Informationssicherheitsbeauftragter (ISB) at Orcrist Technologies | BE, DE | Rezi

Informationssicherheitsbeauftragter (ISB) at Orcrist Technologies

Informationssicherheitsbeauftragter (ISB)

Orcrist Technologies · BE, DE

1 weeks ago

Informationssicherheitsbeauftragter (ISB)

Orcrist Technologies · BE, DE

12 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Informationssicherheitsbeauftragter (ISB) role.

Rezi rewrites your resume against Orcrist Technologies's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Informationssicherheitsbeauftragter (ISB) posting at Orcrist Technologies — free, in seconds.

About the Role

Orcrist is building a next generation data intelligence platform using cutting-edge technologies. We’re handling petabyte-scale data with sub-second queries. Our product is a Kubernetes-based platform delivered as B2B SaaS or as a self-hosted on-prem solution, including air-gapped deployments. We enable customers across defense, law enforcement, and enterprise to turn mission-critical data into actionable intelligence by fusing data processing, ML, and intuitive UX. As Group Information Security Officer (ISB), you will be responsible for the information security strategy, program, and security posture of the Vektor Group, from strategic direction to practical implementation. You will work closely and operationally with the Director Internal IT, especially on technical controls and their implementation. Your central mission is ISO 27001 certification based on BSI IT-Grundschutz and the implementation of NIS-2 requirements. You will guide the entire process – from gap analysis and control implementation through audit readiness and ongoing maintenance to the regulatory obligations of both frameworks. We develop AI platforms for customers from the defense and public sectors. Information security is a prerequisite for our business – not a downstream process. At the same time, we are expanding our security organization in parallel with the group's growth. In this phase, you and the management will be hands-on: you will take care of operational security issues in day-to-day business, directly support the IT team, and also take on tasks that go beyond the boundaries of a classic governance role. We will be supported by external consultants in the setup. As the ISMS and the team mature, your focus will shift more towards strategy, governance, and further development.

Responsibilities

  • Build and continuously develop the group-wide ISMS according to BSI IT-Grundschutz, including structural analysis, determination of protection needs, modeling, and risk analysis.
  • Create and maintain the group-wide security policy and process framework and coordinate company-specific additions.
  • Prepare and accompany the ISO 27001 certification, conduct internal audits, and collaborate with external auditors.
  • Implement NIS-2 requirements, particularly reporting processes, evidence management, and tracking of corrective actions.
  • Manage risks across technical and organizational areas, assess and prioritize them, and prepare them for management.
  • Coordinate external consultants and service providers within the ongoing security program.
  • Build and operate our security awareness program, from training to continuous sensitization.
  • Plan and further develop our incident response processes and coordinate in emergencies with IT, Legal, and responsible management.
  • Assess third-party and vendor risks and conduct security assessments for new tools, service providers, and partners.
  • Work closely with the Director Internal IT on technical controls such as access governance, endpoint security, and identity, and with Platform Engineering at the interface to Product Security.
  • Support Sales and Customer Trust processes, e.g., with security questionnaires, due diligence inquiries, and customer audits.
  • Monitor further regulatory requirements, including the EU AI Act and Cyber Resilience Act, and derive concrete measures for the group.

Requirements

  • Several years of experience as an ISB or in a comparable responsible role in information security.
  • Sound practical experience with BSI IT-Grundschutz, especially BSI Standards 200-x and the Grundschutz Compendium – ideally including a completed certification process.
  • Experience building or managing ISO 27001 programs and practical knowledge from gap analysis to audit readiness.
  • Proficiency in risk management: ability to assess and prioritize risks and clearly communicate complex issues to both technical and non-technical stakeholders.
  • Willingness to be hands-on during the setup phase and not delegate operational tasks.
  • Comfortable interacting with management, auditors, and customers, and able to reconcile different interests and perspectives.
  • German language skills at C1 level or higher and English at B2 level or higher.

Skills

  • BSI IT-Grundschutz
  • ISO 27001
  • Risk Management
  • Incident Response
  • Security Awareness Programs
  • Third-Party Risk Assessment
  • Technical Controls (Access Governance, Endpoint Security, Identity)
  • Product Security
  • Security Questionnaires
  • Due Diligence
  • EU AI Act
  • Cyber Resilience Act

Location

  • Remote-first in Germany

Work Type

  • Remote
  • Full-time

Experience Level

  • Several years of experience

Benefits

  • Competitive compensation
  • 30 vacation days
  • Equipment budget
  • Learning budget

About the Company

  • Orcrist is building a next generation data intelligence platform using cutting-edge technologies.
  • We’re handling petabyte-scale data with sub-second queries.
  • Our product is a Kubernetes-based platform delivered as B2B SaaS or as a self-hosted on-prem solution, including air-gapped deployments.
  • We enable customers across defense, law enforcement, and enterprise to turn mission-critical data into actionable intelligence by fusing data processing, ML, and intuitive UX.
  • We develop AI platforms for customers from the defense and public sectors.
  • Information security is a prerequisite for our business – not a downstream process.
  • We are expanding our security organization in parallel with the group's growth.
  • We offer an international team with colleagues in Germany and other locations.
  • Startup environment with real scope for design, flat hierarchies, and quick decisions.