INFORMATION SECURITY ASSURANCE EXPERT (ALL GENDERS)
METRO·Düsseldorf, de
Full-timemid
Sign in to applyFree account, takes a minute.
Job description
<p>Purpose of the Role </p><p>To plan, execute, and support independent information security assurance activities across METRO AG and its operating entities. The role provides structured, judgment-driven assessment of the effectiveness, maturity, and alignment of security controls against internal policies, regulatory requirements, and recognized frameworks - enabling informed risk decisions and continuous improvement of the organization’s security posture. </p><p>Key Responsibilities </p><ul><li>Plan and perform information security assurance reviews, including control design and effectiveness assessments, thematic reviews, and targeted evaluations across IT and OT environments. </li><li>Assess the design adequacy and operational effectiveness of security controls based on frameworks such as ISO/IEC 27001, ISO/IEC 42001, the NIST Cybersecurity Framework and the NIST AI Risk Management Framework. </li><li>Identify and document control gaps, non-conformities, and risk exposures with proportionate, actionable recommendations. </li><li>Provide subject-matter support to internal and external audit functions as required. </li><li>Collaborate with risk, compliance, and IT teams to track remediation of identified control gaps and ensure timely closure. </li><li>Prepare clear, concise, and well-evidenced assurance reports and recommendations for senior stakeholders. </li><li>Provide guidance to entities and departments in preparing for assurance assessments and building control maturity. </li><li>Support the continuous improvement of the IS assurance program, including methodology, tooling, and automation. </li></ul>
<ul><li>Master’s degree in Information Security, Computer Science, or a related field. </li><li>Minimum 3 years of experience in cybersecurity assurance, control assessment, or information security governance. </li><li>Professional certifications preferred (e.g. CISA, CRISC, ISO 27001 / 42001 Lead Auditor, ISO 27001 / 42001 Lead Implementer, CISSP). </li><li>Solid understanding of cybersecurity controls, governance frameworks, and assurance and assessment methodologies. </li><li>Familiarity with regulatory and compliance requirements (e.g. ISO/IEC 27001, NIS 2, GDPR, EU AI Act). </li><li>Strong communication and reporting skills, with the ability to explain technical issues to non-technical stakeholders. </li><li>Experience working in complex, multinational environments is a plus. </li><li>Fluent English required; additional languages are a plus. </li></ul>
<ul><li><strong>Work-life balance:</strong> Flexible working hours in agreement with your line manager, 30 days of holidays. </li><li><strong>Training:</strong> A comprehensive training offer via our own training center or externally.</li><li><strong>Well-being:</strong> Health days with lots of health checks and information about your well-being, company medical care including a range of preventive services, such as flu shots, OTHEB employee assistance program. </li><li><strong>Exciting life on campus: </strong>Free gym and sports classes, Rioba coffee bar, canteen with discounted meals for employees, many campus events.</li><li><strong>Discounts:</strong> discounted Jobticket as well as discounts in our wholesale stores and at many partner companies.</li><li><strong>Comfort:</strong> Good transport connections, free parking spaces, JobBike. </li><li><strong>Company pension plan:</strong> You will receive a contribution to your company pension. </li><li><strong>Family driven:</strong> Three daycare centers for children on campus, support of holiday camps for children of employees.</li></ul>