Information Security Officer (Dortmund)

International multi-site organization | Germany / DACH region

The opportunity

This regional role is responsible for implementing, maintaining, and continuously improving information security standards, policies, processes, and procedures across the DACH region. You will help translate an international security strategy and roadmap into practical implementation and measurable results within local business units.

Working closely with regional management, IT leaders, and Security Champions, you will establish effective security governance, advise senior stakeholders, and drive measurable risk reduction. The role combines governance and stakeholder leadership with a willingness to engage directly in operational and engineering matters.

What You’ll Do

Translate group-level information security strategies and standards into regional governance structures, security calendars, roadmaps, and implementation plans.

Establish, chair, and coordinate information security management forums with business unit management, IT leadership, and Security Champions.

Support management teams in evaluating security performance, overseeing compliance, and ensuring that appropriate resources are available for continuous improvement.

Serve as the primary regional point of contact for information security matters and provide clear, pragmatic, and business-focused advice to senior stakeholders.

Ensure that security policies, standards, processes, and procedures are documented, implemented, communicated, and maintained throughout the region.

Monitor compliance, identify control gaps, and drive appropriate remediation across local business units.

Define and report on meaningful security KPIs, control effectiveness, material risks, incidents, exceptions, and remediation progress.

Lead information security risk assessments, define practical mitigation plans, and ensure timely follow-up on material risks and control gaps.

Coordinate the regional implementation of security services, including detection and response, vulnerability management, security monitoring, and incident response capabilities.

Support the coordination, investigation, and follow-up of security incidents, security requests, and crisis management activities.

Conduct vulnerability assessments, penetration testing, and red-team exercises, and promote secure practices throughout the software development lifecycle.

Support third-party cyber risk management, including supplier assessments, contractual security requirements, and risk treatment plans.

Drive regional security initiatives with clearly defined owners, milestones, dependencies, and measurable outcomes.

Prioritize improvements across identity and access management, privileged access, MFA, vulnerability and patch management, endpoints, networks, cloud security, backup and recovery, and end-of-life remediation.

Promote security awareness and empower Security Champions to build a sustainable culture of accountability and secure behavior.

What You Bring

A strong understanding of information security governance, risk, controls, compliance, incident response, vulnerability management, and security monitoring.

Hands-on security experience and a willingness to participate in security operations and engineering activities as needed.

The ability to translate international security strategies and standards into practical regional and business-unit implementation plans.

Excellent analytical and communication skills, with the ability to clearly explain risks, priorities, and required actions to senior stakeholders.

Strong organizational skills, attention to detail, and the ability to manage multiple initiatives, timelines, and dependencies across business units.

The ability to exert effective influence within a federated organization and build trust with management, IT leaders, Security Champions, and central functions.

An action-oriented, results-driven approach, with a strong sense of urgency and a commitment to thorough execution.

Sound judgment, discretion, and respect for confidentiality.

Experience and Qualifications

At least five years of experience in a complex information security role, ideally within an international or multi-site organization.

Demonstrable experience in both security governance and operational security delivery.

Experience with security risk assessments, compliance oversight, control monitoring, and remediation programs.

Hands-on experience with incident response, vulnerability management, penetration testing, security monitoring, and third-party cyber risk.

Experience coordinating stakeholders and initiatives across multiple business units or countries.

Professional proficiency in German and English, with strong written and verbal communication skills.

Working Arrangement

The position is based in Schiphol and requires fluency in German; the role involves responsibility for the DACH region. Further details regarding the organization and location will be provided during the recruitment process.

Apply below or call us 0031(0)235121010