Information Security Lead
FullTime Position
Location: Germany (Hamburg or remote) or Iceland (Reykjavik or remote)
Department: Regulatory & Compliance
Reports to: Director of QM & RA
Your role in helping us achieve our mission
As an Information Security Lead you are responsible for improving and managing the security management systems which need to fulfil requirements of i.e. ISO 27001 HiTrust. You identify vulnerabilities and work with our product and tech teams to resolve them while ensuring that our platform and data remain secure. To be successful as an Information Security Lead you are an expert in analytical skills and have indepth knowledge of best practices to prevent a wide range of security threats. Furthermore you are an excellent communicator and are able and like to train and educate our staff on various information security topics.
Responsibilities
- Hardening the security of our platform by i.e. conducting information security risk and compliance assessments for Sidekick Healths internal processes tools products and thirdparty systems to ensure compliance with industry standards and internal information security policies.
- Collaborating with management and product teams to improve security.
- Communicating and promoting Sidekick Healths corporate rules relevant to information security educating colleagues about best practices for information security.
- Keeping up to date with developments in IT security standards threats and the development in the area of AI.
- Overseeing penetration tests to find any flaws.
- Continuously monitor evaluate and enhance security controls to adapt to evolving cyber threats and technological changes.
- Documenting any security breaches and assessing their damage.
- Coordinate information securityrelated activities (e.g. internal audits external audit preparations) in their area of responsibility.
Must haves
- Hold a degree in computer science or a technologyrelated field.
- Have 35 years of experience in a similar role.
- Excellent written and oral communication skills and the ability to communicate complex security concepts to technical and nontechnical audiences.
- Experience with conducting information security risk assessments.
- Experience with security frameworks/standards (e.g. NIST CSF ISO 27k family BSI etc).
- Handson experience with compliance audits and regulatory assessments.
- Knowledge/good understanding of most common data security & privacy regulations (e.g GDPR).
- Familiarity with cloud concepts & technologies (e.g. infrastructure as code serverless architecture etc.
- Excellent written and verbal skills in English.
- A strong commitment to selfdevelopment particularly in Cybersecurity DevSecOps and Data privacy.
- Be humble yet driven and determined & have a teamfirst mentality.
Desired Requirements (Preferred)
- Good understanding of DevSecOps principles and moderncloud architecture.
- Excellent written and verbal skills in German.
So do you care to join us
Required Experience:
Manager