CYBER SECURITY RISK SENIOR CONSULTANT
Role details
Job location
Tech stack
Job description
Our location is just a stone's throw away from Munich, the beautiful state capital of Bavaria. Do you like sports and other outdoor activities? The Alps and Lake Starnberg are just an hour away and offer a wide range of leisure activities., * Proven track record in developing and implementing enterprise-wide security programs and knowledge in security incident management and business continuity planning
- Performing risk or business impact analysis (on embedded systems, industrial systems (OT), IT and Cloud systems) for medium to big consulting projects including financial quantification of cyber risk and impact analysis of catastrophic scenarios while leading a project team of junior and/or confirmed consultants
- Definition and monitoring of functional and technical mitigation plans, methodological and technical monitoring, data analytics and mathematical modeling
- Plan and lead small consulting projects and significantly participate to consulting projects of medium to big size
- Apply consulting methods independently while documenting and presenting results internally and externally
- Design and delivery of awareness and training to internal and external customers
- Improvement of existing processes and toolings
- Regular advice to customers for possible further support (cross-/up-selling) and Bid preparation for small to medium sized projects or significant support for big sized projects
- Involvement of technical experts to guarantee successful delivery and training of (junior) consultants
- Collaboration in the preparation of offers and company presentations
- Taking on functional and/or project-related tasks in projects (e. g. technical project planning, topic responsibility)
- Preparation of required documentation and presentations of work results
Requirements
- The work task requires knowledge and skills that are generally acquired through a relevant, completed degree programme with a standard duration of up to 4 years in the field of engineering, computer science, cybersecurity or comparable degree programmes and a related extended subject-specific additional qualification. The overall required knowledge and experience may have been acquired in other ways
- Extensive knowledge and experience in the above listed tasks
- Deep understanding of major security and risk management frameworks (ISO 27001, ISO 27005, ISO 31000, NIST CSF, EBIOS RM, FAIR) as well as of security technologies, controls, and best practices
- Ability to develop and maintain security policies, procedures, and standards
- Strong project management skills with experience in managing multiple concurrent projects
- Proven extensive experience leading risk assessment projects and security initiatives, strong experience with risk assessment methodologies and qualitative risk analysis, knowledge of quantitative risk analysis and the associated calculation methods is a plus
- Extensive Knowledge of regulatory requirements across industries (Export Control, GDPR, NIS2, Defense, EASA Regulations) and experience with GRC platforms and risk management tools
- Exceptional ability to communicate complex security concepts to non-technical stakeholders, strong presentation and report writing skills for executive-level audiences and strong negotiation and influence skills, stakeholder management at executive level
- Ability to advise the customer regarding his request and objectives and to build consensus among diverse stakeholders
- Cultural sensitivity for working with international teams
- German and English: negotiation level mandatory (speaking and writing)
- Willingness to travel domestically and abroad
A security clearance is required for this activity or must be issued by the responsible authorities.
This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company's success, reputation and sustainable growth.
Benefits & conditions
Your advantages
- Mobile working and flexible working hours
- Fair and attractive remuneration and special payments
- 30 days' holiday and additional days off for special occasions
- Intensive induction and expert support as part of onboarding in the form of personalized onboarding with a personal mentor
- Excellent training opportunities and promising development prospects
- Attractive social benefits and offers, including employer-financed pension scheme, employee share options, discounted car leasing, bike leasing, special conditions for insurance, employee benefits at cooperating companies
- On-site facilities (depending on location) e.g. canteen and cafeteria, fitness studio, on-site kindergarten, company medical service and other health-related services