Senior Information Security Governance Expert (all genders)
Hamburg, Germany
The Global Information Security department of Evotec is searching for a highly motivated and dedicated
Senior Information Security Governance Expert (all genders)
Full time and permanent
Responsibilities:
- Support the implementation of the ISO 27001 standard across the organisation with the ability to take the lead on some specific domains such as Identity & Access Management, IT Operation Security, Asset Management or Secure software Development
- Support the ISMS certification programs, including taking part to internal and external audits
- Ensure that the organization information security policies are maintained and remain relevant for the organization
- Initiate and control the implementation of information security measures
- Initiate and coordinate target group-oriented awareness and training measures on the topic of information security
- Conduct Information Security risk assessments (ISMS risks, application and infrastructure risks, TPRM)
- Support customer security assessments and performing supplier security assessments
- Support information security incidents management
Qualifications:
- Bachelor's or Master's degree in Business Administration, Information Technology, or a related field or an equivalent qualification, or equivalent work experience
- Sound professional working experience in a complex Information Security Governance environment, including practical years of acting in global information security organizations and belonging teams, ideally in a highly regulated field such as pharmaceuticals, biotech, or healthcare
- Profound technical knowledge of security technologies as well as of enterprise IT Security solutions
- Excellent knowledge of security management systems and respective standards (ISO 27001, NIST, CIS, GMP)
- Industry certifications such as PMP, ITIL, Agile are a plus
- Industry certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISSP, CISM, SANS, GSEC etc. desired
- Experience in leading projects in terms of design and assessment of information security structures and processes
- Proven track record in dealing with complex information security & change projects and meeting conflicting situations and crisis scenarios
- Ability to adapt to a fast-moving information security landscape and keep pace with latest concepts, new security challenges and cyber threats
- Thrives on change, showing an ability to develop the information’s security constantly forward
- Proficiency in verbal and written communication in English. German, French or Italian language skills are an advantage
Our offer (Hamburg, Germany based):
- A position within a vigorous and exciting professional environment promoted by an open culture and a spirit of community
- A diverse, international workforce with a dynamic working environment that fosters creativity, innovations and teamwork
- 30 days of annual holiday, monthly allowance for public transportation, and in-house canteen
- Capital forming benefits, flexible working hours, holiday pay, and annual bonus depending on performance
- Benefits may vary by location and will be discussed separately
To apply, please click on the “Apply” button and provide your application documents (CV and cover letter, including earliest possible start date and salary requirements). We are looking forward to getting to know you and to your application.
FR : Dans le cadre de sa politique Diversité, Evotec étudie, à compétences égales, toutes les candidatures dont celles des personnes en situation de handicap.
ENG : In the frame of our Diversity policy, Evotec considers, with equal competences, all applications including people with disabilities.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Audits CISM CISSP Governance GSEC ISMS ISO 27001 ITIL NIST Risk assessment SANS Security assessment
Perks/benefits: Flex hours Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.