FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

IT Security & Compliance Program Lead
E.ON Drive Infrastructure. Run IT security and compliance as one program across all markets, with milestones per country .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in information security governance, risk management, and compliance across multiple jurisdictions, with a strong focus on incident reporting, supplier assessment, and regulatory adherence. Proficient in communicating complex security obligations and requirements to stakeholders while maintaining a hands-on approach to implementing cybersecurity regulations.
Highest-signal resume keywords
Information Security GovernanceRisk ManagementCompliance Program ManagementISO 27001 CertificationIncident Reporting
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity RegulationSupplier AssessmentRisk Register MaintenanceSecurity Policy DevelopmentPenetration TestingBusiness Continuity ManagementCrisis ManagementNIS2 ImplementationSOC 2 ComplianceIT Audit
Soft Skills
Clear CommunicationStakeholder CollaborationOwnershipAccountability
Certifications & Qualifications
ISO 27001 Lead ImplementerISO 27001 Lead AuditorBSI IT-Grundschutz PractitionerCISMCISA
Industry Keywords
EnergyOTIoTComplianceSecurity Operations
Tech Stack
Tools & technologiesCyber SecurityIoT
About the role
Key responsibilities & impact- Run IT security and compliance as one program across all markets, with milestones per country
- Track cybersecurity regulation in each market and keep authority registrations current
- Provide country managing directors with regular status visibility
- Maintain the risk register and report to management quarterly
- Assess critical suppliers with procurement and evaluate security terms in supplier contracts
- Own incident reporting as the escalation contact for the managed SOC
- Own security policies and test whether key controls operate effectively
- Organize management security training and employee awareness activities
- Provide security evidence for tenders and audits
- Scope and steer external specialists for penetration tests and technical work
- Act as IT contact for business continuity and crisis management
- Collaborate with Legal, Data Protection, Procurement, Product Owners and business leaders across country organizations
- Work as a senior individual contributor with ownership and accountability and no direct people-management responsibilities
Requirements
What you’ll need- Five to eight years in information security governance, risk and compliance
- Experience in a group with several legal entities or countries, ideally
- Career background in IT operations, infrastructure, security operations or IT audit
- Experience assessing suppliers using SOC 2 or ISO 27001 evidence, following up exceptions and evaluating vendor responses
- Ability to determine within hours whether an incident is reportable and to whom, using incomplete information
- Experience running a compliance program end to end, including planning, milestones, status reporting and closure
- Ability to communicate obligations, costs and requirements clearly to managing directors without jargon
- Hands-on experience implementing NIS2, KRITIS or comparable cybersecurity regulation, ideally across several countries
- ISO 27001 Lead Implementer or Lead Auditor, or BSI IT-Grundschutz Practitioner certification
- CISM or CISA welcome
- Fluent English
- German is a strong advantage for working with the BSI
- Based in Germany, ideally within reach of Essen, with occasional travel to markets
- Experience in energy, OT or IoT environments, or business continuity is a plus
Benefits
Comp & perks- Hybrid working with flexible working hours
- Workation: flexibility to work temporarily from abroad within the EU
- Competitive salary with a performance-related bonus
- Company pension scheme
- Training budget of 5,000 euros per year
- Onboarding with welcome gifts
- All necessary hardware provided
- EDRI events and after-work events
- Inclusive and diverse corporate culture