> Markdown version of [/jobs/ext/66167-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/66167-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Orbem Gmbh - **Location:** München, Germany (Remote available) - **Experience:** Expert - **Salary:** €120,000.0 - €135,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Software as a Service, Cyber Security, Smart Devices, Information Security Management System - **Published:** May 13, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=3095d5f2e919b1d3 ## About the Role Do you have experience in Leadership?, * Experience navigating an ISO 27001 re-audit. * Familiarity with the European regulatory landscape (GDPR, NIS2, EU AI Act) and a working understanding of US frameworks (SOC 2). * Deep-tech, AI/ML, or industrial product context. Our security surface is not SaaS-shaped - edge devices, hardware, industrial customers, imaging data. * Experience working with and evaluating external security and compliance service providers. * Comfort with AI-first working. We expect you to use AI to compress the work - and to own the output, not just the prompt. You also bring an informed view on how to monitor and govern AI usage internally. ## Description * Lead our approach to the upcoming ISO 27001 re-audit. Assess the situation, make the strategic recommendation, and own the execution. * Set and maintain Orbem's information security strategy aligned with our stage, our customers (enterprise food today, healthcare in our strategic line of sight), and our risk appetite. * Own the information security risk register end-to-end: build it where needed, maintain it, and run the risk review with key leadership peers. * Represent Orbem externally with auditors, enterprise customer security teams, and regulators in the CISO capacity. * Advise the leadership team on information security risk in product, go-to-market, and expansion decisions, including healthcare readiness planning. Hands-On Execution ( 40%) * Own and continuously improve key operational security processes - including how we assess and manage risk across our vendor and supplier base, how security is embedded in key business workflows, and how we ensure controls translate from policy into practice. * Bring policies and controls to life. Identify which controls are most material, which to operationalize further, and which to consolidate - in partnership with the teams who will execute them. * Own the ISMS governance structure - ensuring that control reviews, evidence collection, management reviews, and internal audits happen to a high standard, whether through direct execution, external support, or a combination. * Lead incident response as incident commander for security-relevant events, with the Security Engineering team as technical co-lead. * Write clear policies, clear communications, clear decisions. You will author or co-author most of the security-related writing that leaves this function. Orchestrating the External Stack & Lateral Leadership ( 20%) * Manage a deliberate external provider stack. You will not build everything in-house. You will orchestrate a set of external partners - examples include audit preparation support, data protection advisory services, a managed security service provider, penetration testing, and an ISMS and compliance management platform. For each, you contribute to the build-vs-buy decision and own the ongoing relationship. * Collaborate closely with the Security Engineering team through a close working relationship that connects governance and technical security. * Co-build a Security Ambassadors network with the Security Engineering team - empowered technical leads across business teams who champion security in their own context. * Leverage AI and automation aggressively across the security programme - compliance evidence collection, vendor review, policy drafting, user training, awareness - to keep the function lean., This is an individual contributor role at Principal level. Your influence is lateral, not hierarchical. You will work alongside the General Counsel, the Corporate Operations lead, the Procurement & Supply Chain lead, and the Security Engineering team. You will interact with the full executive team on security-relevant decisions., * Scale-up security leadership experience. You have been the #1 or #2 information security compliance person at a company in the 150-600 FTE range. * ISO 27001 lived experience. You have personally guided a company through an ISO 27001 cycle. You can make a credible audit strategy recommendation because you have seen the consequences of each option in practice. * Hands-on operator. You have personally set up security processes and controls - not only specified or overseen them. You are comfortable running a security register, writing policies, running workshops, and sitting in working meetings to ship work. * Comfort without a large team. You are motivated by being the person in the room, not the person who built the room. * Resilience. Security leadership means making hard calls - sometimes unpopular ones, sometimes under time pressure. You are energised by that responsibility, not deterred by it. You stand behind your decisions and own the business outcomes. * Communication. You can translate security risk into business decisions for a non-security executive team, and technical specifics for engineers. You write and speak clearly. ## Related Videos - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Europe's Digital Future: How to Get from User to Shaper?](https://www.wearedevelopers.com/videos/100027-europe-s-digital-future-how-to-get-from-user-to-shaper) - [WeAreDevelopers LIVE – AI vs the Web & AI in Browsers](https://www.wearedevelopers.com/videos/1743-wearedevelopers-live-ai-vs-the-web-ai-in-browsers) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)