> Markdown version of [/jobs/ext/3041401-iso-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3041401-iso-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISO - Information Security Officer - **Company:** Österreichische Akademie der Wissenschaften - **Location:** Wien, Austria (Remote available) - **Experience:** Expert - **Salary:** €70,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Information Technology Audit, Information Technology Operations, Information Systems Security Architecture Professional, Network Security, PRINCE2, Zero Trust Network Access, Data Logging, Information Security Management System, Information Technology, ISO/IEC 27002 - **Published:** September 24, 2026 - **Apply:** https://www.adzuna.at/details/5894806545 ## About the Role * A completed degree from a university or university of applied sciences, ideally in computer science or business informatics with a focus on information security, or equivalent knowledge acquired in previous roles. * At least five years of relevant professional experience in comparable positions (information security manager, IT security, IT operations, IT audit). * Sound knowledge of ISO/IEC 27001 and ISO/IEC 27002, combined with hands-on experience in establishing, operating or further developing an information security management system (ISMS). * Experience in identifying, assessing and treating information security risks.Experience with policies, control assessments, audits, management reporting and the tracking of corrective actions. * A solid understanding of modern IT and security architectures, in particular cloud security, identity and access management (IAM), system hardening, network security, security monitoring and zero trust. * Knowledge of the relevant legal and regulatory requirements, in particular data protection and, where applicable, the NIS2 Directive and its Austrian implementation (Network and Information System Security Act, NISG). * The ability to present technical and organisational matters in a way that suits the audience, from specialist units to governing bodies. * Strong advisory, facilitation, communication and presentation skills.A structured, self-directed and solution-oriented way of working. Desirable: * Experience in complex or decentralised organisations and in project and stakeholder management, ideally supported by a certification such as IPMA or PRINCE2. * Certifications such as ISO/IEC 27001 Lead Implementer or Lead Auditor, CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), or qualifications in COBIT or ITIL. Language skills * German: fluent, spoken and written (at least level C1 of the Common European Framework of Reference for Languages,CEFR).English: good command (at least level B2 of theCEFR). ## Description The position is located within the remit of the Chief Information Officer (CIO) of the ÖAW and reports directly to the CIO, who in turn reports to the Directorate for Institutes and Infrastructure (DII). Its remit extends across the entire organisation, working closely with the institutes, the central units and the Legal and Compliance Department., * You establish, operate and continuously develop the information security management system (ISMS) of the Austrian Academy of Sciences (ÖAW) in line with ISO/IEC 27001. * You act as the central point of contact and coordination for all organisation-wide matters relating to information security management. * You prepare decision papers and recommendations on appropriate information security measures for the Presidential Board and the Directorate for Institutes and Infrastructure (DII). * You maintain the ISMS documentation framework and steer the drafting, consultation, approval and periodic review of strategies, policies, standards and procedures. * You coordinate information security risk management, support the identification and assessment of risks, and monitor the implementation of approved risk treatment measures. * Together with the relevant technical units, you define requirements for logging, security monitoring and incident management, and verify that these are implemented appropriately and remain effective. * You plan and coordinate internal and external information security audits, security reviews and penetration tests, and follow up on the resulting actions. * You produce regular reports on the risk landscape, security incidents, control effectiveness, the status of measures and the maturity of the ISMS for the Presidential Board and the DII, and you prepare the ISMS management review. * You design and coordinate target-group-specific training and awareness programmes and help advance the ÖAW's information security culture. * You monitor the implementation and effectiveness of the security measures in place and track deviations and improvement measures in a documented and auditable way. * You work closely with the Legal and Compliance Department as well as with other internal teams and external partners to ensure compliance with legal requirements and sector-specific standards. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Diversity Matters: ÖBB’s Innovative Approach and why we need Queer Thinking in IT](https://www.wearedevelopers.com/videos/908-diversity-matters-obb-s-innovative-approach-and-why-we-need-queer-thinking-in-it) - [Developers Communities in San Francisco - WeAreDevelopers LIVE from Corgi Cafe](https://www.wearedevelopers.com/videos/2144-developers-communities-in-san-francisco-wearedevelopers-live-from-corgi-cafe) ## Related Articles - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria) - [10 Highest Paying Jobs in Austria](https://www.wearedevelopers.com/magazine/268-10-highest-paying-jobs-in-austria) - [Best Companies to Work For in Austria: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/192-best-companies-to-work-for-in-austria-top-25-companies-in-2023) - [Guide for Expats Living in Austria](https://www.wearedevelopers.com/magazine/317-guide-for-expats-living-in-austria) - [Software Developer Salary in Austria [2023]](https://www.wearedevelopers.com/magazine/213-software-developer-salary-in-austria-2023) - [Austria – the most livable place for software developers?](https://www.wearedevelopers.com/magazine/20-austria-the-most-livable-place-for-software-developers)