(Senior) Consultant Information Security developing tailored ISMS solutions for clients and leading projects for regulatory compliance while collaborating within a supportive team.
Responsibilities
You develop tailored ISMS solutions for our clients
You create policies and practical, implementable security concepts
You implement technical and organizational measures
You lead engaging projects to comply with new regulatory requirements (e.g., NIS-2, DORA) and prepare our clients for the future
You support clients in detecting threats early and establishing processes for efficient IT risk management
You conduct Business Impact Analyses
You help embed information security as an integral part of the organization
Together we look for projects that match your interests — you have a say in which client project you work on.
Requirements
Several years of hands-on experience in information security
Willingness to take responsibility and make decisions
Enthusiasm for personal development and continuous learning
Strong ability to self-organize and plan work efficiently
Strong interpersonal and leadership skills
Experience applying standards and regulatory requirements (e.g., ISO 27001, BSI IT-Grundschutz) and adapting them to individual client needs
We welcome the following skills; otherwise you will acquire them during onboarding: confident use of consulting methods such as time management, project and client management, and quality management
Motivation to actively contribute to the further development of carmasec
In-depth knowledge of regulatory standards and industry frameworks (e.g., NIS-2, DORA, BAIT/VAIT, MaRisk, TISAX, CRA)
Ideally: prior professional experience in a consulting environment
Benefits
Autonomy: Freedom to experiment, an open culture around mistakes, and the opportunity to help shape company structures are standard for us
Mentorship: Our experienced colleagues support you in your personal and professional development
Flexible working hours: Work during your most productive hours and schedule personal commitments flexibly. Overtime is compensated
Additional benefits: Choose from options such as a Germany public-transport job ticket (Deutschland-Ticket), Urban Sports Club membership, childcare-place subsidy, or a company bicycle (JobRad)
Training and certifications: We invest in your development through regular training and recognized certifications
Low travel requirements: We work remotely or from our offices in Cologne or Essen. On-site client meetings are the exception
Team building: Our monthly Open Space is dedicated to creative collaboration on current topics. Regular events (e.g., team workation, summer party, or Christmas party) are planned and organized by the team
Workation and sabbatical options: Combine work and travel or take an extended break as part of a sabbatical
Vacation: 30 days of vacation per year plus special leave for significant occasions
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.