> Markdown version of [/jobs/ext/2860443-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2860443-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** IDEALworks GmbH - **Location:** München, Germany - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cyber Security, IT Management, Service-Oriented Architecture, Software Vulnerability Management, Tisax, Data Classification, Software Security, Information Technology, Vulnerability Analysis - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.de/details/5878351839 ## About the Role * Bachelor's degree in Information Technology, Computer Science, or a related field. * 4 - 6 years work experience in information security, compliance, or IT governance. * Hands-on experience with ISO 27001 implementation and audits. * Ideally, you have experience in TISAX requirements and automotive security standards. * Strong understanding of risk management, threat modelling, and vulnerability management. * Experience with penetration testing tools and methodologies. * Knowledge of infrastructure hardening and application security best practices. * Deep understanding of regulatory frameworks and audit processes. * Experience maintaining compliance documentation and evidence. * Excellent problem-solving and analytical skills. * Strong verbal and written communication skills in English, German is a plus. * Ability to work in a highly agile, fast-paced environment. ## Description München, Bayern, 80992 Vollzeit Role Responsibilities: What you will do Governance & Compliance * Implement and maintain ISO 27001 and TISAX certifications. * Own all compliance-related activities, including but not limited to: + Internal and external audit preparation and coordination. + Maintaining the Statement of Applicability (SoA) and evidence for controls. + Ensuring adherence to regulatory and contractual security requirements. * Develop and maintain compliance documentation, policies, and procedures. Incident & Continuity Management * Lead security incident response and ensure proper documentation. * Conduct root cause analysis and follow-up on corrective actions. * Own the end-to-end BCP process, including but not limited to: + Maintain BCP documentation and ensure readiness through periodic BCP drills and readiness assessments. + Launch BCP in case of major incidents or disruptions. + Coordinate communication with stakeholders during BCP activation. Risk Management * Identify, assess, prioritize, and track security risks. * Monitor timely execution of mitigation plans. * Perform and review threat modelling for critical systems and processes. Security Operations * Oversee data classification and define retention periods. * Support infrastructure hardening and application security initiatives. * Maintain and enhance the security playbook AI model for incident response. Testing & Assurance * Plan and coordinate penetration testing and vulnerability assessments. * Prioritize and follow up on mitigation of PEN test findings. Customer & Stakeholder Support * Act as a security and compliance subject matter expert for customer-facing teams. * Respond to security questionnaires and RFPs.