Onventis

IT Compliance & Information Security Manager (m/f/d)

Stellenbeschreibung:

Overview

In this role you will own and evolve the ISMS to meet regulatory and customer requirements for a modern SaaS business. You will translate complex standards (ISO 27001, NIS2, DORA, GDPR) into actionable controls and roadmaps, coordinating audits and governance across engineering, legal, and product teams. You help ensure trust, resilience, and secure use of AI within Onventis. You will be a bridge between compliance, security, and business units, shaping how we operate securely at scale.

Leistungen / Benefits
  • Hybrid work model
  • Free parking
  • Job Ticket
  • JobRad leasing
  • Urban Sports membership
  • fruit, drinks, and meal subsidies","Structured onboarding and training programs","Language courses","Regular team events"),
Verantwortungsbereiche
  • Operate and advance the ISMS based on ISO/IEC 27001 with robust policies, controls and evidence
  • Translate new regulatory requirements into measures, roadmaps and controls (NIS2, DORA, data protection, IT governance, AI-related)
  • Coordinate audits, certifications, and customer reviews; serve as main contact for auditors, customers, and management
  • Conduct risk analyses, identify control gaps, and drive remediation with Engineering, Cloud Operations, Legal, Data Protection, and Product teams
  • Maintain IT-related internal controls, documentation, effectiveness checks, and reporting
  • Evaluate service providers and cloud solutions for compliance, risk, and security throughout their lifecycle
  • Plan and execute awareness, training, and communication to embed regulatory and security requirements
  • Support AI use-case classification and ensure EU AI Act obligations are addressed
Zentrale Anforderungen
  • Several years of experience in information security, IT compliance, IT risk management, IT audit, or GRC in a tech environment
  • Practical ISMS experience per ISO/IEC 27001; familiarity with DORA, NIS2, GDPR
  • Experience preparing for and supporting internal and external audits
  • Ability to translate regulatory requirements into pragmatic SaaS processes and controls
  • Strong German and English communication for cross-functional collaboration
  • Structured, implementation-oriented work style with personal responsibility
  • Certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CISSP are desirable
  • Effective communication
  • Structured, documentation-oriented
  • Cross-functional collaboration
  • ISO/IEC 27001 ISMS
  • Regulatory frameworks: DORA, NIS2, GDPR
  • IT governance and risk management
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    14 Sep 2026
  • Standort:

    Stuttgart

    Einsatzort:

    Germany
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!

Diese Jobs passen zu Deiner Suche:

partner ad:Stepstone partner
Vollzeit Osnabrück
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Geesthacht bei Hamburg
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Marl
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Kiel
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Konstanz
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit München
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Köln
18 Sep 2026Development & IT
partner ad:Stepstone partner
Vollzeit Mainz
19 Sep 2026Development & IT