Login Enter

Projekt 3T GmbH

8 months ago

Chief Information Security Officer - CISO

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
Projekt 3T GmbH
Location
Hamburg Germany
Posted
8 months ago
View all jobs at Projekt 3T GmbH

Job description

Our client is a large, established organization in a highly regulated environment that has consistently developed towards digitalization, cloud transformation, and cyber resilience over several years. Information security and data protection possess high strategic relevance at the board level and are understood as essential prerequisites for sustainable business success.

In this context, a central 2nd-Line function with clear governance, steering, and control responsibilities is being reoriented and strengthened, and a new CISO role is being established.

Aufgaben

In this exposed role, you will take over the overarching responsibility for the governance of information security and privacy in accordance with the Three Lines of Defence model. You will act as a strategic instance, sparring partner to top management, and independent control function.

Your main tasks include:

  • Strategic steering of information security

  • Development of the company-wide information security strategy and architecture

  • Evaluation of existing security architectures, identification of structural weaknesses, and derivation of sustainable measures

  • Initiation of medium- and long-term security initiatives taking into account technological developments (e.g. cloud)

  • Information Security Management & Second-Line Governance

  • Total responsibility for the ISMS (e.g. ISO 27001-oriented) as well as information security risk management

  • Definition of policies, standards, and governance structures for the 1st Line

  • Etablishment of transparent reporting, escalation, and decision-making processes vis-à-vis the board and committees

  • Privacy Security & Data Protection Governance

  • Responsibility for privacy security governance in the 2nd Line

  • Definition of technical and organizational measures according to Art. 32 DSGVO in close coordination with the data protection officer

  • Integration of data protection requirements into the ISMS as well as establishment of analysis and evaluation frameworks (e.g. for data breaches)

  • Clear role definition for operational data protection function

  • Governance, Risk & Compliance

  • Steering regulatory requirements (e.g. DORA, DSGVO, VAIT/KRITIS depending on the context)

  • Active participation in risk, steering, and governance committees

  • Preliminary preparation and accompaniment of internal and external audits

  • Incident Governance & Cyber Resilience

  • Total responsibility for incident response and cyber resilience governance

  • Safeguarding clear processes for recognizing, evaluating, escalating, and post-processing security incidents

  • Steering internal and external specialists without operational daily responsibilities

  • Führung & Stakeholder Management

  • Leadership and further development of a strong, interdisciplinary security team

  • Counseling the board and top management on security and supervisory issues

  • Tight cooperation with IT, law, compliance, data protection, risk management, and specialist departments

Qualifikation

Sought is a souvereign leadership personality, who combines strategic thinking with regulatory depth and technical competence:

  • Completed studies in computer science, business informatics, IT security or comparable qualification
  • Multiple years of leadership experience in the field of information security, ideally as CISO or in a comparable senior function
  • Experience in highly regulated organizations (e.g. financial services, insurance, critical infrastructure)
  • Fundamental knowledge of relevant regulatory requirements (DSGVO, DORA etc.)
  • Broad technical competence (e.g. cloud security, IAM, incident management) paired with risk-oriented, strategic thinking
  • Outstanding communication, change, and stakeholder management skills, particularly at the top management level
  • High degree of integrity, assertiveness, and analytical strength

Desired certifications: CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CIPP/E or comparable; further relevant security certifications are advantageous.

Benefits

This position offers you an outstanding executive role with direct proximity to the board and high organizational visibility:

  • Larger strategic design scope in a security-critical transformation
  • Clear governance role with backing from top management
  • Leadership of a qualified and motivated expert team
  • Attractive, market-based total remuneration on executive level
  • Modern working environment with high investment in cyber security and resilience
  • Long-term perspective in an organization where information security is consistently top priority

Sounds exciting? Then let's talk!

Find more English Speaking Jobs in Germany on Arbeitnow

Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.