> Markdown version of [/jobs/ext/3380514-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3380514-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** Utimaco GmbH - **Location:** Aachen, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Disaster Recovery, Identity and Access Management, Software Vulnerability Management, Information Security Management System, Information Technology - **Published:** September 1, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=560eec3b203490b0 ## About the Role * Bachelor's degree in information security, cybersecurity, computer science, information technology, engineering, risk management, or a related discipline; equivalent professional experience may be considered. * Typically 5-8 years of relevant experience in information security, cybersecurity, IT risk, security governance, security operations, audit, compliance, or a related field. * Experience working in an international, matrixed, regulated, technology-driven, or multi-site organization. * Practical experience with information security risk assessments, control implementation, security policies, audit support, and remediation tracking. * Experience supporting security incident response, vulnerability management, access governance, business continuity, or cyber resilience activities. * Experience working with European privacy and security requirements; practical knowledge of GDPR and German data protection expectations is desirable. * Experience coordinating stakeholders across multiple countries and functions. * Experience with third-party risk assessments, supplier due diligence, or customer security questionnaires is advantageous. * Experience in security awareness, training, communications, or security culture programs is advantageous. * Relevant professional certifications are desirable, such as CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer or Lead Auditor, CompTIA Security+, GIAC certifications, or equivalent qualifications. * Fluency in English is required. Professional working proficiency in German is highly desirable. ## Description * Manage/Contribute to the continuous improvement of the information security management framework, policies, standards, and procedures. * Coordinate information security risk assessments, risk treatment plans, and risk acceptance processes. * Maintain the security risk register and report key risks, trends, and remediation progress to management. * Support the operation and continual improvement of the Information Security Management System (ISMS). * Prepare for and support internal and external security audits, certifications, customer assessments, and regulatory reviews. * Monitor compliance with applicable legal, regulatory, contractual, and internal security requirements. * Coordinate incident preparedness, including security incident procedures, exercises, lessons learned, and follow-up actions. * Support vulnerability, threat, access, asset, and third-party security management activities. * Promote secure working practices through security awareness training, communications, and targeted guidance. * Advise project and product teams on security requirements, secure design, data protection, and risk-based controls. * Contribute to business continuity, disaster recovery, and organizational resilience planning. * Define and track meaningful security metrics and management reports. * Work with stakeholders to ensure security findings and audit actions are prioritized and closed effectively. * Keep current with relevant threats, standards, regulatory developments, and industry practices