Information Security and Data Protection Auditor (f/m/d)
GEA Group makes an important contribution to a sustainable future with its solutions and services, particularly in the food, beverage, and pharmaceutical sectors.
The Expert Information Security Governance assures the information security compliance with regulatory, customer, and internal requirements regarding information security (e.g., ISO 27001, NIST, ISA/IEC 62443, IDW PS 980, and others).
Join GEA and make a positive impact: From safe food and beverages to life-saving medicines, GEA makes it possible. We also help our customers reduce CO2 emissions, protect water, and reduce and recycle waste.
GEA Group Services GmbH in Düsseldorf takes over the corporate functions of GEA AG, including areas such as corporate finance, legal, and IT, which provide central services for all company divisions. The location also houses the Digital HUB and the Center of Excellence (CoE).
We are looking for experienced and motivated Information Security and Data Protection Auditor (f/m/d) for deployment in Düsseldorf as soon as possible.
The responsibilities include:
- Accountable for internal ISMS audits according to ISO 27001, as well as IT system audits, supplier audits, and data protection audits.
- Responsible for the planning and preparation of audit programs for both information security and data protection.
- Coordinating audit programs with the areas to be audited and the persons responsible for information security and data protection.
- Preparing audit plans for the respective audits.
- Preparing audit reports and reporting to the audited areas.
- Following up on findings with deadlines.
- Ensuring compliance with audit intervals.
- Initiating external supplier audits.
- Developing a system of key figures for audit performance and its continuous improvement.
- Further developing internal audit standards and quality assurance of audit work.
- Performing special audits due to special circumstances.
- Being open to technical solutions for audit execution and providing impulses for the integration of tools into the audit process.
- Acting as the contact person for the BISOs, RISOs, and LISOs responsible for the audited area.
- Being independent as an auditor and free in judgment.
- Evaluating neutrally without providing advice.
Your Profile / Qualifications:
- Bachelor's or master’s degree in Information Technology, Computer Science, Economics, Law, or a related technical discipline.
- Information Security Certifications (ISMS Lead Implementor, ISMS Lead Auditor, additional in accreditation of a certification body).
- Beneficial (IT) Security Certifications (e.g., CISSP, CISM, CISA, ITIL, COBIT) but are not a must.
- 5+ years of professional experience in information security and data protection.
- In-depth know-how in management systems, audits, and dealing with audit findings.
- Knowledge of security standards such as ISO, PCI, HIPAA, and SOX.
- In-depth know-how in international Data Protection law (GDPR) and standards such as ISO 27701.
- Experience in multivendor management and dealing with multiple suppliers.
- Strong interpersonal skills in communication and collaboration.
- Strong communication skills in English; local language is a plus.
- Strong personal initiative and analytical ability.
- Strong business acumen and problem-solving skills.
- Capabilities in financial and budget ownership.
What we offer:
- Work with a supportive and international team.
- Modern working environment with flexible working options and home office for a good work-life balance.
- A wide range of personal and professional training and development opportunities for your career planning.
- Company pension scheme and accident insurance.
- 30 days annual leave plus 24 & 31 December.
- Attractive company benefits such as discounts on gym memberships.
- JobRad including subsidy.
- Good access to public transport and a subsidy for public transport use.
Did we spark your interest?
Then please click apply above to access our guided application process.