
Information Security Officer
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in Germany.
• Take charge of the Vektor Group's information security strategy, program, and overall posture, from high-level strategy to hands-on execution.
• Develop and maintain a comprehensive group-wide Information Security Management System (ISMS) in accordance with BSI standards 200-1/200-2/200-3, which includes structural analysis, protection needs assessment, modeling, and risk analysis.
• Establish and oversee the group-level security policy framework and processes, ensuring alignment with company-specific additions.
• Prepare for and support the ISO 27001 certification process, carry out internal audits, and collaborate with external auditors.
• Implement obligations under NIS-2, encompassing reporting processes, evidence management, and tracking corrective actions.
• Manage both technical and organizational risks, providing reports to executive management.
• Oversee external consultants and service providers involved in the security program.
• Develop and conduct security awareness training and sensitization programs.
• Lead incident response planning and coordinate incident management with IT, Legal, and leadership teams.
• Evaluate third-party and vendor risks, performing security assessments for new tools and partnerships.
• Work in conjunction with the Director of Internal IT on access governance, endpoint security, and identity management, as well as with platform engineering on product security.
• Assist in sales and customer trust initiatives, including responding to security questionnaires, performing due diligence, and facilitating customer audits.
• Monitor regulatory requirements such as the EU AI Act and Cyber Resilience Act, deriving necessary actions.
• Several years of experience as an Information Security Officer or in a comparable role focusing on information security.
• Demonstrated expertise with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, with a preference for those who have completed a certification process.
• Experience in establishing or leading ISO 27001 programs, from gap analysis to achieving audit readiness.
• Strong risk management skills: ability to assess, prioritize, and effectively communicate risks to both technical and non-technical audiences.
• Willingness to engage in hands-on work during the initial setup phase.
• Confident in interactions with executive management, auditors, and clients.
• Proficiency in German at C1 level or higher.
• Proficiency in English at B2 level or higher.
• Preferred: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM certifications.
• Preferred: Experience in security governance across multiple legal entities or jurisdictions.
• Preferred: Experience in regulated environments such as defense, government, or critical infrastructure; knowledge of VS-NfD, Geheimschutz, or AQAP.
• Preferred: Hands-on experience in implementing NIS-2 requirements.
• Preferred: Familiarity with security processes related to sales, pre-sales, and customer audits.
• An international team with colleagues located in Germany and beyond.
• A startup environment that offers real ownership, flat hierarchies, and swift decision-making.
• Competitive compensation that reflects experience and responsibility.
• Opportunities for individual learning and growth that extend beyond your current role.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.