
Careers
Cloud Security Governance & Awareness Specialist
This role focuses on the following tasks:
Responsibilities:
- Performing internal cloud security audits, including:
- Managing requests
- Communicating with suppliers and departments regarding cloud architecture
- Reviewing submitted information material and
- Evaluating the security architecture
- Assessing the risks of use
- Approving and monitoring audits
- Preparing, performing and evaluating the security awareness program for the Group
- Usage of awareness platform to create security awareness training, assessments and phishing simulations
- Selection and customization of training materials and contents
- Running awareness campaigns worldwide and communicate with local information security
- Analyzing training data and creating reports for upper management
- Continuously improving the awareness program together with the IT Security Officer
- Working on improving the security and audits processes
- Supporting the department with security issues, especially regarding cloud services and security awareness
- Analyzing and evaluating security concepts for cloud services
- Reviewing and approving IT security requests
- Participating in the incident response process and working in the Security Operation Center in cooperation with our IT security service provider
Skills and experience:
- Fluent in German
- Successfully completed degree in computer science, information technology or comparable training
- Experience with Cloud Services and architectures (SaaS, IaaS)
- Experience with Awareness programs / campaigns
- Very Good Knowledge of IT systems and structures, networks, protocols, encryption and authentication methods
- Able to understand data flow diagrams, authorization concepts and technical documentation
- Enjoy working with documents, willing to do research and document management
- Read and understand standards and requirement catalogs (TISAX, ISO, etc.), ideally with experience
- At least 4 years of professional experience in one of the following areas: Risk Analysis, Security Governance, Cloud Security, Awareness projects or similar
- Ability to understand complex organizational relationships and areas of responsibility within a large organization and to apply security roles in accordance with information security guidelines