远程工作雷达

集团信息安全经理

Group Information Security Manager

开发工程全球可投
公司orcristtechnologies
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间13 天前
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

Orcrist 正在使用前沿技术构建下一代数据智能平台。我们处理海量数据,实现亚秒级查询。我们的产品是一个基于 Kubernetes 的平台,以 B2B SaaS 或自托管本地部署方案提供,包括隔离网络部署。我们为国防、执法和企业客户提供服务,帮助他们将关键任务数据转化为可操作的情报。

职位描述

作为集团 ISB,你负责 Vektor 集团的信息安全策略、计划和态势,从战略到实际执行。你与内部 IT 主管紧密合作,推动技术控制和实施。你的核心职责是基于 BSI IT-Grundschutz 实现 ISO 27001 认证,以及 NIS-2 合规性:从差距分析和控制实施到审计准备、持续维护,以及两种框架下的监管义务。

我们为国防和政府行业的客户提供 AI 平台。信息安全是我们业务的前提条件,而不是事后补充。随着集团的成长,我们正在建立安全组织。在此阶段,包括领导层在内的所有人都需要亲力亲为:日常运营安全、直接支持 IT 团队,以及传统治理角色之外的任务。外部顾问会协助快速推进。随着 ISMS 和团队的成熟,重心将逐渐转向战略和治理。

你会做以下工作

  • 按照 BSI 标准 200-1/200-2/200-3 建立并运行集团范围内的 ISMS:结构分析、保护需求评估、建模、风险分析
  • 创建并维护集团层面的安全政策框架和流程;协调公司特定的补充内容
  • 准备并陪同 ISO 27001 认证,开展内部审计,与外部审计师合作
  • 实施 NIS-2 义务:报告流程、证据管理、纠正措施跟踪
  • 管理技术与组织领域的风险,包括向高管汇报
  • 指导外部顾问和服务提供商在项目中的工作
  • 建立并运行安全意识计划:培训与宣传
  • 负责事件响应计划,与 IT、法务和管理层在事件中协调
  • 评估第三方和供应商风险,对新工具和合作伙伴进行安全评估
  • 与内部 IT 主管紧密合作(t
查看英文原文

Orcrist is building a next generation data intelligence platform using cutting-edge technologies. We're handling petabyte-scale data with sub-second queries. Our product is a Kubernetes‑based platform delivered as B2B SaaS or as a self‑hosted on‑prem solution, including air‑gapped deployments. We enable customers across defense, law enforcement, and enterprise to turn mission-critical data into actionable intelligence.

Role

As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.

We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.

What you'll do

  • Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
  • Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
  • Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
  • Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
  • Manage risk across technical and organizational domains, including reporting to executive management
  • Steer external consultants and service providers within the running programme
  • Build and run the security awareness programme: training and sensitization
  • Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
  • Assess third-party and vendor risk, run security assessments for new tools and partners
  • Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
  • Support sales and customer trust processes: security questionnaires, due diligence, customer audits
  • Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action

About you

  • Several years of experience as an ISB or in comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
  • Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
  • Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
  • Willingness to work hands-on during the build-up phase
  • Confident interaction with executive management, auditors, and customers
  • German at C1 or above, English at B2 or above

Nice-to-haves

  • Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM
  • Experience with security governance across multiple legal entities or jurisdictions
  • Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
  • Practical NIS-2 implementation experience
  • Experience with sales-adjacent security processes (pre-sales, customer audits)

What we offer

  • Remote-first, Germany-wide: Work from wherever you do your best work, with regular team gatherings in Berlin and other off-site locations.
  • Flexibility by default: Flexible working hours help you make work fit your life.
  • Your setup, your way: Get a personal home-office equipment budget to create a workspace that works for you.
  • 30 days of vacation: Take the time you need to recharge and come back with fresh energy.
  • Keep growing: We invest in your personal and professional development.
  • Get rewarded for impact: Performance bonuses are tied to agreed objectives and key results.
  • A warm welcome: Every new team member gets a welcome goodie bag.
  • Good people, good times: From summer and Christmas parties to regular team gatherings, we make time to celebrate together.
  • A mission that matters: Work on challenges with tangible impact on public safety and national security.
本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位