Information Security Officer (80-100%)
Role details
Job location
Tech stack
Job description
As Information Security Officer at Threema, you will be responsible for information security across the company. The role reports directly to the CTO. You will drive the development and formalization of our security program and bring the technical expertise to assess and contribute to the implementation of security measures.
Organizational responsibilities:
- Developing a company-wide security strategy
- Building and operating an Information Security Management System (ISMS)
- Developing and enforcing security policies
- Conducting risk assessments and business impact analyses
- Developing incident response and disaster recovery plans
- Supporting certification processes
- Ensuring compliance with data protection regulations in collaboration with our Legal Counsel
- Responding to security questionnaires and customer requirements
- Raising employee awareness of information security topics
Technical responsibilities:
- Evaluating and assessing security solutions for our infrastructure (Linux, macOS, on-premises, open source)
- Conducting or overseeing penetration tests and security audits
- Continuously analyzing and improving technical security measures
- Contributing to the implementation of security requirements together with the Operations team
Requirements
Our IT environment is not typical of a classic Swiss SME with Microsoft technologies and many cloud services. Instead, we rely on macOS and Linux, use open-source services where appropriate and possible, and operate most of the services we use on-premises. We are looking for someone who likes to get involved and is willing to help lead and execute projects.
Ideally, you will have the following:
- A degree in Computer Science or an equivalent qualification
- At least five years of relevant work experience in information security
- Familiarity with common security frameworks and standards (ISO 27k, NIST, CIS, SOC 2)
- Hands-on experience with certification processes, either as the person in charge or as part of a team that has gone through a certification
- Solid knowledge of network and application security, including common security technologies (firewalls, intrusion detection, SIEM, endpoint protection, MDM, vulnerability scanners, etc.)
- Experience in conducting penetration tests and security audits
- A strong sense of responsibility and a meticulous approach to work
- A positive mindset with a genuine enthusiasm for information security and privacy
- Strong written and spoken German and English
Benefits & conditions
- Opportunity to work on many different projects and improve and define processes
- Flexible working hours, option to work from home up to two days per week
- Up to two Workation weeks per year
- Option to take unpaid leave
- A dedicated budget for computer/workstation (macOS or Linux)
- Public transportation discount or parking space (electric car charging available)
- Free use of fitness room, including a fitness trainer once a month
- Professional massage once a month
- Internal German or English courses
- A great coffee machine :-)
- Regular events and get-togethers
- The good feeling of contributing to the effective protection of the privacy of millions of people