Job
- Level
- Erfahren
- Job Feld
- IT, System, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Ort
- Düsseldorf
- Arbeitsmodell
- Hybrid, Onsite
Job Zusammenfassung
In dieser Position entwickelst du ein effektives Informationssicherheitsmanagementsystem, planst Audits und überwachst die Sicherheitslage in einer cloud-basierten Umgebung, einschließlich IT-Support und Risikomanagement.
Job Technologien
Deine Rolle im Team
- As an Information Security Manager (gn), you'll work at the intersection of governance, process management, and technical implementation all within ISO 27001: You'll translate security requirements into practical processes across a complex, cloud-native SaaS environment as well as maintain hardware, IT infrastructure and assets.
- In this cross-functional role your main responsibilities include:
- Owning and driving our information security management system (ISMS) ensuring it remains current, effective, and up to our ISO 27001 certified standards.
- Create and maintain all documentation required to live and sustain our ISO 27001 certification.
- Organize the preparation and execution of both internal and external audits and ensure audit-readiness at all times.
- Proactively plan and conduct regular management reviews for the ISMS.
- Design, implement, and continuously improve ISMS processes and controls across the organization.
- Handle the whole risk management including risk identification/assessment and treatment plans up to incident reporting, tracking, and following up.
- Oversee the security posture of our technical environment, including e.g. penetration testing, implementation of security controls etc.
- Partner closely with engineering, operations, and business stakeholders to embed security practices into day-to-day ways of working.
- Support and update local office infrastructure as needed.
- Set up and maintain hardware troubleshoot office surroundings (e.g. workstations, meeting room equipment, network devices), acting as first-line support for day-to-day tech issues.
- Manage basic user access and account provisioning/deprovisioning for internal systems, in line with security policies.
Unsere Erwartungen an dich
Qualifikationen
- A background in cybersecurity, information security management, or IT compliance.
- Strong stakeholder management and communication skills, with the ability to work effectively with both technical and non-technical audiences.
- A proactive, ownership-driven mindset whilst still keeping in touch with the team spirit.
- Comfortable switching between strategic/documentation-heavy security work and hands-on, practical IT support tasks.
- Fluent English (written and spoken) is a must, German language skills are a bonus.
- Located in Germany or the Netherlands with the right to work there and ability & willingness to travel to the Amsterdam location if required.
Erfahrung
- Proven experience managing an ISO 27001 ISMS end-to-end, including certification and surveillance/recertification audits.
- Experience working in or with cloud-based SaaS environments - AWS and/or Kubernetes exposure is a strong plus.
- Some hands-on experience with internal IT support.
Unser Angebot
- An established company living the energy of the start-up spirit with a culture of trust and constructive growth feedback without the restraint of strict hierarchies.
- Based in locations in Amsterdam (NL) and Düsseldorf & Hannover (DE) we are an international company group providing flexible working hours and working models (including remote-first).
- Freedom to expand your professional knowledge. You can educate yourself in tech sessions, training courses, lectures and workshops to exchange knowledge.
- Elaborate team events.
- A technically varied role with real ownership and responsibility.
- A collaborative team of highly skilled professionals.
Benefits
Gesundheit, Fitness & Fun
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
i-doit GmbH
Die i-doit GmbH mit Sitz in Düsseldorf entwickelt B2B-Software zur strukturierten Dokumentation und Verwaltung von IT-Landschaften. Das Unternehmen bietet Lösungen für IT-Dokumentation, CMDB und verwandte Bereiche des IT-Managements und bedient sowohl nationale als auch internationale Kunden.
Description
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Hybrid, Onsite
- Branche
- Internet, IT, Telekom