> Markdown version of [/jobs/ext/2265210-senior-conformity-assessment-program-specialist-information-security-management-system](https://www.wearedevelopers.com/jobs/ext/2265210-senior-conformity-assessment-program-specialist-information-security-management-system). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Conformity Assessment Program Specialist - Information Security Management System - **Company:** UL, LLC - **Location:** Aachen, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Tisax, Information Security Management System, Information Technology - **Published:** August 27, 2026 - **Apply:** https://www.adzuna.de/details/5855038202 ## About the Role Bachelor?s or Master?s degree in Information Security, Computer Science, Cybersecurity, Risk Management, or a related field. Minimum 5 years of experience in information security, IT compliance, or risk management roles, preferably within a TIC (Testing, Inspection, Certification) organization. Proven experience in implementing and maintaining ISO/IEC 27001 and TISAX-conformant/compliant ISMS. Preferred certifications: ISO/IEC 27001 or TISAX Lead Implementer. Strong understanding of and experience with risk management methodologies, processes, and tools (e.g., risk registers, threat modeling). Demonstrated experience supporting ISO/IEC 27001/TISAX implementations, including contributing to the resolution of corrective actions and supporting continuous improvement initiatives led by ISMS Managers. Excellent analytical, organizational, and project management skills. Strong interpersonal, networking and communication skills, with the ability to influence internal and external stakeholders at all levels. Fluency in English required. ## Description The Senior ISO/IEC 27001 + TISAX Compliance Specialist is responsible for developing, implementing, and maintaining the organization?s Information Security Management Systems (ISMS) global conformance/compliance requirements to ensure alignment with ISO/IEC 27001 and TISAX requirements across multiple business/customer operating units. This role ensures conformance/compliance with the requirements, supports the management of information security risks, and support of the culture of information and cybersecurity security awareness across the organization where ISO/IEC 27001 /TISAX conformance/compliance is required. Develop and maintain global ISO/IEC 27001 and TISAX conformance/compliance requirements documentation in support of local UL Solutions Statements of Applicability (SoAs), information security policies, procedures, processes, and controls. Collaborate with ISMS Managers to ensure local conformance/compliance with ISO/IEC 27001 and TISAX requirements, including legal, regulatory, and contractual obligations. Partner with Global Technology, Global Cybersecurity, and other key functional teams (e.g., Legal, Business Continuity) to advise on applicable ISMS control requirements and potential solutions to address ISO/IEC 27001 and TISAX conformance/compliance issues. Support locations in conducting information security risk assessments and treatment, providing advice and guidance to ensure a consistent and aligned approach across the organization. Support the development of global processes that enable conformance/compliance with ISO/IEC 27001 and TISAX requirements. Support continuous improvement initiatives led by ISMS Managers. Assist in resolving corrective actions managed by ISMS Managers, leveraging prior experience in managing corrective actions to provide effective support. Stay current with changes in ISO/IEC 27001, TISAX, and other relevant best practice standards and regulatory frameworks. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)