Information Security Officer
TypeFull-time job
LocationGermany
Posted3 hours ago
The Role
As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.
We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.
Your Responsibilities
Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
Manage risk across technical and organizational domains, including reporting to executive management
Steer external consultants and service providers within the running programme
Build and run the security awareness programme: training and sensitization
Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
Assess third-party and vendor risk, run security assessments for new tools and partners
Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
Support sales and customer trust processes: security questionnaires, due diligence, customer audits
Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action
What You Bring
Several years of experience as an ISB or in comparable responsibility for information security
Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
Willingness to work hands-on during the build-up phase
Confident interaction with executive management, auditors, and customers
German at C1 or above, English at B2 or above
Nice to Have
Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM
Experience with security governance across multiple legal entities or jurisdictions
Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
Practical NIS-2 implementation experience
Experience with sales-adjacent security processes (pre-sales, customer audits)
What We Offer
International team with colleagues across Germany and other locations.
Startup environment with real ownership, flat hierarchies, and fast decisions.
Competitive compensation aligned with experience and responsibility.
Individual learning and growth opportunities beyond your role.
Originally posted on Himalayas
As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.
We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.
Your Responsibilities
Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
Manage risk across technical and organizational domains, including reporting to executive management
Steer external consultants and service providers within the running programme
Build and run the security awareness programme: training and sensitization
Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
Assess third-party and vendor risk, run security assessments for new tools and partners
Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
Support sales and customer trust processes: security questionnaires, due diligence, customer audits
Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action
What You Bring
Several years of experience as an ISB or in comparable responsibility for information security
Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
Willingness to work hands-on during the build-up phase
Confident interaction with executive management, auditors, and customers
German at C1 or above, English at B2 or above
Nice to Have
Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM
Experience with security governance across multiple legal entities or jurisdictions
Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
Practical NIS-2 implementation experience
Experience with sales-adjacent security processes (pre-sales, customer audits)
What We Offer
International team with colleagues across Germany and other locations.
Startup environment with real ownership, flat hierarchies, and fast decisions.
Competitive compensation aligned with experience and responsibility.
Individual learning and growth opportunities beyond your role.
Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.