Information Security & Compliance Lead (m/w/d)
Polen
Asseco Solutions
Deine Aufgaben
We are seeking an experienced Information Security & Compliance Lead to take ownership of our organization’s security governance, risk, and compliance programs. This role is critical in maintaining our ISO 27001 certification, strengthening our security posture, and ensuring regulatory compliance across all business functions. The ideal candidate will drive a culture of security and collaborate closely with internal stakeholders, control owners, and external partners to uphold robust security standards.- Maintain and continuously improve the ISO 27001 Information Security Management System (ISMS).
- Collaborate with control owners to ensure timely and effective implementation of technical and organizational controls.
- Lead and conduct internal audits, coordinate external audits, and manage audit findings to closure.
- Drive and maintain a risk management process, including risk identification, assessment, treatment, and reporting.
- Own and update security policies, procedures, and awareness programs across the organization.
- Conduct vendor and third-party security assessments (including DPAs and security questionnaires).
- Prepare and deliver risk and compliance reports for the Head of IT and the Board of Directors.
- Monitor changes in relevant laws and regulations (e.g., GDPR, NIS2) and adjust practices accordingly.
- Support incident response planning and exercises in cooperation with technical teams.
- Collaborate with IT, Legal, HR, and other functions to ensure alignment on compliance requirements and initiatives.
Dein Profil
- Proven experience (3+ years) in Information Security, Risk, or Compliance roles.
- In-depth knowledge of ISO 27001 standards and certification process.
- Experience conducting internal audits and managing external audits.
- Familiarity with frameworks such as NIST, CIS, ITIL, or COBIT.
- Strong understanding of risk management principles, data protection (e.g., GDPR), and regulatory compliance.
- Excellent communication skills with ability to present to senior management and non-technical stakeholders.
- Ability to work independently, influence others, and drive cross-functional initiatives.
- Experience with GRC tools, vendor assessment platforms, or audit management tools is a plus.
Unser Angebot
- A diverse working environment in which you can contribute your own ideas and potential in the long term.
- Intensive induction and development opportunities for your professional and personal development in our in-house training center, as well as support from a mentor.
- Flat hierarchies and an open corporate culture that values teamwork and fun at work.
- Flexible trust-based working hours with mobile office options and an attractive salary package including standard benefits (MultiSport, LuxMed, Life Insurance, etc.)
- If you're in the office, we enrich everyday working life with coffee, drinks, company parties and team events.
Unsere Kontaktdaten
Asseco Solutions AG
People & CultureAmalienbadstraße 41c
76227 Karlsruhe
Deutschland
jobs.dach@assecosol.com
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: Audits CISM CISSP COBIT Compliance GDPR Governance Incident response ISMS ISO 27001 ITIL NIS2 NIST Risk management Security assessment
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsInformation Security Specialist jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSystems Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
TS/SCI jobsEDR jobsSaaS jobsBash jobsJava jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsIPS jobsSOC 2 jobsSQL jobsMalware jobsFinance jobsForensics jobsCompTIA jobsDocker jobsActive Directory jobsGIAC jobsIntrusion detection jobsITIL jobsDoDD 8570 jobs
VPN jobsOWASP jobsHIPAA jobsCRISC jobsIT infrastructure jobsAnsible jobsTCP/IP jobsCCSP jobsData Analytics jobsClearance Required jobsNIST 800-53 jobsOSCP jobsMITRE ATT&CK jobsBanking jobsZero Trust jobsCISO jobsUNIX jobsSOAR jobsDNS jobsIndustrial jobsJira jobsSOX jobsEndpoint security jobsPolygraph jobsJavaScript jobs