Local Information Security Officers (w/m/d) at Korian Deutschland GmbH
berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

27 Dec, 26

Salary

55000.0

Posted On

28 Sep, 26

Experience

3 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

About this job

Local Information Security Officers (w/m/d)

Welcome to Team Korian - We look forward to your application!

As Local Information Security Officer (m/f/d), you will be responsible for the information security of Korian Germany, which operates approximately 240 facilities and outpatient services in critical infrastructure environments – reporting directly to our Chief Digital & Information Officer. Together as a team, we at Korian work every day to provide excellent care. The values ​​of "Trust – Initiative – Responsibility" guide our work and are tangibly practiced. Your position will be permanent, based in Munich, and available immediately.

In this role, you will be responsible for the further development of our information and cybersecurity landscape and ensure that regulatory requirements such as NIS2 and ISO 27001 are effectively integrated into our organization and IT landscape.

In this role, you combine security governance and compliance with technical security architecture: You will work closely with the Group Security team in France on a professional level, while managing operational implementation together with our IT departments and external IT service providers. This position is designed as an expert role without disciplinary authority: You will provide technical guidance on standards, guidelines, and security projects, and your influence will extend across all IT areas.

Your future tasks:

  • You ensure the timely fulfillment of NIS2 reporting and documentation obligations and further develop our ISMS according to ISO 27001/NIS2 – including risk registers, guidelines, reporting channels, documentation, audit control and security awareness.
  • You set the security standards and reference architectures for IT and OT and define the requirements for cloud (SaaS, IaaS, PaaS), IAM around Microsoft Entra ID, network (SD-WAN, WLAN, segmentation, firewall policies) and workplace (EDR strategy) – including security-by-design in projects.
  • You will build the security incident and emergency management system and plan the associated processes from detection and NIS2-compliant reporting to recovery – including crisis organization, emergency drills, and analysis and follow-up of incidents for the sustainable derivation of measures.
  • You define the security requirements for applications and in-house developments – from secure software development to vulnerability management – ​​enforce their implementation with IT departments and service providers, and evaluate cloud providers and contracts from a security perspective.
  • You manage the assessment and sustainable reduction of security risks and audit findings, and ensure transparent monitoring of security measures and their effectiveness.
  • As the central contact person in Group Security, you translate the corporate guidelines into the German context, are responsible for reporting security KPIs and incidents, and pragmatically implement security requirements together with internal teams and relevant stakeholders.

This is what you bring with you

  • You have a completed degree in computer science, business informatics, IT security or a comparable qualification.
  • You have at least 8 years of experience in information security and are familiar with regulatory requirements from the KRITIS, NIS2 or ISO 27001 environment from practical experience.
  • You combine strategic thinking with strong implementation skills and have experience in independently building and sustainably establishing ISMS, security processes and structures.
  • Ideally, you have certifications such as CISSP, CISM or ISO 27001 Lead Auditor/Implementer.
  • You have experience in enforcing security requirements with departments and external IT service providers and in monitoring compliance.
  • You possess a broad technical understanding of cloud, network, and application security and can discuss security requirements with technical teams on an equal footing.
  • You are fluent in German and English; knowledge of French is an advantage.
  • You impress with your expertise and assertiveness, enabling you to represent security issues to diverse stakeholders on an equal footing and to sustainably embed them within the organization.

This is what we offer you

  • Diverse career opportunities in a future-oriented and purpose-driven company
  • A dedicated area of ​​responsibility with freedom to contribute.
  • Professional onboarding including your own mentor:
  • A balanced work-life balance with home office arrangements, flexible working hours and diverse health promotion programs.
  • Attractive employee benefits such as a subsidy for company pension schemes, employee benefits within the framework of corporate benefits and much more.
  • Individual training opportunities offered by Corporate Clariane University Germany and personal development opportunities

Responsibilities

About this job

Local Information Security Officers (w/m/d)

Welcome to Team Korian - We look forward to your application!

As Local Information Security Officer (m/f/d), you will be responsible for the information security of Korian Germany, which operates approximately 240 facilities and outpatient services in critical infrastructure environments – reporting directly to our Chief Digital & Information Officer. Together as a team, we at Korian work every day to provide excellent care. The values ​​of "Trust – Initiative – Responsibility" guide our work and are tangibly practiced. Your position will be permanent, based in Munich, and available immediately.

In this role, you will be responsible for the further development of our information and cybersecurity landscape and ensure that regulatory requirements such as NIS2 and ISO 27001 are effectively integrated into our organization and IT landscape.

In this role, you combine security governance and compliance with technical security architecture: You will work closely with the Group Security team in France on a professional level, while managing operational implementation together with our IT departments and external IT service providers. This position is designed as an expert role without disciplinary authority: You will provide technical guidance on standards, guidelines, and security projects, and your influence will extend across all IT areas.

Your future tasks:

  • You ensure the timely fulfillment of NIS2 reporting and documentation obligations and further develop our ISMS according to ISO 27001/NIS2 – including risk registers, guidelines, reporting channels, documentation, audit control and security awareness.
  • You set the security standards and reference architectures for IT and OT and define the requirements for cloud (SaaS, IaaS, PaaS), IAM around Microsoft Entra ID, network (SD-WAN, WLAN, segmentation, firewall policies) and workplace (EDR strategy) – including security-by-design in projects.
  • You will build the security incident and emergency management system and plan the associated processes from detection and NIS2-compliant reporting to recovery – including crisis organization, emergency drills, and analysis and follow-up of incidents for the sustainable derivation of measures.
  • You define the security requirements for applications and in-house developments – from secure software development to vulnerability management – ​​enforce their implementation with IT departments and service providers, and evaluate cloud providers and contracts from a security perspective.
  • You manage the assessment and sustainable reduction of security risks and audit findings, and ensure transparent monitoring of security measures and their effectiveness.
  • As the central contact person in Group Security, you translate the corporate guidelines into the German context, are responsible for reporting security KPIs and incidents, and pragmatically implement security requirements together with internal teams and relevant stakeholders.

This is what you bring with you

  • You have a completed degree in computer science, business informatics, IT security or a comparable qualification.
  • You have at least 8 years of experience in information security and are familiar with regulatory requirements from the KRITIS, NIS2 or ISO 27001 environment from practical experience.
  • You combine strategic thinking with strong implementation skills and have experience in independently building and sustainably establishing ISMS, security processes and structures.
  • Ideally, you have certifications such as CISSP, CISM or ISO 27001 Lead Auditor/Implementer.
  • You have experience in enforcing security requirements with departments and external IT service providers and in monitoring compliance.
  • You possess a broad technical understanding of cloud, network, and application security and can discuss security requirements with technical teams on an equal footing.
  • You are fluent in German and English; knowledge of French is an advantage.
  • You impress with your expertise and assertiveness, enabling you to represent security issues to diverse stakeholders on an equal footing and to sustainably embed them within the organization.

This is what we offer you

  • Diverse career opportunities in a future-oriented and purpose-driven company
  • A dedicated area of ​​responsibility with freedom to contribute.
  • Professional onboarding including your own mentor:
  • A balanced work-life balance with home office arrangements, flexible working hours and diverse health promotion programs.
  • Attractive employee benefits such as a subsidy for company pension schemes, employee benefits within the framework of corporate benefits and much more.
  • Individual training opportunities offered by Corporate Clariane University Germany and personal development opportunities

Loading...