- Location
- Düsseldorf, NRW,DE, DE
- Type
- Full-time
- Seniority
- Senior
- Source
- Eightfold
Description
CSB / Charm Control governance, coordination and reporting Ownership for VGSG Security Solutions and respective Work Council negotiations Local Incident Management Support and Coordination with DUS Data Center Coordination with the DUS DC Compliance & Security Teams Support for ISO Security Certifications (27001 and 3500) As well as NIS2 / Cyber Resilience Support for Asset Mgt, Vulnerability Assessments and Testings Support Regular work council reports Board Report Security (in Combination with Board Report Privacy) Supplier Security Assessments (local supplier) Government / Authority liaison / interaction Security Clearance process as formal government nominated responsible party Cyber Sec Investigations SPDA for VGSG Projects in coordination with the local cyber assurance team Formal Responsible Party for Security in customer contracts Support for Security customer and government authority Audits Exception Approvals DLP enforcement Cyber Risk Management for VGSG Cyber Support for VGSG audits (internal und external) NIS2 Germany or KriTis) Representation of VGSG in typical security governance bodies What you will do Define and own the end-to-end cyber security strategy, performance and risk posture of VGSG, with full accountability for business outcomes, regulatory compliance and protection of operations and customer trust. Lead and develop the VGSG cyber security organisation, providing direction to cross-functional and matrix teams to deliver measurable improvements in security, resilience and operational performance. Own and optimise the cyber security budget, investment prioritisation and financial performance, ensuring effective resource allocation and delivery of business value. o Act as the accountable cyber security representative for VGSG towards executive leadership, regulators and external stakeholders, owning audits, regulatory commitments and contractual security obligations. What sets you apart Degree in IT, Engineering, Cyber Security or related discipline Recognised industry certifications (e.g. CISSP, CISM, CISA or equivalent) Extensive experience in cyber security leadership, governance frameworks and risk management at scale Demonstrated experience in regulatory and audit environments (e.g. NIS2, ISO27001) Proven leadership of cyber security at organisational or legal-entity level, with accountability for strategy, risk posture and business outcomes. Strong strategic thinking with the ability to define long-term cyber security direction and translate it into executable roadmaps and measurable results. Extensive experience influencing senior stakeholders (C-level, regulators, external partners) and representing the organisation in complex, regulated environments. Deep expertise in cyber security governance, risk management and regulatory compliance frameworks (e.g. ISO 27001, NIS2, KRITIS), applied at enterprise scale. Ability to lead through complexity, driving alignment and execution across multiple functions, geographies and stakeholders, with strong communication skills to articulate complex topics to executive audiences. German and English (min. B2) We also value diversity and equal opportunities. We therefore welcome applications from people with disabilities and will give them special consideration if they are equally qualified. You can find all the information on myHR. Technology by and for people - it makes everything possible. In every respect. It starts with you. It starts now.