Information Security Assurance Expert (all genders)

Stellenbeschreibung:

Overview

In this role you will plan, execute, and support independent information security assurance activities across METRO AG and its entities. You will assess the design and effectiveness of controls against internal policies and key frameworks to support risk-based decisions. You’ll produce clear reports for senior stakeholders and drive remediation with cross-functional teams. This position shapes the organization’s security posture in a multinational, regulated environment. You will work with a mission-driven team that values continuous improvement and practical, evidence-based risk management.

Leistungen / Benefits
  • flexible working hours
  • 30 days of holidays
  • training offer via own training center or external
  • health days and well-being programs
  • company medical care and preventive services
  • discounts for stores and partner companies
Verantwortungsbereiche
  • Plan and perform information security assurance reviews across IT and OT environments
  • Assess control design and operational effectiveness against ISO/IEC 27001, ISO/IEC 42001, NIST CSF, and NIST AI RMF
  • Identify and document control gaps and risks with actionable recommendations
  • Provide SME support to internal and external audit functions
  • Collaborate with risk, compliance, and IT teams to track remediation and closure
  • Prepare concise assurance reports and recommendations for senior stakeholders
  • Guide entities in readiness for assurance assessments and improving control maturity
  • Support ongoing improvement of the IS assurance program, including methodology, tooling, and automation
Zentrale Anforderungen
  • Master’s degree in Information Security, Computer Science, or related field
  • Minimum 3 years in cybersecurity assurance, control assessment, or information security governance
  • Professional certifications preferred (CISA, CRISC, ISO 27001/42001 Lead Auditor/Lead Implementer, CISSP)
  • Strong understanding of cybersecurity controls, governance frameworks, and assurance methodologies
  • Familiarity with ISO/IEC 27001, NIS 2, GDPR, EU AI Act
  • Strong communication and reporting skills for non-technical stakeholders
  • Experience in multinational environments is a plus
  • Fluent English; additional languages are a plus
  • strong communication and reporting
  • collaboration across risk, IT, and compliance teams
  • ability to explain technical issues to non-technical stakeholders
  • ISO/IEC 27001
  • ISO/IEC 42001
  • NIST Cybersecurity Framework
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    14 Sep 2026
  • Standort:

    Düsseldorf
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!