Senior Manager Compliance & Information Security
Location
Germany
Posted
2 days ago
Salary
0
Seniority
Lead
Job Description
Senior Manager Compliance & Information Security
Nitrobox
Role Description Compliance ist für dich kein Selbstzweck. Vielmehr möchtest du Strukturen entwickeln, die Vertrauen schaffen und gleichzeitig schnelle Entscheidungen ermöglichen. Du verstehst Informationssicherheit als Wettbewerbsvorteil und Governance als Fundament für nachhaltiges Wachstum. Du denkst strategisch, arbeitest pragmatisch und verlierst auch bei komplexen regulatorischen Anforderungen nie den Blick für das Wesentliche. Auditoren überzeugst du mit belastbaren Nachweisen, interne Teams mit sinnvollen Lösungen und unsere Kunden mit Professionalität und Kompetenz. Wir sind ISO 27001- und TISAX-zertifiziert und entwickeln unsere Assurance-Landschaft konsequent weiter. Der Aufbau eines internen Kontrollsystems nach ISAE 3402 / IDW PS 951 läuft bereits, SOC 2 Type II ist der nächste große Meilenstein. Genau hier kommst du ins Spiel. Deine Mission: - Du übernimmst die fachliche Verantwortung für Compliance und Information Security bei instellix und entwickelst unsere Governance-Landschaft konsequent weiter. - Gemeinsam mit unserer Informationssicherheitsbeauftragten stellst du sicher, dass unsere Sicherheits- und Compliance-Standards nicht nur Audits bestehen, sondern unseren Kunden jeden Tag Vertrauen geben. - Dabei arbeitest du eng mit Engineering, Product, People, Finance und der Geschäftsführung zusammen und sorgst dafür, dass Compliance als Enabler verstanden wird – nicht als Hindernis. Was gehört dazu? - Du entwickelst unser Compliance-Programm strategisch weiter und übernimmst die fachliche Verantwortung für unseren Compliance- und Information-Security-Bereich. - Du verantwortest die kontinuierliche Weiterentwicklung unseres Informationssicherheitsmanagementsystems nach ISO 27001:2022 – von Management Reviews über Zielplanung bis hin zu Überwachungs- und Rezertifizierungsaudits. - Du baust unser internes Kontrollsystem nach ISAE 3402 / IDW PS 951 weiter aus, etablierst belastbare Nachweis- und Evidenzprozesse und koordinierst die Zusammenarbeit mit Wirtschaftsprüfern. - Du führst unser SOC-2-Programm ein und steuerst sämtliche Aktivitäten von der System Description bis zur erfolgreichen Type-II-Prüfung. - Du entwickelst unsere Security Governance kontinuierlich weiter – von Richtlinien über Vendor-Management bis hin zu organisatorischen und technischen Sicherheitsmaßnahmen. - Du beobachtest regulatorische Entwicklungen wie NIS2, EU AI Act oder neue Compliance-Anforderungen und übersetzt sie in praktikable Maßnahmen für unser Unternehmen. - Du unterstützt unseren Vertrieb bei Enterprise-Kunden, beantwortest Security-Fragebögen, begleitest Kundenaudits und bist kompetente Ansprechperson für alle Security- und Compliance-Themen. - Du übernimmst als Senior Verantwortung über deine eigenen Aufgaben hinaus. Du hinterfragst bestehende Prozesse, entwickelst Strukturen weiter und bist Sparringspartner für Management und Fachbereiche. Qualifications - Du verfügst über mindestens fünf Jahre Berufserfahrung im Bereich Information Security Governance, IT-Compliance oder IT-Audit – beispielsweise in einer Wirtschaftsprüfungsgesellschaft, einer Beratung oder einem SaaS-Unternehmen. - Du hast praktische Erfahrung mit mindestens zwei relevanten Frameworks wie ISO 27001, ISAE 3402 / IDW PS 951, SOC 2 oder TISAX und idealerweise bereits Kontrollsysteme aufgebaut oder Audits verantwortlich begleitet. - Du verfügst über ein solides technisches Verständnis und kannst mit Engineering-Teams auf Augenhöhe über Cloud-Architekturen, Zugriffskonzepte, Change Management oder Verschlüsselung sprechen. - Du kommunizierst sicher mit Auditoren, Wirtschaftsprüfern, Enterprise-Kunden und internen Stakeholdern und schaffst es, komplexe Anforderungen verständlich zu vermitteln. - Du arbeitest strukturiert, eigenverantwortlich und lösungsorientiert. Statt Prozesse lediglich zu verwalten, entwickelst du sie aktiv weiter. - Du verstehst Compliance als Business Enabler. Dein Anspruch ist es, Anforderungen so umzusetzen, dass sie Sicherheit schaffen, ohne unnötige Bürokratie zu erzeugen. - Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift runden dein Profil ab. Requirements - Zertifizierungen wie CISA, CISM oder ISO 27001 Lead Implementer