Information Security Officer 80 - 100%
Role details
Job location
Tech stack
Job description
We are looking for an experienced Information Security Officer to join our small but growing IT Governance, Risk and Compliance team in a 2nd-line of-defense role. The mission is to ensure cyber and information security risk-management across the firm. The role will report to the Corporate Security Officer.
Your responsibilities will include:
- Developing, maintaining, and improving the Information Security Management System (ISMS) and Cyber Risk Management framework;
- Review and monitor the organizational security compliance against frameworks and regulatory environments as a global firm;
- Support in further shaping and executing the cybersecurity strategy and management reporting;
- Take an active role in security-related projects (e.g. Information Protection) and initiatives;
- Act as a subject matter expert within teams like the CSIRT, Corporate Security Team and other internal stakeholders;
- Support of Business Continuity Management, Swift Customer Security Programme initiatives and other internal and external audits including regulatory reviews;
- Planning and implementation of training and awareness programs on security culture;
- SupportingOperational Due-Diligence exercises for IT / cyber security related topics;
- Serve as a deputy for team members during their absences, while taking advantage of opportunities for learning and growth within the organization.
Requirements
- Academic degree in Computer Science or a related field;
- Additional education, such as CAS/MAS in Cyber or Information Security, ICT Security Expert, or certifications like CISM, CRISC, CISSP, is an advantage;
- At least 3 years of relevantworking experience in cyber and information security;
- Fluency in English and German is required;
- Solid knowledge of IT processes and controls and good understanding of risk and control frameworks such as (CoBIT, ISO, NIST, ITIL, PCI) and regulatory environments;
- Thorough understanding of the latest security principles, techniques, and protocols;
- Experienced with Microsoft Cloud Security Solutions (Defender Suite, Cloud App Security, Azure Sentinel, Purview) and Cloud Proxy solutions;
- Combines strong problem-solving, analytical, communication, and negotiation skills with a client-focused, proactive, and results-driven approach.