About the Role
The Director Physical Security owns everything in security that isn't IT/cyber, including people, sites, material, and processes. This role builds and runs the group's physical and organizational security program largely from scratch in an environment with classified work, sensitive hardware, and regulatory scrutiny.
Responsibilities
- Define and own the group-wide physical security strategy across all sites and entities, scaling it with company growth.
- Design, implement, and operate physical access control, perimeter protection, intrusion detection, CCTV, alarm management, and visitor/contractor management.
- Build and maintain the organizational security framework for classified work (VS-handling, Sicherheitsbereiche, secure storage) in line with the Geheimschutzhandbuch.
- Act as the operational interface to German authorities on industrial security and coordinate closely with the Sicherheitsbevollmächtigte(r).
- Manage the physical dimension of personnel security, including clearance-linked access, escorting rules, badge lifecycle, and onboarding/offboarding.
- Run crisis management, emergency response, evacuation, and business continuity planning for physical incidents.
- Ensure physical security across the supply chain and logistics, including secure transport, storage, and handling of sensitive hardware and prototypes.
- Secure company events, trade shows, and customer/site visits.
- Manage external security vendors, including budgets and SLAs.
- Develop policies, run audits, drills, and training; drive a security-awareness culture.
- Own the physical/organizational side of the insider-threat program, in coordination with IT Security and People & Culture.
- Ensure compliance with relevant defense and regulatory frameworks (SÜG, Geheimschutzhandbuch, NATO/EU classified standards, KRITIS/BSI, ITAR/EAR physical controls).
Requirements
- Several years leading physical/corporate security, ideally in defense, aerospace, critical infrastructure, or a comparably regulated and security-sensitive environment.
- Solid working knowledge of German Geheimschutz (Geheimschutzhandbuch, VS-handling, Sicherheitsbereiche) and the SÜG framework.
- Proven experience building a physical security program greenfield.
- Hands-on expertise with access control, CCTV, intrusion detection, and alarm systems, including relevant standards.
- Crisis/emergency management and business continuity experience.
- Comfortable operating in a remote-first, multi-site setup with frequent travel between locations.
- Fluent German and strong English.
- Eligible and willing to undergo a German Sicherheitsüberprüfung (typically Ü2/Ü3).
- Around 8–12+ years in security overall, with several years in a program-owning or leadership capacity, and a clear track record in regulated or high-sensitivity environments.
- Startup or scale-up experience is a strong plus.
Skills
- Physical access control
- Perimeter protection
- Intrusion detection
- CCTV
- Alarm management
- Visitor/contractor management
- Classified work handling (VS-handling)
- Secure storage
- Crisis management
- Emergency response
- Evacuation planning
- Business continuity planning
- Supply chain security
- Logistics security
- Security vendor management
- Policy development
- Auditing
- Drills
- Training
- Security awareness
- Insider-threat program management
- Regulatory compliance (SÜG, Geheimschutzhandbuch, NATO/EU classified standards, KRITIS/BSI, ITAR/EAR physical controls)
Location
- Multi-site
- Remote-first
Work Type
- Full-time
- Remote-first
Experience Level
- Director
- 8-12+ years overall security experience
- Several years in program-owning or leadership capacity
- Startup or scale-up experience a plus
Benefits
- International team
- Startup environment with ownership, flat hierarchies, and fast decisions
- Competitive compensation
- Individual learning and growth opportunities
About the Company
- Orcrist is building a next generation data intelligence platform using cutting-edge technologies.
- Handling petabyte-scale data with sub-second queries.
- Product (OIP) is a Kubernetes‑based platform delivered as B2B SaaS or as a self‑hosted/on‑prem solution, including air‑gapped deployments.
