Information Security Officer driving security strategy and compliance at AllUnity, a fintech company. Leading Information Security Management System design and liaising with regulators and stakeholders.
Responsibilities
Develop, implement, and maintain AllUnity’s Information Security Management System (ISMS) in compliance with ISO 27001, GDPR, ZAG-MaRisk, DORA, and other relevant standards.
Identify, assess, and mitigate information security risks across the organization, safeguarding critical data and systems.
Draft, enforce, and continuously improve information security policies, guidelines, and technical standards.
Lead internal and external audits, coordinate remediation activities, and ensure full regulatory compliance on information security matters.
Act as lead in security incidents and crises, managing detection, response, and recovery processes.
Report on vulnerabilities, incidents, and overall security posture to senior management.
Assess and monitor third-party providers’ compliance with AllUnity’s security standards.
Design and deliver ongoing awareness programs to strengthen security culture across the company.
Serve as Emergency Officer, maintaining readiness, continuity planning, and effective crisis communication.
Act as central contact for supervisory authorities, internal audit, and external auditors on information security matters.
Requirements
Bachelor’s or Master’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or comparable professional training with relevant experience and recognized certifications (e.g., CISSP, CISM, CISA, ISO 27001 Lead Auditor).
At least 6 years in information security, ideally in financial services or banking.
Experience with blockchain/DLT and crypto environments required.
Proven leadership in managing security projects in dynamic, regulated settings.
Strong understanding of ZAG-MaRisk, DORA, GDPR, ISO 27001, and comparable compliance frameworks.
Proficiency with security technologies (SIEM, IDS/IPS, firewalls, endpoint protection, DLP).
Fluent in German and English, with the ability to present complex issues clearly to both technical and non-technical stakeholders.
Benefits
Competitive Compensation
30 Days Paid Vacation
Transparent culture, open communication and a driven, collaborative team committed to innovation, professionalism, and excellence.
IT & Cybersecurity Intern assisting with help desk support and IT system maintenance at OBDeleven. Collaborating with teams and improving IT documentation in a fun workplace culture.
Werkstudent supporting information security management and business continuity projects for Syneco's energy operations. Engaging in the development and upkeep of management systems and reporting tools.
Security Consultant providing IT - Security Consulting by leveraging knowledge and skills to assist clients. Involved in diverse projects from analysis to execution and results presentation.
Lead functional safety for product development in PEM electrolyzers at Quest One. Collaborate with teams and support certification processes in the field of green hydrogen technology.
(Senior) Consultant in Automotive - & Product Security at Wavestone, focusing on cyber security solutions for clients in innovative projects. Collaborative work in a vibrant team environment across multiple German cities.
Consultant specializing in Cyber & Product Security for clients in a hybrid role. Focused on implementing security strategies and conducting assessments with a collaborative approach.
Information Security Manager focusing on risk management for Xecuro GmbH. Implementing and optimizing risk management processes within a technological environment in Bonn.
Information Security Expert working on safe digital solutions, ensuring compliance and conducting risk assessments. Join Xecuro GmbH in shaping Germany's digital future with innovative security measures.
Teamlead position for Security Governance & Assurance at Xecuro GmbH in Bonn. Leading team and implementing information security management systems (ISMS).
Lead ISSO ensuring security compliance for multi - tenant cloud and hybrid environments at Agile Defense. Responsible for vulnerability analyses and risk management decision - making expertise.