Cyber risk management and ensuring compliance with IT GRC requirements
Conducting cyber risk assessments and designing measures to mitigate risks
Raising security awareness across the organization
Verifying the effectiveness of security measures by regularly defining and conducting security tests
Regular review of existing platforms against best practices and internal policies and guidelines
Analyzing the impact of the security architecture on security and compliance and continuously developing it
Supporting and being closely involved in application projects to implement a “secure-by-design” strategy
Requirements
Completed Master's, Bachelor's, HF or EFZ degree in Cyber Security, IT/Computer Science, or Business Informatics (certifications such as CISA/CISM/CISSP are a plus)
Several years of experience creating security concepts and policies, and with IT risk management and assessments (ISO 27005 / ISO 31000)
Familiarity with information security standards such as ISO 27001, NIST, BSI IT-Grundschutz, IKS (internal control system) and/or OWASP SAMM
Ability to understand attacker techniques and proactively identify vulnerabilities
Experience in network security, cloud security and application security — able to contribute at an engineering level and incorporate a “security by design” approach from the start
Experience in an OT or energy-related environment is advantageous
Business-fluent German and fluent English; French is an advantage