Information Security Manager*
Role details
Job location
Tech stack
Job description
The Information Security Manager is responsible for establishing, coordinating, and maintaining all information security-related activities within the division. The role ensures compliance with relevant security standards and regulatory requirements (e.g. NIS2, ISO/IEC 27001, Cyber Resilience Act), supports secure processes across IT, OT, and product environments, and aligns divisional practices with Group Security Strategy. The position acts as the divisional subject-matter expert and single point of contact for security, operating independently and cross-functionally., * Information Security Management: Define and maintain division-specific security policies, standards, and procedures; perform risk assessments; manage the security risk register; and support correct information classification and protection
- Regulatory Compliance (NIS2 / ISO 27001 / CRA): Lead divisional readiness for NIS2 and ISO/IEC 27001, coordinate audits and documentation, and support product-related cybersecurity requirements in line with the Cyber Resilience Act; maintain a regulatory dotted-line reporting relationship to the EVP to ensure transparency and escalation on compliance-relevant matters
- Security Operations & Incident Handling: Serve as divisional coordinator for security incidents and align with Group processes, including vulnerability management and remediation tracking
- Supplier & Third-Party Security: Conduct supplier security assessments, ensure contractual requirements are met, and follow up on deviations and corrective actions
- Awareness & Training: Coordinate mandatory security awareness activities and enable role-based security competence across relevant teams
- Project & Product Security Support: Advise ISM, R&D, Operations, and other functions on necessary security requirements, ensuring their integration into projects, products, systems, and processes
- Governance, Process Oversight & Reporting: Define, monitor, and continuously improve security-relevant governance and compliance processes; act as senior escalation authority for internal and external audits; prepare regular reports on security status, risks, and KPIs for divisional management; and ensure close alignment with Group Security and other divisions, What will you get in return for all the great things you bring to the table?
- 30 days of annual leave
- Subsidized company pension plan
- Subsidized group accident insurance
- Hybrid working model
- Flexible working hours
- Opportunity to purchase TOMRA shares at a discounted rate
- Employee discounts for various online shops via Corporate Benefits
- Company (e-)bike leasing
- Subsidy for gym memberships
- Employee Resource Groups (ERGs) for Women, LGBTQ, and Roots
- Health management programs
- On-site canteen and parking garage
Requirements
Do you have experience in Risk management?, * University degree in Information Security, Computer Science or comparable qualification
- Several years of experience in information security, cybersecurity, or risk management
- Experience with ISO/IEC 27001, NIS2 implementation, incident response, and supplier/security governance
- Experience in industrial or product-oriented environments (IT/OT) is an advantage
- Strong communication and facilitation skills paired with a structured, independent working style
- Able to operate independently and reliably as a "one-person function" while coordinating cross-functional stakeholders
- Strong communication skills with the ability to translate complex security topics into actionable guidance
- High degree of integrity, confidentiality, and resilience
- Very good English skills; German is beneficial