Overview
Senior Cyber Security Manager will define, implement and enforce security standards across a modern, API-driven digital landscape. The role protects commercial platforms (e.g., Salesforce, frontend, portal, integrations) while enabling speed and scalability in a fast-paced, resource-conscious environment with multiple priorities. It operates within a federated CISO model and acts as the primary security interface between the Audio business unit and the central CISO Office, balancing risk with business agility and ensuring compliance with regulatory frameworks where applicable.
Responsibilities
- Security Strategy & Governance
- Definition and implementation of a lean, risk-based cyber security strategy aligned with business priorities
- Adoption of security policies, standards, and controls across all digital platforms (CRM, frontend, APIs, ERP, MDM)
- Ownership of identity & access management strategy (SSO, RBAC, least privilege)
- Architecture & Platform Security
- Collaborate with the E2E IT Architect to embed security into architecture design (secure-by-design)
- Define security requirements for API-first and headless architecture (OAuth2, OIDC, token-based security)
- Ensure secure integration patterns across Salesforce, portal, iPaaS, and backend systems
- Risk, Compliance & Operational Security
- Execute risk assessments, vulnerability management, and coordinate penetration testing
- Own monitoring, alerting, and incident response; act as escalation point for security incidents and breaches
- Ensure compliance with GDPR, NIS2, ISO 27001, and internal audit requirements; define data protection and classification standards
- Governance & Reporting
- Regular reporting to leadership on security risks, compliance status, and security KPIs/KRIs
- Participate in security governance boards and risk & compliance forums; escalate critical risks to the central CISO Office
- Translate lessons learned from incidents into improvements
- Vendor & Stakeholder Management
- Security governance for external partners (Salesforce, implementation partners, SaaS vendors)
- Define security requirements in contracts, DPAs, and architecture decisions
- Act as trusted security partner to business leadership; translate security policies into business-relevant requirements and align with business objectives and risk appetite
Qualifications
- Education : Degree in Cyber Security, Information Security, Computer Science, or related field
- Experience and Know-how : 7+ years in cyber security roles within modern cloud and SaaS environments; experience securing API-first architectures and enterprise SaaS platforms; experience working in cross-functional teams with architects, engineering, and business stakeholders. Hands-on cloud security (AWS/Azure) and enterprise SaaS platforms, deep knowledge of Salesforce security models. Strong understanding of OAuth2/OIDC, API gateway security, and securing integration layers (iPaaS, headless architecture). Working knowledge of ISO 27001, NIST CSF, NIS2, and GDPR; familiarity with risk frameworks (e.g., ISO 27005, FAIR) and translating framework requirements into pragmatic controls
- Nice to have : Security certifications (e.g., CISSP, CISM, CISSP-ISSAP, AWS Certified Security – Specialty); experience contributing to large-scale technology transformation programmes (e.g., SAP/cloud migration, ERP rollouts, post-M&A integration)
- Personality and Working Style : Pragmatic, risk-based judgement; able to balance security rigour with business enablement; comfortable navigating ambiguity in a fast-moving environment
- Languages : Fluent English (written and spoken) required; working German preferred
Location
This position can also be filled at the Ovar location.
About Keenfinity
Keenfinity is an equal opportunity employer, offering equal opportunities for all. We welcome applications from people with disabilities and can offer support, if needed. When everyone has a chance to contribute, we all do better.
Contact
Questions about the application process?
Sarah Wurm (Human Resources) —
#J-18808-Ljbffr