Sobre el puesto
Permanent governance-risk-compliance role in operational cyber security for public-sector IT: certification readiness, risk and business-impact analysis, awareness and IT emergency management.
Responsabilidades
- Advise and technically support all operational information-security topics
- Prepare the organisation for ISO 27001 and critical-infrastructure certification
- Advise on technical and organisational measures (TOMs) under GDPR
- Run IT risk analyses and business impact analyses (BIA)
- Design and deliver security awareness workshops and training
- Advise on IT emergency management and business continuity management (BCM)
- Contribute findings to IT planning and IT strategy via the ITSM processes
La IA se encarga · Tú te encargas
La IA se encarga
Control mapping and gap analysis · Evidence collection · Policy and TOM first drafts · Risk register maintenance
Tú te encargas
Risk judgment · Certification readiness call · Stakeholder trust · Sign-off
Tu perfil
- Operational information security: key management (KMS), multi-factor authentication (MFA), SIEM, central logging
- ISO 27001, critical-infrastructure regulation, GDPR
- IT risk analysis, BIA, BCM and IT emergency management
- Jira and/or Confluence; IT infrastructure, operating systems, relational databases, software distribution
- User-management systems, cryptography, security controls on IT data flows
- German C1 or better
Titulación
- Degree in computer science or comparable qualification (or vocational IT training plus several years relevant work)
- 3+ years practical information-security experience with documented project references
- 1+ year hands-on with Jira and/or Confluence
- Security clearance is a precondition for this assignment