- Location
- Germering, Bayern
- Type
- Full-time
- Department
- Finance
- Seniority
- Manager
- Source
- Personio
Description
Why should you join?
DocuWare stands for globally distributed, international teams and an open corporate culture that invites you to help shape it. Mobile Work and flexible working hours are part of our everyday life. Would you like to be part of an innovative company whose solutions are digitizing everyday work in a wide range of industries? In that case, we are happy to welcome you to the team.
Your Responsibilities
As Information Security Manager – Risk Management (m/f/d), you will run our information security risk management end-to-end – from the first report of a concern to the quarterly risk report for our C-Level – based on our own scenario-based, quantitative Security Risk Method. In addition, you will be responsible for the information security part of our third-party risk management and support your colleagues with our internal control framework and audits.
Your responsibilities include:
- You are part of our Information Security & BCM organization (CISO area) and will be the go-to Person for security risk and supplier security risk across our group entities.
- You will triage reported concerns, moderate the framing of risk scenarios with Risk Owners, and lead estimation workshops with Cloud Operations, Engineering, Legal, Data Protection, Sales and Customer Success.
- You will estimate frequencies and losses, rate confidence, calculate the expected annual loss and run the plausibility checks – making sure every figure is consistent, comparable and traceable.
- You will assess the efficiency of treatments, prepare treatment and acceptance decisions, consolidate the risk portfolio quarterly and prepare the C-Level report together with the CISO.
- You will evaluate suppliers across the entire lifecycle – from scoping, questionnaires, SOC 2 reports and ISO certificates to contract requirements, the security result and annual reassessments – and link their findings to our risk portfolio.
- You will support your colleagues in maintaining our internal control framework and in internal and external audits such as ISO 27001 and SOC 2 Type 2, and answer customer due diligence, RFP and questionnaire requests on risk and supply chain security.
- As sparring partner to the CISO, you will help develop the risk methodology further, train Risk Owners and Business Owners, and actively shape a risk culture in which people are glad to report.
What you need to succeed
- You have a completed degree in (business) informatics, business administration, information security or risk management, or a comparable qualification.
- You have several years of professional experience in information security, IT risk management or GRC and had hands-on responsibility for risk assessments, ideally with a SaaS, cloud or software provider.
- You run risk assessments independently, including complex and novel cases, and you enjoy moderating workshops with technical and business stakeholders.
- You are comfortable with numbers: scenario-based and quantitative risk analysis (e.g., FAIR), three-point estimates and cost-benefit considerations are familiar to you, and you can challenge an estimate on its order of magnitude.
- You bring a solid understanding of cloud and SaaS architectures, ideally Microsoft Azure, so that you can discuss attack paths and loss scenarios with engineers on equal footing.
- Additionally, a certification such as CRISC, CISM, CISSP, ISO 27005 Risk Manager or Open FAIR, as well as experience with Jira, Confluence or GRC tooling, is an advantage.
- You are characterized by analytical rigor, sound judgment and the ability to challenge constructively – you work independently, take ownership of your portfolio and communicate risks clearly and honestly, up to C-Level.
- You are business fluent in English as you will work across group entities; German is a plus.
What we can offer
There are many great reasons to join DocuWare - our company culture is only one of them. As part of the DocuWare team, you will benefit from many advantages:
- Globally distributed, international teams: You will find our teams working in Germering, New York, Sofia or other worldwide locations.
- Flexible work location and hours: You can work on the road or in our modern office - and you have the flexibility to arrange your own working hours.
- Individual support: After an intensive induction, you will receive regular training tailored to your needs (e.g. conferences, internal team building measures).
- Well-earned rest: 35 vacation days per year, sport offerings, massages, a football table and a relaxing lounge area.
- Healthy food: Together we enjoy Fairtrade coffee with organic milk or oat milk, snacks and fresh fruit - all free of charge - as well as subsidized lunch from the Foodji fridge.
- Good accessibility: Choose how you would like to come to the office with a leased e-bike, by train or via highways A96/A99 (you can charge your e-car on site for free).
- Team spirit: Regular employee and team events (virtual or on-site) ensure excellent collaboration with colleagues around the world.
- Sustainability and social commitment: DocuWare stands for paperless work and supports volunteer organizations and local sports clubs.
- Your health matters: DocuWare subsidizes your company pension plan!
- We offer a stable job with a well-established and growing company.
- Unique benefits: Choose one of three great options (Bonago, E-Gym or subsidized Deutschlandticket) to suit your needs.
- We only use the latest technologies - find out more on Stackshare.
- 30 Days Work from Abroad: Experience international opportunities and broaden your horizons.
- Family First: Preferred enrollment in our selected daycare center in Germering (no guarantee).
- Buddy Program: You'll be paired with a buddy, who will support you during your onboarding and offer valuable tips.
Our Values
Our application process
Your hiring partner
Sarah Jagenow
Recruiting & Employer Branding Specialist
Here you can find us
Planegger Str. 1
82110 Germering