Information Security & Compliance Lead (m/w/d)
Polen
Asseco Solutions
✓ Erfahrung ✓ Zuverlässigkeit ✓ Sicherheit ✓ Innovation ✓ Fokus auf gehobenen Mittelstand - vereinfachen Sie Ihren Arbeitsalltag mit APplus. ▶ Mehr erfahren.Deine Aufgaben
We are seeking an experienced Information Security & Compliance Lead to take ownership of our organization’s security governance, risk, and compliance programs. This role is critical in maintaining our ISO 27001 certification, strengthening our security posture, and ensuring regulatory compliance across all business functions. The ideal candidate will drive a culture of security and collaborate closely with internal stakeholders, control owners, and external partners to uphold robust security standards.- Maintain and continuously improve the ISO 27001 Information Security Management System (ISMS).
- Collaborate with control owners to ensure timely and effective implementation of technical and organizational controls.
- Lead and conduct internal audits, coordinate external audits, and manage audit findings to closure.
- Drive and maintain a risk management process, including risk identification, assessment, treatment, and reporting.
- Own and update security policies, procedures, and awareness programs across the organization.
- Conduct vendor and third-party security assessments (including DPAs and security questionnaires).
- Prepare and deliver risk and compliance reports for the Head of IT and the Board of Directors.
- Monitor changes in relevant laws and regulations (e.g., GDPR, NIS2) and adjust practices accordingly.
- Support incident response planning and exercises in cooperation with technical teams.
- Collaborate with IT, Legal, HR, and other functions to ensure alignment on compliance requirements and initiatives.
Dein Profil
- Proven experience (3+ years) in Information Security, Risk, or Compliance roles.
- In-depth knowledge of ISO 27001 standards and certification process.
- Experience conducting internal audits and managing external audits.
- Familiarity with frameworks such as NIST, CIS, ITIL, or COBIT.
- Strong understanding of risk management principles, data protection (e.g., GDPR), and regulatory compliance.
- Excellent communication skills with ability to present to senior management and non-technical stakeholders.
- Ability to work independently, influence others, and drive cross-functional initiatives.
- Experience with GRC tools, vendor assessment platforms, or audit management tools is a plus.
Unser Angebot
- A diverse working environment in which you can contribute your own ideas and potential in the long term.
- Intensive induction and development opportunities for your professional and personal development in our in-house training center, as well as support from a mentor.
- Flat hierarchies and an open corporate culture that values teamwork and fun at work.
- Flexible trust-based working hours with mobile office options and an attractive salary package including standard benefits (MultiSport, LuxMed, Life Insurance, etc.)
- If you're in the office, we enrich everyday working life with coffee, drinks, company parties and team events.
Unsere Kontaktdaten
Asseco Solutions AG
People & CultureAmalienbadstraße 41c
76227 Karlsruhe
Deutschland
jobs.dach@assecosol.com
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: Audits CISM CISSP COBIT Compliance GDPR Governance Incident response ISMS ISO 27001 ITIL NIS2 NIST Risk management Security assessment
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsSenior Information Security Engineer jobsChief Information Security Officer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsSenior Software Engineer jobsSecurity Operations Analyst jobsSenior IT Auditor jobs
EDR jobsSaaS jobsCEH jobsEncryption jobsJava jobsSplunk jobsThreat detection jobsTop Secret jobsSDLC jobsTerraform jobsMalware jobsIDS jobsRMF jobsIPS jobsSQL jobsSOC 2 jobsFinance jobsDocker jobsForensics jobsCompTIA jobsOWASP jobsIntrusion detection jobsActive Directory jobsVPN jobsITIL jobs
HIPAA jobsAnsible jobsGIAC jobsClearance Required jobsCRISC jobsIT infrastructure jobsTCP/IP jobsDoDD 8570 jobsOSCP jobsMITRE ATT&CK jobsSOAR jobsZero Trust jobsBanking jobsSOX jobsIndustrial jobsData Analytics jobsJira jobsDNS jobsCCSP jobsNIST 800-53 jobsGCIH jobsCISO jobsArtificial Intelligence jobsUNIX jobsJavaScript jobs