Information Security Lead (m/f/d) at TeleClinic GmbH
berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

27 Nov, 26

Salary

0.0

Posted On

29 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

Strategie & Governance

  • Strategie: Gesamtverantwortung für die Cybersecurity-Strategie der Interzero-Gruppe im Einklang mit Geschäfts- und Digitalisierungszielen
  • ISMS: Steuerung und kontinuierliche Weiterentwicklung des Information Security Management Systems über alle Standorte
  • Compliance: Sicherstellung der Konformität mit NIS2, KRITIS, ISO 27001, BSI IT-Grundschutz und DSGVO
  • Framework: Etablierung eines messbaren Cyber-Risiko-Frameworks inkl. KPIs, KRIs und Risk Appetite

Cyber Resilience & Operations

  • Krisenmanagement: Verantwortung für unternehmensweite Cyber Resilience inkl. Incident Response und Business Continuity & Disaster Recovery
  • Infrastruktur: Aufbau von Fähigkeiten in Threat & Vulnerability Management, Detection & Response (SOC), IAM sowie modernen Architekturen (Zero Trust)
  • Security by Design: Sicherstellung sicherheitskonformer Umsetzung in IT- und Businessprojekten (Cloud, Infrastruktur, digitale Lösungen)

Risiko- & Third-Party Management

  • Risikomanagement: Verantwortung für das unternehmensweite Cyber-Risikomanagement
  • Lieferanten: Bewertung und Steuerung von Drittparteirisiken gemäß NIS2
  • Integration: Einbettung von Cyber-Risiken in das Enterprise Risk Management

Koordination & Reporting

  • Schnittstelle: Zentrale Governance-Funktion zwischen deutschen Standorten und internationalen Security-Einheiten
  • Reporting: Regelmäßige Berichterstattung an Vorstand und C-Level
  • Beratung: Zentrale Ansprechperson der Geschäftsleitung in allen Fragen der Informationssicherheit

Awareness & Organisation

  • Teamaufbau: Aufbau und Weiterentwicklung einer leistungsstarken Security-Organisation
  • Awareness: Steuerung eines nachhaltigen Security Awareness Programms
  • Kultur: Förderung einer unternehmensweiten Sicherheitskultur

Information Security Lead (m/f/d)


This is a hybrid role sitting within our Infrastructure team. You'll own TeleClinic's information security strategy as our de facto CISO, while staying close enough to the engineering to make security real rather than documentary. You'll be the go-to person for all security-related topics, bridging engineering, operations, and leadership. Our ISO 27001 and ISO 9001 certifications are in place — your job is to keep them, extend them, and turn the ISMS into something the whole company actually uses. If you want your security work to have company-wide impact in a regulated healthcare environment, this role is for you.


What You'll Do

  • Own our ISO 27001 certification end to end — surveillance audits, re-certification, scope changes, and closing findings with our external auditor (our ISMS runs in Vanta).
  • Coordinate with our ISO 9001 programme so both audit cycles run as one, and help shape what we certify next (e.g. BSI C5).
  • Run and evolve the ISMS day to day: risk register, control ownership, evidence collection, and the internal audit programme.
  • Define and implement security policies, standards, and procedures across and with all teams.
  • Lead risk assessments, threat modelling, and vulnerability management.
  • Own third-party and vendor risk, from due diligence through to ongoing review.
  • Monitor the threat landscape and proactively address emerging risks relevant to a regulated healthcare environment.
  • Collaborate with product teams and infrastructure on architecture decisions with a security-first mindset.
  • Educate and upskill colleagues on security awareness and best practices.
  • Contribute hands-on to our Python/Django services where security work calls for it (tooling, automation, remediation).


What You Bring

  • Several years owning information security in a regulated or audited environment, including direct exposure to external auditors.
  • Hands-on experience with ISO 27001, ideally having led or significantly contributed to an implementation, re-certification, or surveillance cycle.
  • Solid understanding of network security, identity & access management, encryption, and secure SDLC.
  • Experience running third-party and vendor risk management.
  • Strong communicator who can translate complex security concepts to non-technical stakeholders.
  • Experience operating within an integrated management system (ISO 27001 alongside ISO 9001 or similar) is a strong plus.
  • Familiarity with healthcare data regulations (GDPR, potentially HIPAA, or German digital health regulations such as DiGA) is a strong plus.
  • Proven track record with cloud infrastructure (AWS, GCP, or Azure) and modern DevSecOps practices is a plus.
  • Python backend engineering experience is a plus.

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities
Loading...