> Markdown version of [/jobs/ext/3369089-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/3369089-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** SolutionHouse - **Location:** Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Microsoft Security Essentials, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Information Security Management System - **Published:** September 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=87b26231e64c76f2 ## About the Role * Proven experience in senior information security, cybersecurity, or CISO-related roles, ideally in an international, multi-country organization. * Strong expertise in security governance, risk management, security operations, and compliance. * Hands-on experience with ISO 27001 and NIS2. * Strong technical understanding of the general security stack. * Experience with SIEM/SOC, incident response, vulnerability management, and security monitoring. * Strong understanding of identity security and Zero Trust principles. * Experience with business continuity and disaster recovery frameworks. * Excellent executive communication skills and the ability to translate complex security risks into clear business implications. * Proven leadership experience with security specialists and external partners. * Independent, pragmatic, and business-oriented approach, with sound judgement and strong crisis-management skills. * Excellent command of English, both written and spoken. Desirable: * CISSP or CISM certification. * Master's degree in Information Security, Cybersecurity, or a comparable field. * ITIL 4 Foundation; Managing Professional is a plus for function heads. ## Description As the Chief Information Security Officer (CISO), you will lead and further develop BE-terna's Group Information Security function, ensuring a secure, resilient, and well-governed environment across all countries and regions. You will report to the Director of IT and work closely with IT, Digitalization, Legal, Finance, Sales, and other group functions. You will be accountable for BE-terna's overall security posture, security governance, risk management, and security operations. Working with your international team and external partners, you will ensure that security is embedded throughout the end-to-end lifecycle - from architecture and project delivery to daily operations, incident response, and continuous improvement. #yourmission * Define and implement BE-terna's Group Information Security Strategy, roadmap, and security governance framework. * Lead and develop the security function, ensuring clear priorities, effective resource allocation, and continuous improvement. * Own and continuously improve the ISMS, including the ISO 27001 certification, NIS2 readiness and audit roadmap. * Ensure compliance with relevant security and data protection requirements, including ISO 27001 and NIS2. * Drive Security by Design, including security architecture assessments and threat modelling. * Lead information-security risk assessments and treatment, ensuring continuous improvement of the Group's security posture. * Oversee the security technology stack, including SIEM, Microsoft security solutions, security monitoring, and vulnerability management. * Steer the SOC and security operations model, including incident response and external security partners. * Drive business continuity and disaster recovery capabilities from an information-security perspective. * Provide security assurance to clients, auditors, management, and the owner, including security questionnaires, contractual requirements, and audits. * Lead Group-wide security awareness, training, and education and build a strong security culture. #successinthefirstyear In your first 12 months, success means: * A clear and implemented Group Information Security Strategy and evolving roadmap. * A transparent and measurable view of BE-terna's overall security posture and key risks. * A well-governed and continuously improving ISMS, including continuation of ISO 27001 and NIS2 readiness. * An effective SOC, incident response, vulnerability management, and security monitoring model. * Strong collaboration across IT, Digitalization, Legal, Sales, and other group functions, with security embedded into business and technology decisions. * A motivated and well-structured security function with clear responsibilities, priorities, and development paths., We operate as one international team - and so are our benefits. While local specifics may vary, our Group-level benefits are designed to ensure a positive and rewarding employee experience, no matter your location: * Flexible working hours and a modern hybrid work environment * Support for sports activities * Participation in international team events and knowledge-sharing initiatives * Meaningful employee recognition and celebration moments * A supportive and inclusive company culture * Opportunities for growth in a dynamic, international setting ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing ASP.NET Core Microservices with Dapr: A practical guide](https://www.wearedevelopers.com/videos/1528-developing-asp-net-core-microservices-with-dapr-a-practical-guide) - [Building Multi-Tenant ASP.NET Core Applications: Best Practices and Real-World Solutions](https://www.wearedevelopers.com/videos/1552-building-multi-tenant-asp-net-core-applications-best-practices-and-real-world-solutions) - [The CHRO Agenda: Navigating AI Regulation and Organizational Change](https://www.wearedevelopers.com/videos/1879-the-chro-agenda-navigating-ai-regulation-and-organizational-change) - [Inside Mercedes-Benz: How CIO Katrin Lehmann is Empowering 5,000 Developers and Driving Digital Change](https://www.wearedevelopers.com/videos/1360-inside-mercedes-benz-how-cio-katrin-lehmann-is-empowering-5-000-developers-and-driving-digital-change) ## Related Articles - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)