At Uniper, we proactively transform the world of energy while ensuring the security of energy supply. As an internationally operating company, we work in very diverse teams with the greatest possible working time flexibility for our employees. Our corporate culture is characterized by equal opportunities, mutual appreciation, and respect. With us, you will be able to develop new business models, work on technological solutions for a modern, sustainable, and future-oriented energy supply, as well as proactively help shape changes. Interested? We look forward to meeting you!
Our Risk Management Function is looking for a Head of Group Information Security Management.
The primary target of this role is to ensure protection and integrity of Uniper's information assets, where appropriate based on an effective information security management system (ISMS). The Head of Group Information Security Management reports to the Chief Risk Officer (CRO).
Key responsibilities include:
- Lead the international team of 10+ information security professionals.
- Develop the information security strategy, policies, and overall information security framework.
- Report information security matters to the relevant management bodies and act as key contact for auditors and authorities.
- Ensure compliance with information security requirements and examine information security incidents.
- Initiate and monitor the implementation of information security measures, as well as advise on issues of information security, e.g., help to resolve conflicting goals, support the preparation of respective contingency plans.
- Regularly perform measures to raise awareness (e.g., phishing simulations) and prepare training sessions on information security.
Minimum Qualifications:
- Completed degree in business information technology, computer science, or a similar field.
- Several years of experience in information security, a security-related field, or other information risk management function. Preferably previous experience as information security team lead / Chief Information Security Officer.
- Profound knowledge of information security industry standards and regulatory requirements, e.g. ISO 27001, NIST CSF, NIS 2. Proven track record of implementing new regulation and maintaining compliance.
- Detailed understanding of respective subject matter content, e.g., modern IT technology stacks, control system architecture.
- Capable of assessing trade-offs holistically and making risk-informed decisions.
- Convincingly manage conflicting stakeholder requirements.
- Excellent communication skills across various hierarchical levels in the organization.
Location: Information Security • Düsseldorf, Germany