bzw. Lead Auditor sind ein Plus, kein Muss. - Erfahrung mit Compliance-Automatisierungslösungen wie Vanta oder Drata. - Kenntnisse zu GoBD, Datenschutz, NIS2 oder dem EU AI Act. Benefits - Gestaltung statt Verwaltung – Du übernimmst eine neu geschaffene Schlüsselrolle mit direkter Berichtslinie an die Geschäftsführung und großem Gestaltungsspielraum. - Starkes Fundament – Du baust nicht bei null auf. Ein zertifiziertes ISMS, etablierte Prozesse, eine klare Roadmap und eine erfahrene Informationssicherheitsbeauftragte bilden die Basis für deine Arbeit. - Innovatives Produkt – Du arbeitest mit an unserer SaaS-Plattform instellix, die den stark wachsenden Markt für Subscription Management, Billing, Payment und Accounting nachhaltig verändert. - Kollegiale Kultur – Unsere Zusammenarbeit basiert auf Vertrauen, Eigenverantwortung, Verbindlichkeit und dem gemeinsamen Anspruch, die beste Lösung zu finden. - Work-Life-Balance – Mit 100 % Remote-Arbeit innerhalb Deutschlands sowie flexiblen Arbeitszeiten ohne Kernzeiten kannst du Beruf und Privatleben optimal verbinden. - Teamevents – Obwohl wir deutschlandweit verteilt arbeiten, kommen wir regelmäßig zusammen. Ob Sommerfest, Offsites oder Weihnachtsfeier – wir investieren bewusst in persönliche Begegnungen. - Freiraum – Du erhältst die Freiheit, Ideen einzubringen, Verantwortung zu übernehmen und nachhaltige Veränderungen umzusetzen. Next Steps Wenn du Compliance nicht als Selbstzweck, sondern als strategischen Erfolgsfaktor verstehst und Lust hast, den nächsten Reifegrad unserer Governance-Landschaft aktiv mitzugestalten, freuen wir uns auf deine Bewerbung. Sende uns deinen Lebenslauf, relevante Zeugnisse sowie – wenn du möchtest – ein Anschreiben. Teile uns außerdem deine Verfügbarkeit und deine Gehaltsvorstellung mit. Wir freuen uns darauf, dich kennenzulernen.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description We're looking for a highly motivated Staff Security Engineer to join our DevSecOps team and help build and operate the security foundation of Nue's platform and engineering systems. This is not a policy or analyst role. We want someone who is hands-on, writes code, automates security controls, improves infrastructure, hardens systems, and helps engineers ship safely at speed. You'll work at the intersection of software engineering, cloud infrastructure, security operations, and developer enablement. You'll partner closely with Product Engineering, Platform, and DevSecOps teams to reduce real risk through practical engineering. If you're passionate about securing cloud-native systems, building internal tooling, improving detection and response, and making security a force multiplier for engineering, this is the role for you. Responsibilities - Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows. - Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions. - Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery. - Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes. - Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement. - Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps. - Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems. - Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk. - Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices. - Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through. - Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets. Qualifications - Bachelor's degree in Computer Science, Engineering, or equivalent practical experience. - 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments. - 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles. - Strong hands-on experience securing cloud-native environments on AWS. - Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash. - Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows. - Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design. - Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms. - Practical experience with security monitoring, detection engineering, alert tuning, and incident response. - Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection. - Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness. - Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment. - Comfortable working in a fast-paced startup environment with a small, high-impact team. - Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck.
