Information Security Governance Product Owner
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Overview Responsible for the delivery of the governance product and services: governance service: design, implementation and continuous improvement of the global Information Security Framework (ISF), aligning it with the evolving business needs, regulatory environment, industry standards and customer requirements.Support delivery of the GRC platform service and customer security assurance service.The working location for this position will be in Madrid city, where we operate a hybrid model, requiring at least 40% of the working time on-site.Responsibilities Information Security Framework (ISF) Management: Design, implement, and maintain the ISF: policies, standards, procedures, and control baselines, aligned to business needs, regulatory obligations (e.g. NIS2, GDPR), industry standards (e.g. NIST CSF, ISO **), and customer contractual requirements Regulatory Integration & Control Framework Alignment: Maintain inventory and traceability of external obligations (e.g. NIS2, GDPR, ISO/IEC **, IEC **) and customer requirements, integrating these into the ISF components (policies, controls) Governance Operations & Executive Engagement: Oversee ISF governance processes, including stakeholder coordination, approval workflows, and documentation.Collaborate and support the GRC platform service owner to deliver technology required to enable digital implementation of the information security framework.Collaborate and support the Customer Security Assurance Service owner by delivering governance which supports the business to comply with customer security requirements.Governance Metrics & Reporting: Design key risk and performance indicators, dashboards and report on the governance product and services relevant for management at the Liebherr group, divisions and companies Qualifications Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field 5+ years of working experience in global organizations including Governance, GRC technology and customer security assurance services delivery Following certificates are preferred: CISSP, CRISC, CISM, GSLC Excellent written and verbal communication skills in English, German is a plus Proven expertise in designing and maintaining information security governance frameworks using industry standards e.g. NIST CSF, ISO/IEC **, IEC *** and requirements in security regulations e.g. NIS2, GDPR, Defense contracting Ability to lead multi-stakeholder governance processes across global business units and ensure documentation is structured, endorsed, and maintained Experience in applying agile principles (e.g. iterative planning, continuous improvement, stakeholder collaboration) to the delivery and evolution of governance services, frameworks, or organizational processes Experience in owning and evolving enterprise GRC platforms to support compliance, risk, and governance services Strategic thinking combined with a pragmatic execution mindset, especially when aligning governance with operational realities Highly desirable: experience in product ownership and service delivery using SAFe (Scaled Agile Framework) or similar agile methodologies Benefits Competitive compensation and benefits package that recognizes your expertise Flexible and hybrid working model Creative freedom and responsibility to shape processes and solutions in our global transformation Continuous learning and development with tailored training and certification opportunities Meal vouchers Life and accident insurance Option to include a premium private health insurance package as part of the flexible remuneration A safe, stable and international workplace within a trusted family business that invests in people Location Liebherr IT Shared Service Centre Ibérica, S.L., Madrid, Spain (ES)#J-***-Ljbffr
Requirements
Governance Metrics & Reporting: Design key risk and performance indicators, dashboards and report on the governance product and services relevant for management at the Liebherr group, divisions and companies Qualifications Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field 5+ years of working experience in global organizations including Governance, GRC technology and customer security assurance services delivery Following certificates are preferred: CISSP, CRISC, CISM, GSLC Excellent written and verbal communication skills in English, German is a plus Proven expertise in designing and maintaining information security governance frameworks using industry standards e.g. NIST CSF, ISO/IEC **, IEC ** and requirements in security regulations e.g. NIS2, GDPR, Defense contracting Ability to lead multi-stakeholder governance processes across global business units and ensure documentation is structured, endorsed, and maintained Experience in applying agile principles
Benefits & conditions
(e.g. iterative planning, continuous improvement, stakeholder collaboration) to the delivery and evolution of governance services, frameworks, or organizational processes Experience in owning and evolving enterprise GRC platforms to support compliance, risk, and governance services Strategic thinking combined with a pragmatic execution mindset, especially when aligning governance with operational realities Highly desirable: experience in product ownership and service delivery using SAFe (Scaled Agile Framework) or similar agile methodologies Benefits Competitive compensation and benefits package that recognizes your expertise Flexible and hybrid working model Creative freedom and responsibility to shape processes and solutions in our global transformation Continuous learning and development with tailored training and certification opportunities Meal vouchers Life and accident insurance Option to include a premium private health insurance package as part of the flexible remuneration A safe, stable and international workplace within a trusted family business that invests in people Location Liebherr IT Shared Service Centre Ibérica, S.L., Madrid, Spain (ES) #J-*****-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in Germany
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Companies to Work For in Germany: Top 25 Companies in 2023Â
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again