Cyber security & Risk Management at RTX TECHNOLOGY RESEARCH CENTER A DIVISION OF RTX CORPORATION
berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

27 Nov, 26

Salary

0.0

Posted On

29 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

The German Cancer Research Center (DKFZ) is one of Europe’s largest cancer research centers. “Research for a life without cancer" is the mission of our world-class scientists and all our team members.

We investigate how cancer develops, identify cancer risk factors and search for new cancer prevention strategies. We develop new methods with which tumors can be diagnosed more precisely and cancer patients can be treated more successfully. Every contribution counts – whether in research, administration or infrastructure. This is what makes our daily work so meaningful and exciting.

We are looking for an IT Security Specialist to define security standards for two major data infrastructure projects in the Heidelberg-Mannheim region: (1) The Data Space Project of the Health + Life Science Alliance has recently been launched to develop a trusted research environment (TRE) for seven leading life sciences and biomedical research institutions in the Heidelberg-Mannheim region. (2) The German Human Genome-Phenome Archive (GHGA) is part of the national program for research data infrastructures (NFDI) and has established a secure national omics data infrastructure, enabling the secondary use of human omics data in research.

These infrastructures are supporting the bioinformatics community with software tools for secure data/metadata storage, interactive data portals with data visualization, and streamlined data deposition and acquisition solutions. Prof. Oliver Stegle is coordinating GHGA at the DKFZ and representing the Data Space project for the DKFZ in close collaboration with the other Health + Life Science Alliance member institutions Heidelberg University, European Molecular Biology Laboratory (EMBL), Central Institute of Mental Health, Max Planck Institute for Medical Research, Heidelberg University Hospital and University Hospital Mannheim.

In order to develop the Data Space Trusted Research Environment (TRE) and the GHGA platform into a state-of-the-art infrastructure for the secure handling and analysis of genome data, we are seeking with immediate effect an


Job description:

We are looking for a team member with substantial experience in information security and risk governance. Your role will be instrumental in technical and organizational decision-making for the Data Space and GHGA projects and will ensure compliance with modern standards for both infrastructures. You will be part of two tightly connected teams spanning cloud engineers, data stewards and interdisciplinary researchers with the joint mission of enabling the secure sharing of sensitive biomedical data for the scientific research community. You will have a diverse set of tasks, shaping the IT infrastructure of the Data Space TRE from the start, while also managing the IT security for the operation of the established GHGA Portal and upcoming new functionalities. Your expertise will help ensure the safe operation of the Data Space TRE and GHGA while also contributing to the development of standards in Germany and supporting their role in international efforts.


Your responsibilities :

  • Analysis and documentation of current operations with respect to IT security, identifying gaps and supporting continuous improvement
  • Implementation and maintenance of a framework for risk and asset management, utilizing modern tools and standards
  • Creation and maintenance of an Information Security Management System (ISMS)
  • Implementation and maintenance of a program for security awareness that works across multiple communication channels
  • Regular monitoring of risks through third-party interactors, such as used infrastructures or sub-contractors
  • Provision of information security guidance for IT projects, including the evaluation and recommendation of technical controls
  • Coordination of interaction with external expertise on legal and technical IT security topics
  • Ensure the management and local cyber governance of the Information Systems within the sites under ISSO scope.
  • Ensure adherence to global and regional/local regulatory requirements and applicable frameworks (ISO 27001, 27005, NIST SP800-171 etc.).
  • Maintain the Information Security Management System (ISMS) or equivalent governance model.
  • Define, implement, coordinate, manage and monitor activities related to the Part-IS regulation (acting as Aviation Safety ISMS Manager).
  • Drive internal and external audits, certifications, and compliance readiness across multiple sites.
  • Continuous monitoring of emerging regulations and standards, ensuring proactive & compliance and risk management.
  • Ensure relationship and interface with cyber stakeholders in relation with site ecosystem including security authorities, customers & partners.
  • Define, derive and maintain security policies, procedures and guidance for Restricted and Classified IS located on site (if any) and ensure their implementation with the support of DT team.
  • Ensure accreditation activities on Restricted and Classified networks (when applicable).
  • Develop and execute an annual security awareness plan to reduce business compliance risks, cyber operational risks and to foster a cyber culture within the sites.

Cyber Risk Management:

  • Manage cyber risks (identification, evaluation and treatment) according to applicable enterprise-wide cyber risk program and regulations including but not limited to Part-IS and NIS2. As part of the risk management, the ISSO will perform/lead risk assessment for the sites and associated risk treatment plans with the support of DT Int’l Operations and RTX Global GRC teams.
  • Oversee implementation of security controls (technical, administrative, physical) for applications, infrastructure, Cloud, and OT systems under ISSO scope.
  • Ensure secure enablement of new technologies and digital transformation programs.

Responsibilities
Loading...