Head of Information & Cyber Security (m/w/d)
Bremen, Bremen, Germany
OHB SE, headquartered in Bremen, is Germany's first publicly listed aerospace and technology group. Operating in three business units, it serves its international customers with sophisticated solutions and systems. More than 40 years of experience in high technology, combined with expertise in aerospace and telematics, ensures the group's outstanding position as one of the leading independent players in the European aerospace and high-tech industry. OHB SE currently employs around 3,200 people worldwide.
OHB SE is seeking to fill a permanent position at its Bremen location :
Head of Information & Cyber Security (m/w/d)
We are seeking an experienced leader to build and manage our Information Security & Cyber Security department. In this key role, you will develop a modern security organization that protects our products, systems, development environments, and business processes throughout their entire lifecycle. The focus will be on technological information security and cybersecurity, as well as the integration of security requirements into development, production, and operations.
Your tasks
- Establishment and management of the information security and cybersecurity organization
- Development and implementation of the information security strategy in accordance with company, customer and regulatory requirements.
- Establishment, operation and continuous development of an Information Security Management System (ISMS)
- Ensuring compliance with relevant standards and regulatory requirements, in particular ISO 27001, NIS2, BSI IT Baseline Protection, BSI VS-ITR, ECSS security requirements and customer-specific specifications.
- Introduction and anchoring of Security-by-Design, Secure-by-Default and an enterprise-wide Secure Development Lifecycle (SDL) in development, integration and production processes
- Responsibility for product security, cyber resilience, and the protection of hardware, software, and system solutions throughout the entire product lifecycle.
- Responsibility for cyber risk management, security assessments, threat analyses, vulnerability management, penetration testing and security audits.
- Development and enhancement of a zero-trust security approach for enterprise, development, and production environments
- Establishment of measures for supply chain security, including assessment, control and monitoring of security requirements at suppliers and partners.
- Supporting development, software, system and product teams with security-critical issues and with the implementation of security requirements in customer projects.
- Responsibility for the accreditation and approval of safety-critical systems and infrastructures in cooperation with customers, authorities and certification bodies.
- Development and management of processes for incident response, security monitoring, threat detection, business continuity and cyber resilience
- Management of external service providers and collaboration with customers, partners and authorities in all matters relating to information and cyber security.
- Conducting and supporting customer, regulatory and certification audits, as well as ensuring the organization's audit capability.
- Regular reporting to management and executive leadership on security risks, compliance status and necessary measures.
- Building and developing a high-performing security team
Your qualifications
- Completed studies in computer science, IT security, communications engineering or a comparable field
- Several years of professional and management experience in the field of information security, cyber security or product security
- Experience in regulated industries such as aerospace, aviation, defense or critical infrastructure
- Solid knowledge in security engineering, secure software development, network and cloud security, and risk management.
- Good knowledge of common standards and frameworks such as ISO 27001, NIS2, IEC 62443, NIST or BSI basic protection
- Ideally, certifications such as CISSP, CISM, CCSP or ISO 27001 Lead Implementer/Auditor
- Excellent communication skills and the ability to successfully combine technical and organizational requirements.
We offer
Work-life balance: flexible working hours, sabbatical, 30 vacation days & special leave days
Mobile working: hybrid working model & mobile working abroad
Structured onboarding process (including support from a buddy)
Development: Comprehensive training program, individual professional development & annual employee dialogue
Space projects
Additional benefits: 13th gross monthly salary, accident insurance & company pension scheme
Catering: High-quality company restaurant & generous meal allowance
Active health promotion: health management, E-GYM Wellpass & sports groups
Family: Kindergarten subsidy / kindergarten places, children's holiday care & paid sick days for children
Mobility: Subsidized Germany Ticket, Job Bike & Parking
Company celebrations & events: Christmas party, Satellite Launch Events, NextGen Speakers Night
Innovation: Company suggestion scheme & independent research and development
A full overview of our benefits and more details can be found here on our website.
Incase you would like to apply to this job directly from the source, please click here