- Location
- Mainz, Rheinland-Pfalz · Berlin, Berlin · München, Bayern · Mannheim, Baden-Württemberg
- Workplace
- Hybrid, Onsite
- Department
- Security
- Seniority
- Manager
- Source
- Personio
Description
Your new role
As our Information Security Manager (all genders), you will join our growing Information Security team within the broader Privacy & Governance organisation. Together, you will help strengthen and scale NFON's information security capability while protecting our products, services, and business operations. You will drive security governance, collaborate across the business, and contribute to building a strong security culture. This is an opportunity to make a lasting impact in a collaborative environment where you can shape the future of information security at NFON.
The work you‘ll do
- Define, implement, and continuously improve NFON's Information Security Management System (ISMS) and security governance framework.
- Develop and maintain security policies, standards, and procedures aligned with business, regulatory, and customer requirements.
- Conduct security risk assessments and drive mitigation initiatives across products, services, and internal operations.
- Partner with Privacy, R&D, IT Security, Legal, and other stakeholders to embed security into business processes and product development.
- Coordinate internal and external security audits, certifications, and compliance activities.
- Monitor the evolving threat landscape and recommend pragmatic measures to continuously improve NFON's security posture.
- Promote security awareness through training, guidance, and collaboration across the organization.
- Support security incident response activities and drive continuous improvement based on lessons learned.
The qualifications you need
- Experience in information security, privacy, cybersecurity, or information security management.
- Solid understanding of security frameworks and standards such as ISO 27001, NIS2, DORA, BSI C5, or comparable frameworks.
- Experience developing and implementing security policies, governance, and risk management processes.
- Knowledge of the German Telecommunications Act (TKG) and the General Data Protection Regulation (GDPR) is an advantage.
- Ability to collaborate effectively with technical and non-technical stakeholders across an international organisation.
- Strong analytical, communication, and stakeholder management skills.
- A proactive, ownership-driven mindset with the ability to build and continuously improve security capabilities.
- Proficiency in German and English.
What we can offer you
- Permanent employment contract
- Flexible working hours and the option to work hybrid (2 days/week in the office)
- 30 days of vacation
- Modern and ergonomically equipped offices with on-site parking
- Support for further education, including language courses
- Company pension scheme
- Workation (up to 20 days per year)
- Sabbatical opportunity (available after 3 years of company tenure)
- Up to 50 EUR tax-free compensation (combination of Edenred Card for Shopping and Wellpass Membership)
- Professional & confidential mental health support (powered by OpenUp)
- Member at Corporate Benefits
- Choose your preferred device: Windows Laptop or MacBook
- Regular team and company events
- Kindergarten allowance + 10 fully paid child sick days
- JobRad: Good for you, good for the environment
- Subsidy for public transport if office presence >= 60%
- Fruits and beverages in Office
- Referral Programmes - Earn up to €3,000 bonus by referring top talent!