Инженер.БГ ООД (Engineer.BG ltd.) logo

Corporate IT Security & Risk Oversight Owner

Инженер.БГ ООД (Engineer.BG ltd.)

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Описание на позицията
With more than 14,000 customers worldwide and over 35 years of experience, SEEBURGER is a world leader in business-to-business integration software. Founded in 1986 in Bretten, Germany, SEEBURGER operates 17 subsidiaries across Europe, Asia, and North America.
We provide a central platform and data hub for secure, reliable data transfer and the automated integration of all business processes. Whether integrating with external business partners or internal applications, SEEBURGER makes it all click—both in the cloud and on-prem.

Corporate IT Security & Risk Oversight Owner (ISO Corporate IT, 2nd Line of Defense)
The Blueprint
Provide independent information security and risk oversight for SEEBURGER Corporate IT in the Second Line of Defense
Report directly to the Global Head of Governance, Risk & Compliance
Align Corporate IT at a governance level with SEEBURGER management systems, including:

  • Information Security Management System (ISMS)
  • Data Protection Management System (DSMS)
  • Business Continuity Management System (BCM)
  • AI Management System (AIMS)
  • Enterprise Risk Management System (ERM) incl. Third Party Risk Management System (TPRM)
    Coordinate the creation, maintenance, and continuous improvement of Information Security Process Descriptions within the Corporate IT scope, in alignment with SEEBURGER policies, standards, and control frameworks
    Maintain a complete and up‑to‑date overview of all Corporate IT systems, infrastructure components, platforms, applications, and tools, including security‑relevant classifications and governance attributes
    Assess and review security and risk implications related to Corporate IT architectures, systems, processes, and operational models

Perform And Coordinate Customer Security Assessments, Which Includes

  • Reviewing and validating customer security questionnaires
  • Supporting customer due diligence and assurance requests
  • Ensuring consistent documentation of customer‑facing security statements
    Plan, execute and document risk‑based internal audits and control reviews within the Corporate IT scope.
    Monitor and evaluate control design and control effectiveness for Corporate IT systems and processes
    Support Third‑Party Risk Management (TPRM) in the Corporate IT context, specifically:
  • Providing governance‑level support for vendor, system, and tool‑related risk assessments
  • Participating in reviews of Corporate IT tools and infrastructure components
  • Supporting security and risk assessments related to AI tools within Corporate IT
    Support external certifications, audits, and assurance activities relevant to Corporate IT, including:
  • TISAX
  • ISO/IEC 27001:2022
  • SOC 1
  • SOC 2
  • BSI C5
  • CyberVadis
    Coordinate and provide audit evidence for Corporate IT scopes, ensuring structured handling of auditor inquiries
    Track, document and follow‑up on audit findings, deviations, and remediation measures within the GRC framework
    Execute Second Line of Defense responsibility for Business Continuity Management (BCM) within Corporate IT, including:
  • Overseeing business continuity concepts for Corporate IT
  • Reviewing business impact analyses and continuity measures
  • Assessing BCM control effectiveness and coordinating BCM tests
    Support the SEEBURGER Global Data Protection Manager in data protection matters related to Corporate IT systems and services, including alignment with the DSMS and support during audits and assessments
    Maintain security, risk, data protection, BCM, audit and tool-related documentation for Corporate IT oversight
    Contribute to GRC reporting, management reviews, and internal governance bodies regarding Corporate IT security, risk, data protection, business continuity, and tool governance topics
    Coordinate with Corporate IT and other relevant stakeholders strictly in an oversight and assurance function
    Escalate material risks, control deficiencies, or compliance gaps through defined GRC governance channels

You
Education & Experience: Degree in IT, Information Security (or similar) + 8+ years of professional experience in a 2nd Line of Defense (2LoD), IT audit, or GRC role
Security & Risk Expertise: Strong knowledge of ISMS (ISO 27001), BCM (ISO 22301), and Enterprise Risk Management (ERM)
Audit & Compliance: Hands-on experience executing risk-based internal audits and checking IT controls
Third-Party & Customer Assurance: Experience with TPRM and handling customer security questionnaires
Technical Acumen: Ability to spot security and risk implications in complex IT systems and architectures
Languages: Fluent English; German is a big plus
Mobility & Workstyle: Highly independent, analytical, and comfortable collaborating with senior stakeholders, with readiness for quarterly business travels to Germany
Certifications: Relevant professional certifications (such as CISM, CRISC, or CISA) are a distinct advantage

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Инженер.БГ ООД (Engineer.BG ltd.) was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.