Information Security Manager (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Security Manager (GRC): Ensuring that security governance, risk management, and compliance capabilities operate effectively across the organization with an accent on oversight, challenge, and assurance. Focus on identifying security risks, coordinating assurance reviews, and supporting regulatory compliance within the complex energy trading environment.
Location: Must be based in or be able to commute to Kassel, Germany (Hybrid role)
Company
is a leading international energy company headquartered in Germany, providing reliable energy solutions across the value chain to over 50,000 industrial and municipal clients.
What you will do
- Lead GRC activities and act as the primary security governance representative for assigned business areas.
- Identify, assess, and track security risks while developing effective treatment plans.
- Ensure internal security policies, standards, and controls are clearly understood and applied.
- Coordinate assurance reviews, control effectiveness checks, and support internal or external audits.
- Perform third-party and supplier security risk assessments to maintain supply chain integrity.
- Provide GRC expertise for major corporate projects and strategic change initiatives.
Requirements
- Proven experience in GRC, security risk governance, or compliance roles.
- Strong background in information security, cybersecurity, or IT risk management.
- Deep knowledge of security risk frameworks, policies, and internal control systems.
- Experience managing audits, assurance testing, and evidence collection.
- Ability to bridge communication between technical IT teams and business stakeholders.
- Proficiency in complex regulatory environments, such as energy, trading, or critical infrastructure.
Culture & Benefits
- Hybrid work model with flexible working hours.
- Comprehensive company pension scheme and competitive compensation.
- Professional growth support with an emphasis on knowledge development.
- Access to health and fitness programs, bike leasing, and job ticket.
- Inclusive, team-oriented culture with a modern workplace and company cafeteria.
- 30 days of annual vacation plus additional special leave.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →