yandex
ionos2
Страна
Германия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
HeadГибридПолная занятость

Head of GRC (f/m/d)

Оценка ИИ

Высокая позиция с прямым подчинением Group CISO и выходом на совет директоров. Работа в ведущей европейской компании с современным стеком и фокусом на инновации в GRC.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует высокого уровня ответственности, управления командой из 50+ человек и глубоких знаний специфических немецких регуляций (KRITIS, BSI). Необходимость трансформации GRC в формат 'Compliance-as-Code' добавляет технической сложности.

Анализ зарплаты

Медиана145 000 €
Рынок120 000 € – 180 000 €
Оценка ИИ

Предлагаемая позиция Head of GRC в крупной технологической компании уровня IONOS в Германии обычно предполагает вознаграждение выше среднего по рынку. Учитывая масштаб ответственности (KRITIS, NIS2) и руководство большой командой, зарплата будет находиться в верхнем дециле для руководителей в сфере ИБ.

Сопроводительное письмо

Dear Hiring Team at IONOS,

I am writing to express my strong interest in the Head of GRC position. With over a decade of experience in information security and a proven track record of leading large-scale GRC teams, I am particularly drawn to IONOS's vision of 'Compliance-as-Code'. My background in navigating complex ISO 27001 and KRITIS audits within the cloud infrastructure sector aligns perfectly with your requirement to move from a reactive to a proactive, risk-driven organization.

In my previous roles, I have successfully integrated ISMS, Risk Management, and BCM into unified frameworks, significantly reducing operational overhead. I am passionate about automating evidence collection and leveraging AI to streamline GRC processes, ensuring that security remains an enabler for engineering speed rather than a bottleneck. I look forward to the possibility of bringing my strategic vision and technical leadership to the Group CISO's team at IONOS.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в ionos2 уже сейчас

Станьте лидером GRC в IONOS и трансформируйте безопасность ведущего облачного провайдера Европы!

Описание вакансии

At IONOS, the leading European provider of cloud infrastructure, cloud services and hosting services, you will work together with a wide range of teams. We are characterized by open structures, a friendly working culture and flat hierarchies with a strong team spirit. We firmly believe that work and fun are compatible, and offer you the right environment for this. Our constant growth means that we are always looking for new colleagues. Become part of IONOS and grow with us.

The Challenge

As a leading European hosting provider, our infrastructure is the backbone of our customers' digital presence. We operate in a regulated environment where ISO27001, KRITIS and NIS2 are not just acronyms, but core operational requirements. Your challenge is to build a "Compliance-as-Code" culture — ensuring our distributed team of 10+ GRC professionals enables our engineers to move fast while remaining rock-solid against audits. Be the driver that moves the organization from "reactive" (audit-driven) to "proactive" (risk-driven).

Tasks

  • Leadership & Scale: Mentor and lead a high-performing, distributed GRC team (10+ direct FTEs) and an indirect organization of 50+ people. Transition the team from manual evidence gathering to automated, data-driven oversight.
  • End-to-End ISMS Lifecycle Ownership: Having the full accountability for the design, implementation, and continuous improvement of the management system.
  • Integrated Management System (IMS): Lead the team to architect a unified IMS that bridges ISMS, Risk Management, and BCM.
  • Regulatory Authority: Act as the primary interface for the BSI (Federal Office for Information Security). Own the implementation of NIS2 and the KRITIS across our international Brands and Products.
  • Security Audits & Evidence: Drive ISO27001 re-certifications, TKG and BSIG (KRITIS) audits. Move us toward continuous compliance with real-time dashboards for executive reporting.
  • Third-Party Risk (TPRM): In the hosting world, our supply chain is critical. Refine our vendor risk management to meet the stringent requirements of NIS2 and CRA.
  • Collaboration with developing machine learning algorithms in our Dev teams, operating AI tools for our customers and using artificial intelligence in our day to day work to achieve this.Partner with Development teams to integrate machine learning algorithms, leveraging AI tools to enhance customer-facing operations and internal workflows.

Qualifications

  • Senior Tech Leadership: at least 5+ years in GRC/Security & leadership positions, with ideally experience in the Hosting, SaaS, or Cloud sectors. You understand the difference between a "paper" ISMS and an operational one.
  • Strategic Vision: Ability to define a 3-year roadmap for GRC maturity to ensure it evolves with the business. Moving the organization from "reactive" (audit-driven) to "proactive" (risk-driven).
  • Framework Mastery: Hands-on experience with ISO 27001, NIS2 & BCM. You know how to map these frameworks to avoid double work.
  • Regulatory Expert: You have successfully navigated ISO27001/KRITIS audits and are currently preparing (or have implemented) NIS2 strategies.
  • Tooling Visionary: You prefer GRC tools (like Auditboard) over Excel. You able to define a tool driven vision of how GRC is able to work seamless across the organization.
  • Organization Development: You know how to build up a network in a group with 10+ locations, various regional brands and how to structure and steer the organization effectively.
  • Languages: Native/Professional German and fluent English.