Information Security Officer
PROMOS consultBereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!
Role Description - Gestaltung, Weiterentwicklung und Verbesserung von Informationssicherheit in einem Unternehmen - Analyse von Risiken und Entwicklung pragmatischer Lösungen zur Erhöhung des Sicherheitsniveaus - Erstellung von Richtlinien, Standards und Sicherheitskonzepten - Beratung von Kolleginnen und Kollegen sowie Zusammenarbeit mit unterschiedlichen Fachbereichen - Begleitung von Projekten und Veränderungen aus Sicht der Informationssicherheit - Durchführung von Audits, Reviews und Sicherheitsbewertungen - Vermittlung von Sicherheitswissen durch Schulungen und Awareness-Maßnahmen - Beobachtung neuer gesetzlicher, regulatorischer und technologischer Entwicklungen im Bereich Informationssicherheit Qualifications - Studium oder vergleichbare Qualifikation im Bereich Informationssicherheit, IT, Wirtschaftsinformatik, Informatik oder einem ähnlichen Fachgebiet - Erste praktische Erfahrungen im Bereich Informationssicherheitsmanagement (ISMS) - Interesse an Informationssicherheitsstandards wie ISO 27001 und ISO 27002 - Gutes technisches Grundverständnis von IT-Systemen und Prozessen - Interesse an Themen wie Datenschutz, Compliance, NIS2 und regulatorischen Anforderungen - Strukturiert, zuverlässig und eigenverantwortlich arbeitend - Freude an der Kommunikation mit unterschiedlichen Ansprechpartnern und Wissen zu vermitteln - Wunsch nach kontinuierlicher fachlicher und persönlicher Weiterentwicklung Benefits - Flexible Arbeitszeiten und die Möglichkeit, wo du möchtest zu arbeiten: in unseren Büroräumen, im Home-Office oder mobil in und außerhalb Deutschlands - 30 Tage Urlaub, eine 39 Stunden-Woche bei Vollzeit oder individuelle Teilzeitmodelle - Faires und branchenorientiertes Gehalt, das deiner Erfahrung und Qualifikation entspricht - Ausgewogenes Programm rund um health@PROMOS, wie z.B. Urban Sports-Mitgliedschaft, JobRad, monatliche Gesundheitsangebote und Zuschuss zur Arbeitsplatzbrille - Regelmäßige Teamevents sowie jährliche Sommer- und Weihnachtsfeste - Weitere Benefits, die PROMOS zum Great Place to Work machen Company Description Bereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!
• Serve as the primary security advisor for client organizations • Develop and lead enterprise security strategies, roadmaps, and governance frameworks • Translate technical risk into business and financial impact for executive and board-level audiences • Lead incident response planning, tabletop exercises, and breach investigations • Conduct risk assessments and maturity evaluations aligned to NIST, CIS, ISO, and other frameworks • Build and mature security programs, policies, and compliance initiatives • Establish and guide vendor risk and third-party risk programs • Deliver regular executive reporting on security posture, risk trends, and program progress • Partner with IT, architecture, and business leaders to embed security into operations • Stay ahead of emerging threats, technologies, and regulatory requirements
Security Officer
Charles River LaboratoriesCharles River Laboratories is a global company offering products and services to help biotechnology and pharmaceutical companies, government agencies, and acade
Title: Security Officer - Worcester, MA (Sat & Sun, 6p-6a) Req ID #: 234911 Location: Worcester, MA, US, 01608 Workplace: Part-Time Department: Operations Job Overview Charles River Laboratories is seeking a PART TIME (24 hrs. per week, benefit eligible) Security Officer for the Worcester, MA site. Shift is overnights, Saturday & Sunday, 6pm-6am (12hrs) + 15% Shift Differential Following established procedures and guidelines, monitor and ensure compliance with company security and safety policies. Monitor all access activities to the facility by checking and issuing security badges. Monitor security, safety and integrity of buildings and environs and respond to any unusual circumstances. Protect facility from unwanted actions or espionage. Provide a safe and secure environment for employees, clients, visitors and animals. ESSENTIAL DUTIES AND RESPONSIBILITIES: - Greet, screen, record and allow visitors and employees admittance to the site in accordance with company procedures. - Monitor security systems and/or environmental systems and investigate and/or report any incidents. - Report all unauthorized persons to the proper authorities and initiate action to protect employees, animals, products, and physical site. In so doing, the incumbent should not place him or herself in harm’s way. - Ensure the physical safety and security of the facility by enforcing company policies