Назад
Company hidden
8 часов назад

(Senior) Information Security Officer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
(Senior) Information Security Officer (Cybersecurity): Supporting customer security engagements, ISO 27001-aligned ISMS operations, audits, risk assessments, and platform security oversight with an accent on regulated financial customers, compliance frameworks, and stakeholder communication. Focus on responding to security questionnaires and RFPs, strengthening endpoint and access security, coordinating audits, and translating complex security topics for technical and non-technical audiences.

Location: Hybrid in Munich or Berlin, Germany

Company

hirify.global provides AI-supported anti-money laundering and fraud detection technology for banks and payment providers.

What you will do

  • Respond to security questionnaires, RFPs, and due-diligence requests with Sales and Pre-Sales.
  • Explain Hawk’s security posture and technical, compliance, and infrastructure controls to customers and regulated financial institutions.
  • Operate and improve the ISO 27001-aligned ISMS, including documentation, evidence gathering, audits, risk assessments, and corrective actions.
  • Monitor the security posture of corporate tools, infrastructure, integrations, and third-party vendors.
  • Collaborate with Information Security, IT, Engineering, Sales, Customer Success, and Procurement.
  • Contribute to security awareness, documentation, and operational processes.

Requirements

  • 5+ years of hands-on experience in Information Security, IT Security, or a related GRC role in a B2B technology or SaaS environment.
  • Experience operating and improving an ISO 27001-aligned ISMS, including policies, risk assessments, internal audits, and certification maintenance.
  • Working knowledge of SOC 2, DORA, and NIS 2, plus solid fundamentals in authentication, endpoint security, encryption, and networking.
  • Technical competence across macOS, Windows, and Linux, with experience coordinating external auditors, certification bodies, or regulators.
  • Fluent German and English are mandatory for customer, auditor, and regulator engagement.
  • Strong communication, documentation, accuracy, and audit-readiness skills.

Nice to have

  • ISO 27001 Lead Implementer/Auditor, CISSP, CISM, CRISC, or CompTIA Security+ certification.
  • Experience with identity and access management tools such as JumpCloud or Okta, MDM solutions, and enterprise security platforms.
  • Experience with third-party risk management, vendor security assessments, SaaS security tooling, or security questionnaires for regulated financial customers.
  • Familiarity with GDPR in a security context.

Culture & Benefits

  • Culture based on mutual trust, support, and passion.
  • Opportunities for professional growth and meaningful work in the fight against money laundering, fraud, and terrorist financing.
  • Collaboration across security, engineering, IT, commercial, customer, and procurement functions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →