providing updates to management on the 'state of security' at their company.
- Holding steering committees at the customer with relevant stakeholders to guide & adapt the security program, where needed.
- Beteiligen Sie sich aktiv am Verkaufsprozess, indem Sie Statements of Work, Projektpläne, Anforderungsdefinitionen… für Projekte in Ihrem Team erstellen und präsentieren.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelor's or Master's degree in Business Administration, Information Security, or a related field.
Qualifications
- You hold citizenship in one of the 32 NATO member states or Austrian citizenship.
- Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISO27001 Implementer/Auditor or equivalent are strongly preferred.
- In-depth knowledge of relevant industry standards and frameworks, such as ISO 27001, DORA, NIST, NIS-2, GDPR, etc.
- Vertrautheit mit Risikomanagement- und Bewertungsmethoden sowie deren Anwendung im Bereich Cybersicherheit.
- Quickly grasping the complexity and the business reasons for a company to perform security and adapting your communication style and the security program to make it fit for the client.
- Excellent English and German written and verbal communication skills to effectively convey complex concepts to technical and non-technical stakeholders.
- Leadership skills to manage a team and collaborate with clients and cross-functional teams.
Experience
- Nachweisliche Erfahrung als CISO und/oder erfolgreiche Implementierung von ISO27k oder BSI Grundschutz bei Kunden. Dies umfasst, ist aber nicht beschränkt auf: Risikoanalyse, Erstellung von Sicherheits-Roadmaps, CISO as a Service (CISOaaS) und Entwicklung von Sicherheitsrichtlinien.
- Or proven experience in being a resilience officer having successfully implemented a BCM or DRP program.
This text has been machine translated. Show original
What we offer
- At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components.
- Working and learning from the best people in the European cyber security industry.
- We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc).
- Generous training budget of 10,000 EUR + 10 man-days for attending lectures rolling over 2 years.
- Base salary range (depending on experience and skillset): 90,000 EUR p.a. - 130,000 EUR p.a.
- Support for technical growth with Cloud trainings + certifications (AWS, GCP, Azure).
- Regular team-building and fun events.
- Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
- Flexible working hours and home office options (including working abroad weeks within the EU).
- Business Bike Leasing.
- BahnCard 50 First Class + public transport ticket.
- 30 holidays.
- Company pension scheme.
- Cool offices in the center of Frankfurt, Munich and Vienna (with BBQ, kicker table, table tennis, PlayStations, etc.).
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
NVISO
As a pure cyber security consulting firm, NVISO supports clients from the financial and technology sectors as well as government agencies with a dedicated team of over 200 professionals.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Consulting