Information Security Manager (w/m/d)
- Hiring from
- Germany
- Work type
- Remote
- Posted
Is this job info correct?
Show job descriptionHide job description
Your mission
JTL-Software runs e-commerce software that our customers run their businesses on. Customers, partners and stakeholders trust in JTL to secure their information.
This role runs JTLs information security management system end to end: the ISO/IEC 27001:2022 ISMS, the internal audit programme, the policy and standard framework, the cyber risk register, and security awareness across the company. The goal is to demonstrate, that JTL successfully has established processes to continuously improve its security capabilities.
This is a hands-on role in the security team without management responsibility.
This role runs JTLs information security management system end to end: the ISO/IEC 27001:2022 ISMS, the internal audit programme, the policy and standard framework, the cyber risk register, and security awareness across the company. The goal is to demonstrate, that JTL successfully has established processes to continuously improve its security capabilities.
This is a hands-on role in the security team without management responsibility.
ISMS ownership
- Run and maintain the ISO/IEC 27001:2022 management system: scope, Statement of Applicability, control ownership, management review
- Prepare for and defend certification, surveillance and recertification audits
- Keep the evidence base current and collectible, and make it repeatable rather than a scramble before each audit
Internal audit
- Plan and run the internal audit programme against the control set
- Write findings that are specific enough to act on, and drive them to closure with the control owners
- Provide factual assurance to the management team
Policy and standards
- Own the policy and standard framework: authorship, review cycle, approval, publication, versioning
Risk management
- Run the cyber risk register: assessment, treatment plans, acceptance decisions, review cadence
External assurance
- Act as the single point of contact for customer security assessments, questionnaires and due diligence
- Run the response cycle for our investor's portfolio-wide cyber assessment
- Manage third-party and vendor security assessments, and the security half of the vendor onboarding process
Awareness and training
- Design and run the security awareness programme, including role-based training
- Measure whether it changed anything, and change it when it did not
Your profile
- You have personally owned an ISO/IEC 27001 ISMS and defended it in front of an external auditor, through certification, recertification or surveillance. Only advising or having provided implementation guidance is not enough for this role.
- You have planned and run internal audits, written the findings, and driven them to closure
- You have written a policy and control framework and then operated an ISMS on it for at least a year
- You have run a risk register where real treatment and acceptance decisions were made
- technical literacy to look at control evidence from an engineer and tell whether it proves the control
- Fluent English, written and spoken
Why us?
- Remote-first within Germany, with the option to work remotely from eligible countries for up to 180 days per year
- Meal allowance of up to €115 net per month
- Ergonomic workspace allowance for your home office setup
- Regular team events, company-wide gatherings, and summer and Christmas parties to stay connected as a remote-first company
- EGYM Wellpass and JobRad subsidy
- Financial benefits including capital-forming payments (Vermögenswirksame Leistungen) and a company pension scheme
About us
JTL is one of the leading providers of e-commerce software in the German-speaking region – with around 450 employees across the group and 50,000 customers from a wide range of industries. We develop scalable, flexible solutions for the online retail of the future – from ERP systems to shop and marketplace integrations.
Fairness and respect are part of our everyday practice. Are you committed, curious, and eager to work in a team while taking on responsibility? Are you looking for a job where Monday isn’t the worst day of the week? Then we look forward to receiving your application!