Information Security Management Expert

Posted 26 Days Ago
Be an Early Applicant
Strasbourg, Bas-Rhin, Grand Est, FRA
In-Office
Senior level
Artificial Intelligence • Software • Cybersecurity
The Role
Support Information Security Officers in ISMS and business continuity management: perform risk assessments, develop ISMS procedures, security controls, policies, audits, gap assessments, security and disaster recovery plans, and assist formal accreditation for systems handling EU sensitive and classified information.
Summary Generated by Built In
Background:

eu-LISA is the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) manages large-scale IT systems to support the implementation of asylum, border management and migration policies in the European Union (EU). The Agency is also a front-runner for the digitalisation efforts of the EU's Justice and Home Affairs domain, building a new information architecture and contributing to the development of a new security ecosystem. Since the Agency's beginnings in 2012, eu-LISA has become the digital engine of the Schengen Area. With its activities and tasks, the Agency adds value to the EU Member States by supporting their efforts towards justice, security and freedom.

Task description:         
  • Supports the Agency's Information Security Officers in the management of information security and business continuity across organizational business processes and information systems
  • Develop security controls in the context of the agency's information security framework.
  • Expected also to perform the following tasks:
  • Perform risk assessments
  • Develop Information Security Management System (ISMS) procedures
  • Develop conceptual, logical and physical security models as appropriate.
  • Draft security policies, standards, procedures and guidelines in accordance with ISO27001
  • Development of security plans and documentation (e.g. risk treatment plans, security test plans)
  • Development of business continuity and disaster recovery plans.
  • Perform security assessments and audits
  • Perform ISMS control audits
  • Perform ISMS gap assessments
  • Design security controls in accordance with agency information security policies and standards
  • Provide assistance in formal accreditation process for information systems handling EU sensitive and classified information.
Education:      
  • Minimum 4 years of relevant education (master or equivalent) after the secondary school
Minimum Experience:
  • Minimum 6 years of general IT professional experience, of which
  • Minimum 3 years of relevant professional experience in Information Security Management
Additional needed qualification, knowledge and skills:         
  • Good knowledge of/in:
  • ISO27001 implementation and management.
  • Relevant standards and good practice in information security management
  • Information risk management (in particular E-BIOS)
  • Governance, Risk & Compliance (GRC) practices and controls
  • ISO27001 security control audits and assessments
  • Developing security policies, standards and guidelines in accordance with ISO27001 and EU security policies and standards
  • Design, implementation and assessments of good practice security control frameworks such as SANS Top 20 Critical Controls, OWASP Application Security Verification Standard,
  • Secure development processes (Security and Privacy design)
  • Implementation of EU data protection principles in information system design and processes.
  • This profile is expected to possess one or more of the following qualifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • ITIL/ITIL V3
  • BSI ISO27001 Lead Auditor Qualification

Skills Required

  • Minimum 4 years of relevant education (master or equivalent) after secondary school
  • Minimum 6 years of general IT professional experience
  • Minimum 3 years of relevant professional experience in Information Security Management
  • Knowledge of ISO27001 implementation and management
  • Experience with Information Risk Management, in particular E-BIOS
  • Knowledge of Governance, Risk & Compliance (GRC) practices and controls
  • Experience performing ISO27001 security control audits, ISMS control audits, and gap assessments
  • Ability to develop security policies, standards, procedures and guidelines in accordance with ISO27001 and EU security policies
  • Familiarity with security control frameworks such as SANS Top 20 and OWASP ASVS
  • Experience with secure development processes and security/privacy by design
  • Implementation of EU data protection principles in information system design and processes
  • Experience developing business continuity and disaster recovery plans
  • Assistance in formal accreditation processes for information systems handling EU sensitive and classified information
  • Possess one or more certifications: CISSP, CISM, CISA, ITIL/ITIL V3, or BSI ISO27001 Lead Auditor
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company

What We Do

Spektrum Labs is building the backbone of the cyber resilience ecosystem, unifying cybersecurity, compliance, and insurance into one seamless platform powered by AI, cryptography, and automation.

Similar Jobs

Mondelēz International Logo Mondelēz International

Senior Director, Global Supply Chain Excellence Program & Focused Improvement Lead

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
29 Locations
90000 Employees
174K-287K Annually

Samsara Logo Samsara

Sales Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
France
4000 Employees

SailPoint Logo SailPoint

Sales Executive

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
France
2461 Employees
68K-102K Annually

Pfizer Logo Pfizer

Machine Learning Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
32 Locations
121990 Employees
163K-272K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account