Senior Consultant Information Security creating ISMS solutions and supporting clients in effective IT risk management. Collaborating on projects and ensuring compliance with regulations like NIS-2 and DORA.
Responsibilities
You develop tailored ISMS solutions for our clients
You create policies and practical, implementable security concepts
You implement technical and organizational measures
You lead engaging projects to ensure compliance with new regulatory requirements (e.g., NIS-2, DORA) and prepare our clients for the future
You help our clients detect threats early and establish processes for efficient IT risk management
You conduct business impact analyses
You support our clients in embedding information security as an integral part of their organization
Together we will look for projects that match your interests. You will have a say in which client project you work on.
Requirements
Several years of practical experience in information security
Willingness to take responsibility and make decisions
A strong interest in personal development and continuous learning
Excellent self-organization and efficient work-planning skills
Strong interpersonal and leadership abilities
Experience applying standards and regulatory requirements (e.g., ISO 27001, BSI IT-Grundschutz) and adapting them to individual client needs
Confident use of consulting methods such as time management, project and client management, and quality management (nice to have)
Motivation to actively contribute to the further development of carmasec (nice to have)
In-depth knowledge of regulatory standards and industry frameworks (e.g., NIS-2, DORA, BAIT/VAIT, MaRisk, TISAX, CRA) (nice to have)
Ideally, prior experience in a consulting environment (nice to have)
Benefits
Autonomy: Freedom to experiment, an open culture that accepts mistakes, and the opportunity to help shape company structures
Mentorship: Our experienced colleagues support you in your personal and professional development
Flexible working hours: Work during your most productive times and schedule private commitments flexibly. Overtime is compensated
Additional benefits: Choose from options such as a Germany JobTicket, Urban Sports Club membership, childcare subsidy, or a company bike (JobRad)
Training and certifications: We invest in your development through regular training and recognized certifications
Low travel requirements: We work remotely or from our offices in Cologne or Essen. On-site client meetings are the exception
Team building: Our monthly Open Space is dedicated to creative work on current topics. Regular events (e.g., joint workations, summer party, or Christmas celebration) are planned and organized by the team
Workation: Combine work and travel or take an extended sabbatical
Vacation: 30 days of vacation per year plus special leave for significant occasions
Coordenador das atividades de gestão de EHS na BASF, garantindo o cumprimento das normas de saúde e segurança no trabalho. O candidato deve ter sólida experiência em legislações de Saúde e Meio Ambiente.
Safety Coordinator ensuring workplace safety and compliance on client sites in Lisbon. Managing prevention activities and coordinating worksite safety for Bureau Veritas.
Internship in Cybersecurity at Mapfre, gaining hands - on experience in incident response and data analysis. Working within a collaborative team to develop cybersecurity skills and knowledge.
Senior Cybersecurity GRC Specialist shaping Orion Pharma's cybersecurity governance, risk management, and compliance. Engaging with teams to enhance security posture and meet regulatory standards.
Product Security expert ensuring secure software development at NETGEAR. Championing security practices and monitoring vulnerabilities while collaborating with development teams.
System Architect driving secure cloud - native applications using cutting - edge technologies for Product Security at Nokia. Leading AI - driven design and architecture with collaboration across global teams.
Cyber Security Engineer protecting data from threats in a fintech startup. Collaborating with the Information Security Team and implementing security controls for technical projects.
Junior Security Incident Responder in an innovative IT service company protecting clients against cyber threats. Collaborating with teams to enhance IT security and respond to incidents.
Security Incident Responder managing IT security incidents in the Security Operations Center, analyzing threats and coordinating responses effectively for clients' safety.
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.