INFORMATION SECURITY MANAGER (f/m/d)
Core
Lead the ISO 27001:2022 Information Security Management System (ISMS), drive DORA compliance, and oversee ICT risk governance and third-party risk oversight.
Role type
Senior Information Security Manager
Builds
Security policies, risk frameworks, and compliance controls aligned with international regulations
Domain
Information Security / Cybersecurity / Regulatory Compliance
Required skills
ISO 27001:2022 ISMS management, DORA compliance, ICT risk governance, Three-Lines-of-Defence model, Security-by-Design architecture reviews, vulnerability management, privileged access management, threat intelligence, incident response lifecycle (NIST-aligned), security exercise coordination
Preferred skills
CISSP, CRISC, CISM, ISO27001 Lead Implementer or Auditor, ISAE3402, SOC1, SOC2 (via careerplan.io/jobs/476957-information-security-manager-fmd-at-360-treasury-systems-ag)
Technologies
ISO 27001, DORA, NIST, Zero-trust networking, Security event monitoring, Intrusion detection, Deception platforms
Responsibilities
Maintain and enhance the ISO 27001:2022 ISMS and policy framework; Oversee compliance with DORA provisions; Run risk analyses in line with regulations; Advise product teams on secure architecture and zero-trust networking; Define and monitor technical controls (vulnerability management, hardening baselines, privileged access); Manage and optimize threat intelligence and security monitoring platforms; Manage the NIST-aligned incident response lifecycle; Coordinate regular cybersecurity exercises
Seniority
Senior, hands-on IC