Chief Information Security Officer (CISO)

SolutionHouse
Germany
15 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Cyber Security Identity and Access Management Microsoft Security Essentials Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Information Security Management System

Job description

As the Chief Information Security Officer (CISO), you will lead and further develop BE-terna’s Group Information Security function, ensuring a secure, resilient, and well-governed environment across all countries and regions. You will report to the Director of IT and work closely with IT, Digitalization, Legal, Finance, Sales, and other group functions. You will be accountable for BE-terna’s overall security posture, security governance, risk management, and security operations. Working with your international team and external partners, you will ensure that security is embedded throughout the end-to-end lifecycle - from architecture and project delivery to daily operations, incident response, and continuous improvement.

yourmission

  • Define and implement BE-terna’s Group Information Security Strategy, roadmap, and security governance framework.
  • Lead and develop the security function, ensuring clear priorities, effective resource allocation, and continuous improvement.
  • Own and continuously improve the ISMS, including the ISO 27001 certification, NIS2 readiness and audit roadmap.
  • Ensure compliance with relevant security and data protection requirements, including ISO 27001 and NIS2.
  • Drive Security by Design, including security architecture assessments and threat modelling.
  • Lead information-security risk assessments and treatment, ensuring continuous improvement of the Group’s security posture.
  • Oversee the security technology stack, including SIEM, Microsoft security solutions, security monitoring, and vulnerability management.
  • Steer the SOC and security operations model, including incident response and external security partners.
  • Drive business continuity and disaster recovery capabilities from an information-security perspective.
  • Provide security assurance to clients, auditors, management, and the owner, including security questionnaires, contractual requirements, and audits.
  • Lead Group-wide security awareness, training, and education and build a strong security culture.

successinthefirstyear

In your first 12 months, success means:

  • A clear and implemented Group Information Security Strategy and evolving roadmap.
  • A transparent and measurable view of BE-terna’s overall security posture and key risks.
  • A well-governed and continuously improving ISMS, including continuation of ISO 27001 and NIS2 readiness.
  • An effective SOC, incident response, vulnerability management, and security monitoring model.
  • Strong collaboration across IT, Digitalization, Legal, Sales, and other group functions, with security embedded into business and technology decisions.
  • A motivated and well-structured security function with clear responsibilities, priorities, and development paths., We operate as one international team - and so are our benefits. While local specifics may vary, our Group-level benefits are designed to ensure a positive and rewarding employee experience, no matter your location:
  • Flexible working hours and a modern hybrid work environment
  • Support for sports activities
  • Participation in international team events and knowledge-sharing initiatives
  • Meaningful employee recognition and celebration moments
  • A supportive and inclusive company culture
  • Opportunities for growth in a dynamic, international setting

Requirements

  • Proven experience in senior information security, cybersecurity, or CISO-related roles, ideally in an international, multi-country organization.
  • Strong expertise in security governance, risk management, security operations, and compliance.
  • Hands-on experience with ISO 27001 and NIS2.
  • Strong technical understanding of the general security stack.
  • Experience with SIEM/SOC, incident response, vulnerability management, and security monitoring.
  • Strong understanding of identity security and Zero Trust principles.
  • Experience with business continuity and disaster recovery frameworks.
  • Excellent executive communication skills and the ability to translate complex security risks into clear business implications.
  • Proven leadership experience with security specialists and external partners.
  • Independent, pragmatic, and business-oriented approach, with sound judgement and strong crisis-management skills.
  • Excellent command of English, both written and spoken.

Desirable:

  • CISSP or CISM certification.
  • Master’s degree in Information Security, Cybersecurity, or a comparable field.
  • ITIL 4 Foundation; Managing Professional is a plus for function heads.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:49 min

Securing service invocation with zero-trust networking access

Marc Müller Marc Müller · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:55 min

Mitigating agent risks with zero trust networking

Oren Penso Oren Penso · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all