- Location
- Essen, Nordrhein-Westfalen
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Legal
- Seniority
- Lead
- Source
- Personio
Description
Your mission
- Run IT security and compliance as one program across all markets, with milestones per country
- Track the cybersecurity regulation in each market and keep authority registrations current
- Give every country managing director a clear, regular view of where they stand
- Maintain the risk register and report to management quarterly
- Assess our critical suppliers together with procurement and assess the security terms in their contracts
- Own incident reporting as the escalation contact for our managed SOC
- Own the security policies and test that key controls work
- Organize security training for management and awareness for all employees
- Provide the security evidence for tenders and audits
- Scope and steer external specialists for penetration tests and technical work
- Act as IT contact for business continuity and crisis management
You will collaborate closely with Legal, Data Protection, Procurement, Product Owners, and business leaders across our country organizations. Security Operations, Workplace IT, and Data Protection are managed by dedicated specialist teams and partners.
Your profile
- Five to eight years in information security governance, risk and compliance, ideally in a group with several legal entities or countries
- Your career started in IT operations, infrastructure, security operations or IT audit, so you know how systems fail and how controls are bypassed in practice
- You have assessed suppliers beyond the questionnaire: worked through SOC 2 or ISO 27001 evidence, followed up exceptions and judged whether a vendor's answer holds up
- You can decide within hours, with incomplete information, whether an incident is reportable and to whom
- You have run a compliance program end to end: plan, milestones, status reporting and closure, with senior stakeholders who were not security experts
- You build trust with managing directors. You explain what an obligation means for them, what it costs and what you need, in a few minutes and without jargon
- Hands-on experience implementing NIS2, KRITIS or comparable cybersecurity regulation, ideally across several countries
- ISO 27001 Lead Implementer or Lead Auditor, or BSI IT-Grundschutz Practitioner. CISM or CISA is welcome
- Fluent English. German is a strong advantage for working with the BSI
- Based in Germany, ideally within reach of Essen, with occasional travel to our markets
- A plus: experience in energy, OT or IoT environments, or with business continuity
Why us?
- People take centre stage: Become part of a dynamic, ambitious and agile team that develops solutions for the eMobility market and be part of our EDRI events or the next after-work event
- With us, you get the best of both worlds - 100% start-up with the support of a large company
- The freedom you need: We offer you hybrid working with flexible working hours
- Workation: Enjoy the flexibility to work temporarily from abroad – within the EU
- You will receive a competitive salary with a performance-related bonus
- A company pension scheme is of course also one of the benefits with us
- Sustainable learning opportunities: We support you with a training budget of 5,000 euros per year
- You get everything you need to get started: onboarding with welcome gifts and all the hardware you need
Contact
Diversity counts at E.ON. We welcome all people and are convinced that differences make us stronger. Become part of our inclusive and diverse corporate culture!
Seize the opportunity to become part of our E.ON Drive Infrastructure team and not only create prospects for the future of E.ON, but also for your own.
We look forward to getting to know you!
Laura
Junior Recruiter
Do you have any questions or difficulties with your application? Please contact me at [email protected].