Why This Role?

  • High Visibility: You report directly to the Group CISO and have exposure to the Board of Management. Your work directly impacts our ability to sign major enterprise and public-sector contracts.
  • Complexity at Scale: We aren't just securing an office; we are securing a massive, distributed and international  infrastructure that powers thousands of businesses.
  • Innovation: We want a leader who drives the team to automate the "boring" parts of GRC and leverage Artificial Intelligence, so that we can focus on high-level strategic risk.

Location: Berlin or Karlsruhe

Benefits

  • Hybrid working model with home office option.
  • Flexible working hours through trust-based working hours.
  • At some locations a subsidized canteen and various free drinks.
  • Modern office space with very good transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous training and development opportunities.
  • Various health offers, such as sports and health courses.

About IONOS

IONOS is the leading European digitalization partner for small and medium-sized businesses (SMB). The company serves around six million customers and operates across 18 markets in Europe and North America, with its services being accessible worldwide. With its Web Presence & Productivity portfolio, IONOS acts as a 'one-stop shop' for all digitalization needs: from domains and web hosting to classic website builders and do-it-yourself solutions, from e-commerce to online marketing tools. In addition, the company offers Cloud Solutions to enterprises who are looking to move to the cloud as their businesses evolve.

We value diversity and welcome all applications - regardless of, for example, gender, nationality, ethnic or social origin, religion, disability, age as well as sexual orientation and identity, physical characteristics, marital status or any other irrelevant factor subject to applicable law.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • ISO 27001
  • GRC
  • Risk Management
  • Business Continuity Management
  • NIS2
  • KRITIS
  • AuditBoard
  • Machine Learning
  • Cloud Computing
  • SaaS

Возможные вопросы на собеседовании

Проверка видения кандидата по автоматизации комплаенса, что является ключевым требованием вакансии.

Как бы вы реализовали концепцию 'Compliance-as-Code' в распределенной инфраструктуре IONOS?

Важно понять опыт взаимодействия с немецкими регуляторами, так как роль подразумевает роль основного интерфейса для BSI.

Опишите ваш опыт прохождения аудитов KRITIS и взаимодействия с BSI. С какими основными сложностями вы сталкивались?

Роль предполагает управление большой командой; важно оценить лидерские качества.

Как вы планируете управлять и мотивировать распределенную команду из 10 прямых подчиненных и 50 косвенных сотрудников?

Вакансия требует перехода от реактивного к проактивному подходу.

Каков ваш план на первые 90 дней для перевода организации с модели 'audit-driven' на 'risk-driven'?

В тексте упоминается использование ИИ для оптимизации GRC.

Какие конкретные кейсы использования машинного обучения вы видите в процессах GRC для снижения нагрузки на инженеров?

Похожие вакансии

jetbrains
Не указана

Head of Corporate Security

HeadГибридНидерланды
Corporate Security · Risk Management · Crisis Management · Physical Security · Threat Intelligence · Executive Protection · Internal Investigations · Business Continuity Planning
+8 навыков
jetbrains
Не указана

Head of Security (JetBrains Cloud Platform)

HeadГибридНидерланды
Cloud Security · Product Security · Threat Modeling · Identity and Access Management · Secure SDLC · Incident Response · Vulnerability Management · Compliance · Sandboxing · Supply Chain Security
+10 навыков
fieldwire
Не указана

Head of Information Security and GRC

HeadГибридАвстрия
ISO 27001 · SOC2 · NIST · CISSP · CISM · CISA · Cloud Security · AI Security · Risk Management · Incident Response · Security Architecture · IAM · Endpoint Security · Data Security · SDLC · DevSecOps · Application Security · GRC
+18 навыков
fieldwire
Не указана

Head of Information Security and GRC

HeadГибридШвейцария
ISO 27001 · SOC2 · NIST · CISSP · CISM · CISA · Cloud Security · AI Security · GRC · Risk Management · Incident Response · Security Architecture · IAM · Endpoint Security · Data Security · SDLC · DevSecOps · Application Security
+18 навыков
icapitalnetwork
Не указана

Head of Security Engineering - Senior Vice President

HeadУдалённоПортугалия
AWS · Azure · Google Cloud Platform · IAM · PAM · SIEM · CASB · DLP · Kubernetes · Docker · Terraform · CloudFormation · Python · PowerShell · Bash · CISSP · CCSP · Zero Trust · DevSecOps
+19 навыков
dexory
Не указана

Head of IT & Security

HeadВ офисеВеликобритания
IT Strategy · Information Security · Infrastructure · ISO 27001 · GDPR · SOC2 · Vendor Management · Identity & Access Management · Disaster Recovery · Cloud Computing · Incident Response · Budgeting
+12 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

ionos2
Страна
Германия