Job
- Level
- Experienced
- Job Field
- IT, Project, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- from 70.000 € gross/year
- Location
- Vienna
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will develop an information security management system, coordinate security measures and audits, and be responsible for risk management and training to promote a security culture.
Job Technologies
Your role in the team
- They build, operate, and continuously develop the Information Security Management System (ISMS) of the Austrian Academy of Sciences (ÖAW) based on ISO/IEC 27001.
- You are the central point of contact and coordination for organization-wide questions regarding information security management.
- They develop decision-making bases and action recommendations for suitable information security measures for the Presidium and the Directorate of Institutes and Infrastructure (DII).
- You manage the ISMS document architecture and coordinate the creation, alignment, approval, and regular review of strategies, policies, standards, and procedures.
- They coordinate information security risk management, support risk identification and assessment, and monitor the implementation of approved risk mitigation measures.
- Together with the responsible technical teams, you define requirements for logging, security monitoring, and incident management, and oversee their proper implementation and effectiveness.
- They plan and coordinate internal and external information security audits, security reviews, and penetration tests, and follow up on the resulting measures.
- You prepare regular reports on risk situation, security incidents, control effectiveness, measures status, and maturity level of the ISMS for submission to the Executive Board and DII, and you prepare the ISMS management review.
- You design and coordinate target group-specific training and awareness measures and support the development of the information security culture.
- They monitor the implementation and effectiveness of established security measures and trace deviations as well as improvement actions transparently.
- They coordinate collaboration with the Legal and Compliance Department, other internal units, and external partners to ensure compliance with legal requirements and relevant industry standards.
This text has been machine translated. Show original
Our expectations of you
Education
- Completed technical degree at a university or university of applied sciences, ideally in computer science or business informatics with a focus on information security, or equivalent knowledge from previous roles.
Qualifications
- Good understanding of modern IT and security architectures, especially cloud security, identity and access management (IAM), system hardening, network security, security monitoring, and Zero Trust architectures.
- Knowledge of relevant legal and regulatory requirements, primarily data protection, and possibly the NIS-2 Directive and the Network and Information Systems Security Act (NISG).
- Ability to prepare technical and organizational issues in a manner suitable for the target audience, including specialized departments and management bodies.
- Strong consulting, moderation, communication, and presentation skills.
- Structured, autonomous, and solution-oriented way of working.
- Certifications such as ISO/IEC 27001 Lead Implementer or Lead Auditor, CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), or qualifications in COBIT or ITIL.
Experience
- At least five years of relevant professional experience in comparable positions (information security management, IT security, IT operations, IT audit).
- In-depth knowledge of ISO/IEC 27001 and ISO/IEC 27002, as well as practical experience in establishing, operating, or developing an Information Security Management System (ISMS).
- Experience in identifying, assessing, and managing information security risks.
- Experience with policies, control assessments, audits, management reporting, and action tracking.
- Advantage: Experience in complex or decentralized organizations as well as in project and stakeholder management, ideally complemented by a certification such as IPMA or PRINCE2.
This text has been machine translated. Show original
What we offer
- A key position in an innovative and internationally oriented environment.
- Workplace in the central Vienna city center with flexible flextime arrangements and the possibility of working from home.
- Attractive social benefits, such as additional vacation days, paid lunch breaks, and discounts for ÖAW employees.
- The annual gross salary for this position is EUR 70,000 on a full-time basis.
- In part-time employment, an aliquot adjustment is made according to the agreed working hours.
- Depending on qualifications and professional experience, we offer a market-compliant overpayment.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Topics You Will Work On
Job Locations
About Your Employer
Österreichische Akademie der Wissenschaften
Wien
The ÖAW is Austria's largest non-university research institution. Founded in 1847 as a society of scholars, its mandate is "to promote science in every way possible.
Description
- Founding Year
- 1847
- Language
- English
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Science, Research
Employer reviews
by devworkplaces.com
Total
(2 Reviews)3.5
Culture
3.6Engineering
2.8Career Growth
3.8Workingconditions
4.0