Back to jobs

INFORMATION SECURITY ASSURANCE EXPERT (ALL GENDERS)

METRO·Düsseldorf, de
Full-timemid
Sign in to applyFree account, takes a minute.

Job description

<p>Purpose of the Role&#xa0;</p><p>To plan, execute, and support independent information security assurance activities across METRO AG and its operating entities. The role provides structured, judgment-driven assessment of the effectiveness, maturity, and alignment of security controls against internal policies, regulatory requirements, and&#xa0;recognized&#xa0;frameworks - enabling informed risk decisions and continuous improvement of the&#xa0;organization’s&#xa0;security posture.&#xa0;</p><p>Key Responsibilities&#xa0;</p><ul><li>Plan and perform information security assurance reviews, including control design and effectiveness assessments, thematic reviews, and targeted evaluations across IT and OT environments.&#xa0;</li><li>Assess the design adequacy and operational effectiveness of security controls based on frameworks such as ISO/IEC 27001, ISO/IEC&#xa0;42001,&#xa0;the NIST Cybersecurity Framework&#xa0;and the NIST AI Risk Management Framework.&#xa0;</li><li>Identify&#xa0;and document control gaps, non-conformities, and risk exposures with proportionate, actionable recommendations.&#xa0;</li><li>Provide&#xa0;subject-matter&#xa0;support to internal and external audit functions as&#xa0;required.&#xa0;</li><li>Collaborate with risk, compliance, and IT teams to track remediation of&#xa0;identified&#xa0;control gaps and ensure&#xa0;timely&#xa0;closure.&#xa0;</li><li>Prepare clear, concise, and well-evidenced assurance reports and recommendations for senior stakeholders.&#xa0;</li><li>Provide guidance to entities and departments in preparing for assurance assessments and building control maturity.&#xa0;</li><li>Support the continuous improvement of the IS assurance program, including&#xa0;methodology, tooling, and automation.&#xa0;</li></ul> <ul><li>Master’s degree in Information Security, Computer Science, or&#xa0;a related&#xa0;field.&#xa0;</li><li>Minimum 3 years of experience in cybersecurity assurance, control assessment, or information security governance.&#xa0;</li><li>Professional certifications preferred (e.g.&#xa0;CISA, CRISC, ISO 27001&#xa0;/ 42001&#xa0;Lead Auditor, ISO 27001&#xa0;/ 42001&#xa0;Lead Implementer, CISSP).&#xa0;</li><li>Solid understanding of cybersecurity controls, governance frameworks, and assurance and assessment methodologies.&#xa0;</li><li>Familiarity with regulatory and compliance requirements (e.g.&#xa0;ISO/IEC 27001, NIS 2, GDPR, EU AI Act).&#xa0;</li><li>Strong communication&#xa0;and reporting skills, with the ability to explain technical issues to non-technical stakeholders.&#xa0;</li><li>Experience working in complex, multinational environments is a plus.&#xa0;</li><li>Fluent English&#xa0;required;&#xa0;additional&#xa0;languages are a plus.&#xa0;</li></ul> <ul><li><strong>Work-life balance:</strong>&#xa0;Flexible working hours in agreement with your line manager, 30 days of holidays.&#xa0;</li><li><strong>Training:</strong>&#xa0;A comprehensive training offer via our own training center or externally.</li><li><strong>Well-being:</strong>&#xa0;Health days with lots of health checks and information about your well-being, company medical care including a range of preventive services, such as flu shots, OTHEB employee assistance program.&#xa0;</li><li><strong>Exciting life on campus:&#xa0;</strong>Free gym and sports classes, Rioba coffee bar, canteen with discounted meals for employees, many campus events.</li><li><strong>Discounts:</strong>&#xa0;discounted Jobticket as well as discounts in our wholesale stores and at many partner companies.</li><li><strong>Comfort:</strong>&#xa0;Good transport connections, free parking spaces, JobBike.&#xa0;</li><li><strong>Company pension plan:</strong>&#xa0;You will receive a contribution to your company pension.&#xa0;</li><li><strong>Family driven:</strong>&#xa0;Three daycare centers for children on campus, support of holiday camps for children of employees.</li></ul>