Information Security Officer

ib vogt GmbH
Berlin, Germany
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English, German
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Supervisory Control and Data Acquisition (SCADA) Cloud Services Information Security Management System Information Technology Operational Systems CIS Benchmarks

Job description

As Information Security Officer (ISO), you will be responsible for establishing, implementing, and maintaining IB Vogt’s global information security framework. Reporting directly to the Head of IT & Digitalization, you will ensure the confidentiality, integrity, and availability of corporate and project-related data across all regions and business functions.

You will also act as the independent guardian of information security, ensuring compliance with international standards (ISO 27001, NIS2, GDPR) and enabling secure digital growth. You will lead a team of 2 people and co-ordinate external partners.

  • Develop and maintain the Information Security Management System (ISMS), aligned with ISO 27001/27002 and NIS2 standards
  • Define security policies, standards, and procedures in coordination with the Head of IT & Digitalization
  • Act as the primary point of contact for information security across IB Vogt
  • Conduct risk assessments and vulnerability analyses across IT, cloud, and OT/SCADA environments
  • Ensure compliance with legal, regulatory, and contractual security requirements (e.g., GDPR, NIS2, CSRD)
  • Support internal and external audits and certifications
  • Implement incident detection and response processes, ensuring quick containment and resolution of threats
  • Monitor security posture across IT infrastructure, ERP, cloud services, and operational systems and oversee third-party/vendor security assessments
  • Lead security awareness programs for employees, contractors, and partners
  • Promote a security-first culture across business units and global offices.

Requirements

Do you have experience in Risk management?, * Degree in Information Security, Computer Science, or a related field

  • 5+ years of hands on experience in cybersecurity, risk management, or IT security
  • Proven experience with ISMS frameworks (ISO 27001, NIS2, CIS Controls)
  • Knowledge of cloud security (Azure/AWS), endpoint protection, and OT/SCADA security in energy/EPC environments
  • Familiarity with data protection regulations (GDPR, energy-sector-specific standards)
  • Certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer are highly desirable
  • Strong communication and stakeholder management skills
  • Fluency in English; German language skills are a plus.

Benefits & conditions

  • A truly international working environment with colleagues from all over the world
  • An open-minded, friendly, dynamic, and highly motivated team
  • Interesting and challenging tasks, and thus a scope of professional growth and development
  • We encourage both team work and personal responsibility
  • Competitive remuneration, and other exciting benefits.

About the company

ib vogt is a leading utility-scale renewable energy development platform with a global footprint, a 20-year history, and a 15-year track record in utility-scale PV plants, plus a growing portfolio of wind and Battery Energy Storage Systems (BESS) projects. Our development strategy, which focuses primarily on OECD markets, world-scale development pipeline, and IPP business model strongly position ib vogt for delivering long-term value.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · WWC Europe 2026

Videos

See all

Related articles

See all