and procedures; provide a deterrent and detection factor for wrongful activity; conducts patrols and monitors the status of the physcial security measures; and monitors the critical building systems. - Physically walk the facility grounds to complete visual inspection of site security on regularly scheduled tours. - Document all security department activity and generates incident reports as necessary. - Monitor facility equipment during tours and report equipment failure, reset alarms as instructed and/or assist in minor repair as directed. Provides effective secondary communication during business hours; and primary communications during non-business hours. - Contact emergency personnel as required and in accordance with adherence to pertinent departmental policies, practices, and procedures. - Assist in directing appropriate emergency response efforts when required. - Perform all other related duties as assigned. Qualifications - Education: High school diploma, General Education Degree (G.E.D.) or the equivalent. Associates degree preferred. - Experience: 2 -3 years experience with at least six to twelve months of related security experience and/or training. - An equivalent combination of education and experience may be accepted as a satisfactory substitute for the specific education and experience listed above. - Must be willing to work on a Part time schedule – 24hrs per week (position will be Benefits Eligible) - Shift: Sat & Sun 6pm-6am (12hrs) + 15% Differential. The base pay for this position is $22/hr. + 15% shift differential. Please note that salaries vary within the range (if applicable) based on factors including, but not limited to, experience, skills, education, certifications, and location. About Corporate Functions The Corporate Functions provide operational support across Charles River in areas such as Human Resources, Finance, IT, Legal, Sales, Quality Assurance, Marketing, and Corporate Development. They partner with their colleagues across the company to develop and drive strategies and to set global standards. The functions are essential to providing a bridge between strategic vision and operational readiness, to ensure ongoing functional innovation and capability improvement. About Charles River Charles River is an early-stage contract research organization (CRO). We have built upon our foundation of laboratory animal medicine and science to develop a diverse portfolio of discovery and safety assessment services, both Good Laboratory Practice (GLP) and non-GLP, to support clients from target identification through preclinical development. Charles River also provides a suite of products and services to support our clients’ clinical laboratory testing needs and manufacturing activities. Utilizing this broad portfolio of products and services enables our clients to create a more flexible drug development model, which reduces their costs, enhances their productivity and effectiveness to increase speed to market. With over 20,000 employees within 110 facilities in over 20 countries around the globe, we are strategically positioned to coordinate worldwide resources and apply multidisciplinary perspectives in resolving our client’s unique challenges. Our client base includes global pharmaceutical companies, biotechnology companies, government agencies and hospitals and academic institutions around the world. At Charles River, we are passionate about our role in improving the quality of people’s lives. Our mission, our excellent science and our strong sense of purpose guide us in all that we do, and we approach each day with the knowledge that our work helps to improve the health and well-being of many across the globe. We have proudly worked on 80% of the drugs approved by the U.S. Food and Drug Administration (FDA) in the past five years. We’re committed to providing benefits that elevate your quality of life. Based on your position these may include: bonus/incentives based on performance, 401K, paid time off, stock purchase program, Health and wellness coverage, employee and family wellbeing support programs, and work life balance flexibility. Equal Employment Opportunity Charles River is an equal opportunity employer and is committed to providing equal employment opportunities for all qualified applicants and employees without regard to race, color, sex, religion, national origin, ancestry, age, mental or physical disability, family status, pregnancy, military or veteran status, or any other characteristic protected by federal, state, or local laws. It is unlawful in some states (including Massachusetts) to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

