Information Security Officer at Orcrist Technologies | BE, DE | Rezi

Information Security Officer at Orcrist Technologies

Information Security Officer

Orcrist Technologies · BE, DE

2 weeks ago

Information Security Officer

Orcrist Technologies · BE, DE

16 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Information Security Officer role.

Rezi rewrites your resume against Orcrist Technologies's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Information Security Officer posting at Orcrist Technologies — free, in seconds.

About the Role

As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance. We build AI platforms for customers in the defence and government sector, and information security is a precondition for our business. During this phase, everyone including leadership works hands-on, and external consultants support the ramp-up.

Responsibilities

  • Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
  • Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
  • Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
  • Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
  • Manage risk across technical and organizational domains, including reporting to executive management
  • Steer external consultants and service providers within the running programme
  • Build and run the security awareness programme: training and sensitization
  • Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
  • Assess third-party and vendor risk, run security assessments for new tools and partners
  • Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
  • Support sales and customer trust processes: security questionnaires, due diligence, customer audits
  • Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action

Requirements

  • Several years of experience as an ISB or in comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
  • Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
  • Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
  • Willingness to work hands-on during the build-up phase
  • Confident interaction with executive management, auditors, and customers
  • German at C1 or above, English at B2 or above

Skills

  • BSI IT-Grundschutz
  • ISO 27001
  • NIS-2 compliance
  • Risk management
  • Security awareness training
  • Incident response
  • Third-party risk assessment
  • Sales-adjacent security processes
  • EU AI Act
  • Cyber Resilience Act

Experience Level

  • Several years of experience

Benefits

  • Competitive compensation aligned with experience and responsibility
  • Individual learning and growth opportunities beyond your role

About the Company

  • We build AI platforms for customers in the defence and government sector.
  • International team with colleagues across Germany and other locations.
  • Startup environment with real ownership, flat hierarchies, and fast decisions.