Key Responsibilities
- Own and continuously improve the global ISMS in line with ISO 27001.
- Lead information security governance and compliance across the business.
- Engage and influence senior stakeholders on security requirements and best practice.
- Deliver security awareness initiatives and mandatory training.
- Audit ISMS effectiveness and drive continuous improvement.
- Provide practical guidance on implementing ISO 27001 controls across the organisation.
About You
- Proven experience leading and managing an ISO 27001 ISMS.
- Strong governance, compliance and stakeholder management experience.
- Confident influencing senior leaders and driving organisational change.
- Excellent communication skills with a pragmatic, commercial approach.
- Fluent German language skills.
Preferred Experience
- Automotive or manufacturing environment.
- Experience within commercially focused organisations rather than highly regulated sectors.
Package
- Competitive salary
- Company car
- Stock/equity available for the right candidate
- Hybrid working aligned with business expectations
We are seeking an experienced Senior Information Security Consultant - GRC & Compliance to support a leading German financial services client. In this role, you will drive risk management, compliance, audit, and information security initiatives while ensuring adherence to regulatory and industry standards. You will work closely with security, infrastructure, operations, and business teams to strengthen governance frameworks and maintain a robust compliance posture.
Key Responsibilities
- Lead and execute governance, risk management, compliance, and information security initiatives.
- Define, implement, and maintain policies, controls, and certification processes aligned with ISO 27001 and other regulatory requirements.
- Conduct risk assessments, gap analyses, privacy impact assessments, and oversee remediation activities.
- Plan and support internal, external, and third-party audits including ISO 27001, MaRisk, ISAE 3000, ISAE 3402, KRITIS, SWIFT, DORA, and ISO 9001.
- Perform internal control testing, security reviews, and provide recommendations to improve compliance and security effectiveness.
- Deliver compliance reporting, stakeholder presentations, and security awareness training programs.
Required Skills & Experience
- 10+ years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or Risk Management.
- Strong hands-on experience with ISO 27001, risk assessments, compliance frameworks, audit management, and remediation programs.
- Practical knowledge of SOX ITGC, GDPR, DORA, privacy controls, and security breach management.
- Experience working in complex IT environments including infrastructure, networks, data centers, server management, and IT operations.
- Mandatory certifications: ISO 27001 Lead Auditor and CISA.
- German (C1) and English (C1) language skills
- Experience in the banking or financial services sector is highly preferred.
We promote equal opportunities for all employees, regardless of their cultural and social background, gender, disability, age, religion, beliefs, and sexual identity. We give priority consideration to severely disabled applicants and those of equal status in the case of equal suitability.
HCLTech is committed to protecting and securing the privacy and confidentiality of the Personal Data which it collects directly or indirectly from you when applying for a job at HCLTech either directly or through a third-party human resources agency. This notice (the “Notice”) outlines and explains how HCL Technologies Limited including its subsidiaries, local employing entities, associates, and affiliated companies [collectively referred to as “HCLTech”, “us,” “our”, or “we”] will process your Personal Data in accordance with applicable privacy legislation(s).
Incase you would like to apply to this job directly from the source, please click here