- JTL-Software GmbH
- Mobil, Addis Ababa
- Full-Time
- 4 days ago
Information Security Manager (w/m/d).
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Information Security Manager (w/m/d): our view in 3 lines...
- The Role:This role is for an information security specialist responsible for an ISO/IEC 27001:2022 ISMS in an e-commerce software company.
- The Person:The person will run the ISMS, prepare for and defend audits, maintain policies and standards, manage the cyber risk register, handle external assurance requests, and deliver security awareness training.
- Requirements:The ideal candidate has owned an ISO/IEC 27001 ISMS, run internal audits, written policies and control frameworks, managed a cyber risk register, and handled security assessments.
About the role
Your mission
JTL-Software runs e-commerce software that our customers run their businesses on. Customers, partners and stakeholders trust in JTL to secure their information.
This role runs JTLs information security management system end to end: the ISO/IEC 27001:2022 ISMS, the internal audit programme, the policy and standard framework, the cyber risk register, and security awareness across the company. The goal is to demonstrate, that JTL successfully has established processes to continuously improve its security capabilities.
This is a hands-on role in the security team without management responsibility.Â
ISMS ownership
- Run and maintain the ISO/IEC 27001:2022 management system: scope, Statement of Applicability, control ownership, management review
- Prepare for and defend certification, surveillance and recertification audits
- Keep the evidence base current and collectible, and make it repeatable rather than a scramble before each audit
Internal audit
- Plan and run the internal audit programme against the control set
- Write findings that are specific enough to act on, and drive them to closure with the control owners
- Provide factual assurance to the management team
Policy and standards
- Own the policy and standard framework: authorship, review cycle, approval, publication, versioning
Risk management
- Run the cyber risk register: assessment, treatment plans, acceptance decisions, review cadence
External assurance
- Act as the single point of contact for customer security assessments, questionnaires and due diligence
- Run the response cycle for our investor's portfolio-wide cyber assessment
- Manage third-party and vendor security assessments, and the security half of the vendor onboarding process
Awareness and training
- Design and run the security awareness programme, including role-based training
- Measure whether it changed anything, and change it when it did not
Your profile
- You have personally owned an ISO/IEC 27001 ISMS and defended it in front of an external auditor, through certification, recertification or surveillance. Only advising or having provided implementation guidance is not enough for this role.
- You have planned and run internal audits, written the findings, and driven them to closure
- You have written a policy and control framework and then operated an ISMS on it for at least a year
- You have run a risk register where real treatment and acceptance decisions were made
- technical literacy to look at control evidence from an engineer and tell whether it proves the control
- Fluent English, written and spoken
Why us?
- Remote-first within Germany, with the option to work remotely from eligible countries for up to 180 days per year
- Meal allowance of up to €115 net per month
- Ergonomic workspace allowance for your home office setup
- Regular team events, company-wide gatherings, and summer and Christmas parties to stay connected as a remote-first company
- EGYM Wellpass and JobRad subsidy
- Financial benefits including capital-forming payments (Vermögenswirksame Leistungen) and a company pension scheme

