Director Global IT Security

EVENTIM
Hamburg, Germany
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Shift work
Languages
English, German
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Software as a Service Cyber Security Continuous Integration Information Leak Prevention DDoS Mitigation Identity and Access Management Integrated Development Environments Information Systems Security Architecture Professional Systems Development Life Cycle Cloud Services
+11 more
Secure Coding Software Vulnerability Management Enterprise Software Applications Software Security Rate Limiting Information Technology Integration Frameworks Hardware Infrastructure Cts+ Devsecops Security Orchestration, Automation & Response

Job description

As Director Global IT Security (m/f/d), you will lead the continuous hardening of CTS EVENTIM’s group-wide technology landscape and shape the next stage of our security maturity across technology, people and processes. Reporting directly to the CTO, you will own and further develop the security function across Product Security, Enterprise Security, Governance, Risk & Compliance (GRC) and Security Operations.

A key focus will be strengthening shift-left security across Engineering and Product. You will establish developer-friendly guardrails, practical security standards and strong security capabilities within engineering teams, while protecting high-traffic ticketing platforms against bot attacks, automated abuse and other adversarial traffic patterns., * Define and execute a group-wide IT security strategy and roadmap aligned with business goals, technology strategy and international growth.

  • Drive the hardening of customer-facing platforms, B2B and SaaS products, enterprise systems, cloud services, infrastructure, identity platforms, APIs, development environments and third-party integrations.
  • Build and mature the security operating model across Product Security, Enterprise Security, GRC and Security Operations, including policies, controls, risk management and measurable outcomes.
  • Establish practical DevSecOps and shift-left capabilities, including secure coding, threat modelling, security champions, code and infrastructure scanning, CI/CD security and secure release gates.
  • Lead the security approach for high-traffic, business-critical ticketing platforms, including bot management, WAF/CDN controls, DDoS protection, rate limiting, behavioural analytics, anomaly detection and incident playbooks.
  • Lead Security Operations and incident readiness, including monitoring, detection engineering, escalation paths, exercises, post-incident reviews and continuous improvement.
  • Own the security-related GRC agenda and support compliance and audit readiness in line with relevant frameworks and regulations, including ISO 27001, NIST CSF, GDPR and NIS2-related expectations.
  • Shape the responsible use of AI in cyber defence and security operations, while establishing appropriate governance, human oversight, auditability and safeguards for sensitive information.
  • Lead, develop and scale the IT Security team and strengthen security awareness and behaviour across the organisation., This role offers the opportunity to shape group-wide security in one of the most dynamic technology environments in live entertainment. You will work at the heart of live entertainment and technology, protecting platforms used by millions of fans and developing a strategically important security function with broad organisational visibility. CTS EVENTIM is committed to an inclusive working environment where people of all backgrounds can contribute, grow and do their best work.

Requirements

  • At least 10 years of experience in cybersecurity, information security or IT security, including significant leadership responsibility in a technology-driven, high-scale or digital platform environment.
  • Proven experience leading security across complex IT landscapes covering customer-facing platforms, APIs, cloud services, on-premises infrastructure, enterprise systems, identity platforms and software development environments.
  • A strong track record in building or maturing security functions across Product Security, Enterprise Security, GRC and Security Operations.
  • Deep expertise in application and product security, enterprise security, identity and access management, vulnerability management, secure architecture, incident response and security monitoring.
  • Strong practical understanding of DevSecOps, secure SDLC, software supply chain security, developer enablement and security automation.
  • Experience protecting high-traffic websites, e-commerce, marketplaces, ticketing platforms, SaaS products or similarly business-critical consumer platforms, including hands-on familiarity with bot management and automated abuse defence.
  • Experience applying AI and machine learning to cyber defence, combined with an understanding of AI-specific security risks such as prompt injection, data leakage, adversarial manipulation and model or vendor risk.
  • The ability to work credibly with senior engineers and architects while communicating effectively with executives, business leaders and non-technical stakeholders. Excellent English communication skills are required; German is highly advantageous., You see security as an enabler of trust, resilience and innovation. You combine strategic thinking with hands-on pragmatism, build strong bridges with Engineering and Product, create guardrails that teams actually adopt and remain calm and structured under pressure. A degree in Computer Science, Information Security, Information Technology, Engineering or a related discipline is preferred, while equivalent practical experience is equally valued. Certifications such as CISSP, CISM, CISA, CCSP, GIAC or ISO 27001 Lead Implementer/Lead Auditor are advantageous.

Benefits & conditions

  • 30 days of paid vacation plus the option of up to 15 days of unpaid leave
  • 25 days of workation within the EU
  • Flexible working hours
  • Sofa Concerts and employee events
  • Discounts on ticket purchases & opportunities for clearing assignments
  • Corporate benefits and discounts at KESS
  • Central location & subsidy for a Job Ticket or Germany Ticket
  • Bike leasing
  • Mental health program & company pension scheme
  • “GoFluent” language learning platform as well as Lunch & Learn sessions

About the company

CTS EVENTIM is one of the world’s leading providers of ticketing and live entertainment. We connect millions of fans with unforgettable live experiences and provide promoters, venues, artists and partners with powerful technology, services and platforms.

Our technology landscape includes high-traffic consumer platforms, international ticketing systems, B2B and SaaS solutions, enterprise systems, data platforms, cloud services and scalable infrastructure. IT Security is a strategic enabler of trust, resilience, product quality and continued growth across the CTS EVENTIM Group.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:17 min

Defining goals for multi-tenant rate limiting

Jan Mensch Jan Mensch · WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:43 min

Transitioning to Layer 7 rate limiting safeguards

Jan Mensch Jan Mensch · WWC Europe 2026

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all