Role purpose:

  • The Security and Compliance SME Works closely with the Global Office IT Security & Compliance Manager to ensure that Global Office IT meets security and compliance requirements.

Key accountabilities and decision ownership:
Security Governance and Compliance:

  • Identify, assess, and manage Global Office IT’s ability to meet all security and compliance requirements.
  • Prepare road map for improvement (enhanced security posture, operational processes/procedures, etc..) based on gaps identified.
  • Engage with Global Office IT domains to drive initiatives to close the gaps.
  • Enforce Security Controls as per applicable standards & Regulations (ISO, GDPR, etc.)
  • Internal Audit of ISO 27001 controls
  • Publish compliance reports Other:

  • Willing to work according to the German calendar in terms of the weekends and the public holidays according to the shift schedule

  • Represent Security and Compliance function topics in Office IT-related team meetings - Core competencies, knowledge, and experience: IT Auditor (Internal/External)
  • ISO 27001 (Lead implementer/ Lead Auditor) certified or experience in implementing ISO 27001 framework
  • Experience with SOX testing and IT General Controls (ITGC) framework
  • Preferably Certified Information Systems Auditor (CISA) and/or Certified Information Systems Security Professional (CISSP) professional
  • IT Risk assessment, risk management experience
  • Working experience in Data Privacy and Data Security frameworks and controls (encryption, GDPR, PKI, etc..) preferable.
  • Working experience in Cyber Security (Anti-virus, Patching, Vulnerability Management, etc..) is preferable

Must have technical/professional qualifications:

  • Education:_
  • BSC in Computer Engineering or Computer Science
  • Work Experience:_
  • 6+ years of experience in IT/Information Security
  • ISO27001 knowledge is a must
  • English fluency is a must

movewithus #_VOIS