(Senior) Consultant Information Security designing customized ISMS solutions and technical measures at a hybrid cybersecurity firm. Collaborating with clients to enhance their security aspects in compliance with regulations.
Responsibilities
You develop tailor-made ISMS solutions for our clients
You create policies and practical, implementable security concepts
You implement technical and organizational measures
You lead engaging projects to comply with new regulatory requirements (e.g., NIS-2, DORA) and prepare our clients optimally for the future
You support our clients in detecting threats early and in establishing processes for efficient IT risk management
You conduct Business Impact Analyses
You help our clients anchor information security as an integral part of their organization
Together we look for projects that match your interests. You participate in choosing which client project you will work on.
Requirements
Several years of practical experience in the field of information security
Willingness to take responsibility and make decisions
Enjoyment of personal development and continuous learning
Strong ability to self-organize and plan work efficiently
Strong interpersonal and leadership skills
Experience applying standards and regulatory requirements (e.g., ISO 27001, BSI IT Baseline Protection) and adapting them to individual client needs
We welcome the following skills from you; otherwise you will acquire them during onboarding: confident use of consulting methods such as time management, project and client management, and quality management
Motivation to actively contribute to the further development of carmasec
In-depth knowledge of regulatory standards and industry frameworks (e.g., NIS-2, DORA, BAIT/VAIT, MaRisk, TISAX, CRA)
Ideally, professional experience in a consulting environment
Benefits
Self-realization: Freedom to experiment, an open error culture, and the opportunity to help shape company structures are a given here.
Mentorship: Our experienced colleagues support you in your personal and professional development.
Flexible working hours: Work during your most productive hours and schedule private commitments flexibly. Overtime is compensated.
Additional benefits: Choose from options such as a Germany job ticket, Urban Sports Club membership, childcare subsidy (Kitaplatz support), or a company bike (JobRad).
Training and development: We invest in your growth through regular training and recognized certifications.
Low travel requirements: We work remotely or from our offices in Cologne or Essen. On-site meetings at client locations are the exception.
Team building: Our monthly Open Space is dedicated to collaborative work on current topics. Regular events (e.g., joint workation, summer party, or Christmas party) are planned and organized by the team.
Workation: Combine work and travel or take an extended break as part of a sabbatical.
Vacation: 30 days of vacation per year and special leave for significant life events.
Internship in Cybersecurity at Mapfre, gaining hands - on experience in incident response and data analysis. Working within a collaborative team to develop cybersecurity skills and knowledge.
Senior Cybersecurity GRC Specialist shaping Orion Pharma's cybersecurity governance, risk management, and compliance. Engaging with teams to enhance security posture and meet regulatory standards.
Product Security expert ensuring secure software development at NETGEAR. Championing security practices and monitoring vulnerabilities while collaborating with development teams.
System Architect driving secure cloud - native applications using cutting - edge technologies for Product Security at Nokia. Leading AI - driven design and architecture with collaboration across global teams.
Cyber Security Engineer protecting data from threats in a fintech startup. Collaborating with the Information Security Team and implementing security controls for technical projects.
Junior Security Incident Responder in an innovative IT service company protecting clients against cyber threats. Collaborating with teams to enhance IT security and respond to incidents.
Security Incident Responder managing IT security incidents in the Security Operations Center, analyzing threats and coordinating responses effectively for clients' safety.
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.
Werkstudent Cyber Security bei Wavestone, Unterstützung im IT - Consulting und Entwicklung im Bereich Cyber - Sicherheit. Analyse von Trends und aktive Teilnahme an Teamaktivitäten.
Project Manager for Security Technology managing complex security projects in MENA region. Involving internal teams and external integrators ensuring project success and client satisfaction.