5 дней назад
Information Security Officer (Gaming & Competitions)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Officer (Gaming & Competitions) (ISO 27001/ISMS): Establishing and continuously improving the information security management system for gaming and competition platforms with an accent on governance, regulatory compliance, risk management, and secure development. Focus on leading ISO 27001 certification activities, driving remediation of vulnerabilities and control gaps, and advising product, business, and technology teams on application and cloud security.
Location: Hamburg, Germany; hybrid work arrangement
Company
is a European media business delivering publishing, audio, entertainment, gaming, and competition services across multiple markets.
What you will do
- Own and lead the Information Security programme for the Gaming & Competitions business.
- Establish, operate, and continuously improve the ISMS in line with Group policies and ISO/IEC 27001.
- Lead ISO 27001 certification, surveillance, recertification, audit, and assurance activities.
- Assess risks, identify control gaps, and drive remediation of vulnerabilities, audit findings, and security exposures.
- Guide product, business, and technology teams on threat modelling, secure coding, cloud security, application security testing, and software supply chain security.
- Support incident management and collaborate with architecture, engineering, operations, auditors, regulators, suppliers, and senior stakeholders.
Requirements
- Significant experience in information security, cybersecurity, technology risk, or a related discipline.
- Practical experience implementing, operating, and improving Information Security Management Systems.
- Strong knowledge of ISO/IEC 27001 and ISO/IEC 27002, including risk management, controls, audit preparation, and continuous improvement.
- Experience with application and development security, secure software development lifecycles, cloud technologies, APIs, CI/CD pipelines, and application security testing.
- Experience working with auditors, regulators, suppliers, and senior management, with strong analytical and stakeholder management skills.
- Fluent English is essential. A relevant degree or equivalent practical experience is required.
Nice to have
- Experience in gaming, competitions, or similarly regulated sectors.
- German or Polish language skills.
- Certifications such as CISSP, CISM, CRISC, CCSP, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
Culture & Benefits
- Flexible organisation of working hours and location within the hybrid setup.
- Individual professional and personal development training.
- 30 days of holiday and regular employee events.
- Health management programmes, free sports activities, and Wellhub.
- Deutschlandticket and bike-leasing subsidies, company restaurant, magazines, and corporate discounts.
- A culture focused on personal responsibility, teamwork, creativity, and long-term development.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
8 дней назад
Vice President & Chief Information Security Officer (Cybersecurity)
228 700 - 285 900$
DeepL
9 дней назад
Senior Information Security Manager (Cybersecurity)
8 дней назад
Security GRC Specialist (Fintech)
11 дней назад
Sr. Staff Customer Trust Manager (AI)
11 дней назад
Cybersecurity Lead Engineer/Architect (AI)
175 000 - 225 000$
10 дней назад