Information Security Engineer (m/f/d) at Northern Data
Berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

25 Nov, 26

Salary

0.0

Posted On

27 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Services

Description
  • Maintain and support the continual improvement of the ISO/IEC 27001 Information Security Management System (ISMS).
  • Own the lifecycle of security policies, standards, procedures and guidelines, including drafting, review cycles, approvals and publication via SharePoint and Confluence.
  • Administer Information Security documentation repositories, knowledge bases and workflow platforms (SharePoint, Confluence, Jira), including version control, review schedules and follow-up on overdue actions.
  • Own and maintain Information Security registers, including the Asset Register, Risk Register, Exception Register and Action Tracker, ensuring data quality and timely updates.
  • Support enterprise information asset management and data classification, including governance of data loss prevention (DLP) and sensitivity labelling technologies.
  • Lead audit preparation, evidence collection and logistics for internal and external audits; track findings, observations and corrective actions through to closure.
  • Support Information Security risk assessments, treatment plans and periodic reviews across the business.
  • Prepare Information Security metrics, dashboards, KPIs and management reports.
  • Coordinate Information Security projects, tracking scope, milestones, risks, dependencies, actions and deliverables.
  • Partner closely with Compliance, Legal, IT, Engineering, HR and business stakeholders on governance matters.


Operational Security Support (Approx. 40%)

  • Support the implementation, configuration, administration and continuous improvement of Information Security technologies and platforms.
  • Support third-party security assessments, due diligence questionnaires and supplier assurance activities.
  • Support vulnerability remediation tracking, escalating overdue items and reporting on remediation progress.
  • Support security incident response activities, including documentation, coordination, evidence collection and post-incident improvement actions.
  • Support security awareness and communication initiatives.
  • Support security reporting, KPI tracking and management updates.
  • Provide coordination and administrative support to other Information Security team members.


YOUR QUALIFICATIONS:

  • Bachelor’s degree in information security, Cyber Security, Computer Science or related discipline.
  • 5–7 years' experience in Information Security, GRC, Security Operations.
  • Solid understanding of ISMS and security governance frameworks (e.g. ISO/IEC 27001).
  • Experience with risk management methodologies and conducting information security risk assessments.
  • Familiarity with security compliance frameworks and regulatory requirements (e.g. NIS2, SOC 2, CIS Controls, GDPR).
  • Experience managing documentation, registers and workflows across enterprise collaboration platforms (e.g. SharePoint, Confluence, Jira).
  • Experience with Data Loss Prevention (DLP), information protection, and data classification solutions.
  • Experience with data analysis, reporting, dashboard development and KPI measurement.
  • Experience working in cross-functional environments with Infrastructure, IT, Platform Engineering, Compliance and Legal teams.
  • Familiarity with Vulnerability management processes and vulnerability assessment tools. Security testing methodologies and tools (e.g. vulnerability scanning, security validation, or penetration testing support).
  • Familiarity with Security monitoring, SIEM platforms, and incident detection concepts.
  • Familiarity with Endpoint Detection and Response (EDR) and endpoint security technologies.

Responsibilities
Loading...