IT-Security Specialist (ISO) (m/w/d) at akf bank GmbH And Co KG
berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

27 Dec, 26

Salary

55000.0

Posted On

28 Sep, 26

Experience

3 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

The akf Group, a subsidiary of the international Vorwerk Group, is one of Germany's leading leasing and financing companies. For over five decades, we have been a partner to medium-sized businesses. We understand the needs of our customers in industry and trade and are familiar with the specific characteristics of their sectors. Our regional presence allows us to be close to our customers and act quickly and flexibly. In short: We are a competent partner for customized purchasing, sales, and direct financing of mobile capital goods.

 

We want to continue operating successfully in the market in the future – and for this we need people who fit in with us and want to grow together with us.

 

For our headquarters in Wuppertal, we are looking for an IT Security Specialist (ISO) (m/f/d) to start as soon as possible on a permanent full-time basis.

 

 


Your tasks:

 

Information Security & ISMS

  • Participation in the establishment, maintenance and further development of the ISMS as well as implementation of measures from ISO 27001, DORA, NIS 2 and internal guidelines.
  • Creation and maintenance of safety guidelines, concepts and work instructions, as well as assessment of safety risks and derivation of suitable measures.
  • Tracking of actions from audits, penetration tests and vulnerability analyses

 

Technical coordination in the IT security sector

  • Technical coordination, prioritization and management of operational IT security topics, including maintenance of the security backlog.
  • Evaluation of technical and organizational security measures and preparation of decision-making documents for IT management, CIO and CISO
  • Coordination with specialist departments, data protection, compliance, risk management and external service providers

 

Security Operations & Technical IT Security

  • Operation and further development of security-relevant systems as well as support for SIEM, SOC and vulnerability management processes.
  • Assessment and remediation of vulnerabilities, as well as support in security incidents and incident response.
  • Contributing to the hardening of IT systems, networks, cloud and infrastructure components, and to the selection of security solutions.

 

Regulatory compliance, audits & documentation

  • Preparation of audit-relevant evidence and documentation, as well as support during audits by internal auditors, external auditors, and supervisory authorities.
  • Tracking of findings, measures and deadlines, as well as evaluation of regulatory requirements related to IT security (including DORA, NIS 2)

 

Projects & further development of IT security

  • Support for projects with security relevance and evaluation of new technologies and architectures from a security perspective.
  • Creation of security concepts and risk assessments, as well as participation in the continuous improvement of IT security processes.

 


Your profile:

 

  • Successfully completed studies in computer science, business informatics, IT security or a comparable qualification
  • Solid knowledge of information security, IT security and ISO 27001 / ISMS
  • Very good understanding of regulatory requirements, especially DORA, NIS2 and banking supervisory requirements.
  • Experience in vulnerability management, SIEM/SOC processes, incident response, and network, server, and endpoint security.
  • Secure handling of firewall, VPN, anti-malware, email security solutions as well as Microsoft infrastructures, Active Directory, Windows Server, Microsoft 365 and cloud/hybrid environments
  • Knowledge of IT risk management, action tracking, and audit, testing, and documentation requirements.
  • Excellent German and English skills, both spoken and written.
  • Structured, independent and solution-oriented work style as well as a strong awareness of risk and responsibility.
  • Strong communication skills, assertiveness, and a confident demeanor when dealing with IT, specialist departments, auditors, and management.

Responsibilities

The akf Group, a subsidiary of the international Vorwerk Group, is one of Germany's leading leasing and financing companies. For over five decades, we have been a partner to medium-sized businesses. We understand the needs of our customers in industry and trade and are familiar with the specific characteristics of their sectors. Our regional presence allows us to be close to our customers and act quickly and flexibly. In short: We are a competent partner for customized purchasing, sales, and direct financing of mobile capital goods.

 

We want to continue operating successfully in the market in the future – and for this we need people who fit in with us and want to grow together with us.

 

For our headquarters in Wuppertal, we are looking for an IT Security Specialist (ISO) (m/f/d) to start as soon as possible on a permanent full-time basis.

 

 


Your tasks:

 

Information Security & ISMS

  • Participation in the establishment, maintenance and further development of the ISMS as well as implementation of measures from ISO 27001, DORA, NIS 2 and internal guidelines.
  • Creation and maintenance of safety guidelines, concepts and work instructions, as well as assessment of safety risks and derivation of suitable measures.
  • Tracking of actions from audits, penetration tests and vulnerability analyses

 

Technical coordination in the IT security sector

  • Technical coordination, prioritization and management of operational IT security topics, including maintenance of the security backlog.
  • Evaluation of technical and organizational security measures and preparation of decision-making documents for IT management, CIO and CISO
  • Coordination with specialist departments, data protection, compliance, risk management and external service providers

 

Security Operations & Technical IT Security

  • Operation and further development of security-relevant systems as well as support for SIEM, SOC and vulnerability management processes.
  • Assessment and remediation of vulnerabilities, as well as support in security incidents and incident response.
  • Contributing to the hardening of IT systems, networks, cloud and infrastructure components, and to the selection of security solutions.

 

Regulatory compliance, audits & documentation

  • Preparation of audit-relevant evidence and documentation, as well as support during audits by internal auditors, external auditors, and supervisory authorities.
  • Tracking of findings, measures and deadlines, as well as evaluation of regulatory requirements related to IT security (including DORA, NIS 2)

 

Projects & further development of IT security

  • Support for projects with security relevance and evaluation of new technologies and architectures from a security perspective.
  • Creation of security concepts and risk assessments, as well as participation in the continuous improvement of IT security processes.

 


Your profile:

 

  • Successfully completed studies in computer science, business informatics, IT security or a comparable qualification
  • Solid knowledge of information security, IT security and ISO 27001 / ISMS
  • Very good understanding of regulatory requirements, especially DORA, NIS2 and banking supervisory requirements.
  • Experience in vulnerability management, SIEM/SOC processes, incident response, and network, server, and endpoint security.
  • Secure handling of firewall, VPN, anti-malware, email security solutions as well as Microsoft infrastructures, Active Directory, Windows Server, Microsoft 365 and cloud/hybrid environments
  • Knowledge of IT risk management, action tracking, and audit, testing, and documentation requirements.
  • Excellent German and English skills, both spoken and written.
  • Structured, independent and solution-oriented work style as well as a strong awareness of risk and responsibility.
  • Strong communication skills, assertiveness, and a confident demeanor when dealing with IT, specialist departments, auditors, and management.

Loading...