Logo for Orcrist Technologies

Group Information Security Manager

Role overview

Qualifications

  • Several years of experience as an ISB or in a comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium
  • Experience building or leading ISO 27001 programmes
  • Solid risk management skills

Responsibilities

  • Build and operate the group-wide ISMS following BSI standards
  • Prepare and accompany ISO 27001 certification, run internal audits
  • Implement NIS-2 obligations: reporting processes, evidence management
  • Own incident response planning and coordinate during incidents

Key facts

Hard skills

Other skills

  • Security Policies
  • Governance
  • Communication
  • Teamwork
  • Problem Solving

About the company

Orcrist Technologies logo

Orcrist Technologies

Defense Technology

Orcrist Technologies offers pioneering AI and data analytics solutions in the private and public sectors, turning sensors into strategy. We are a Berlin-based data defense technology company building AI-powered software for real-time situational awareness and sensor fusion. Our mission is to give decision-makers the clarity they need—when it matters most. Designed for interoperability, speed, and modularity, Orcrist enables NATO and European partners to operate with information dominance in fast-moving, high-threat scenarios.

Company details

IndustryDefense Technology
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Orcrist is building a next generation data intelligence platform using cutting-edge technologies. We're handling petabyte-scale data with sub-second queries. Our product is a Kubernetes‑based platform delivered as B2B SaaS or as a self‑hosted on‑prem solution, including air‑gapped deployments. We enable customers across defense, law enforcement, and enterprise to turn mission-critical data into actionable intelligence.

Role

As Group ISB, you own the information security strategy, programme, and posture of the Vektor Group, from strategy to hands-on execution. You work in close operational partnership with the Director of Internal IT on technical controls and implementation. Your core mandate is ISO 27001 certification on the basis of BSI IT-Grundschutz, together with NIS-2 compliance: from gap analysis and controls implementation through audit readiness, ongoing maintenance, and the regulatory obligations arising under both frameworks.

We build AI platforms for customers in the defence and government sector. Information security is a precondition for our business, not an afterthought. We are building the security organisation while the group grows. During this phase, everyone including leadership works hands-on: day-to-day operational security, direct support for the IT team, and tasks outside the boundaries of a traditional governance role. External consultants support the ramp-up. As the ISMS and the team mature, the balance shifts toward strategy and governance.

What you'll do

  • Build and operate the group-wide ISMS following BSI standards 200-1/200-2/200-3: structure analysis, protection needs assessment, modelling, risk analysis
  • Create and maintain the security policy framework and processes at group level; coordinate company-specific additions
  • Prepare and accompany ISO 27001 certification, run internal audits, work with external auditors
  • Implement NIS-2 obligations: reporting processes, evidence management, corrective action tracking
  • Manage risk across technical and organizational domains, including reporting to executive management
  • Steer external consultants and service providers within the running programme
  • Build and run the security awareness programme: training and sensitization
  • Own incident response planning and coordinate during incidents, together with IT, Legal, and leadership
  • Assess third-party and vendor risk, run security assessments for new tools and partners
  • Work closely with the Director of Internal IT (technical controls: access governance, endpoint security, identity) and with platform engineering (interface to product security)
  • Support sales and customer trust processes: security questionnaires, due diligence, customer audits
  • Track further regulatory requirements (EU AI Act, Cyber Resilience Act, among others) and derive required action

About you

  • Several years of experience as an ISB or in comparable responsibility for information security
  • Proven practice with BSI IT-Grundschutz: BSI standards 200-x and the Grundschutz-Kompendium, ideally including a completed certification procedure
  • Experience building or leading ISO 27001 programmes, from gap analysis to audit readiness
  • Solid risk management: you assess, prioritize, and communicate risk clearly to technical and non-technical audiences
  • Willingness to work hands-on during the build-up phase
  • Confident interaction with executive management, auditors, and customers
  • German at C1 or above, English at B2 or above

Nice-to-haves

  • Certifications: IT-Grundschutz-Praktiker/-Berater, ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM
  • Experience with security governance across multiple legal entities or jurisdictions
  • Experience in regulated environments: defence, government, critical infrastructure; familiarity with VS-NfD, Geheimschutz, or AQAP
  • Practical NIS-2 implementation experience
  • Experience with sales-adjacent security processes (pre-sales, customer audits)

What we offer

  • Remote-first, Germany-wide: Work from wherever you do your best work, with regular team gatherings in Berlin and other off-site locations.
  • Flexibility by default: Flexible working hours help you make work fit your life.
  • Your setup, your way: Get a personal home-office equipment budget to create a workspace that works for you.
  • 30 days of vacation: Take the time you need to recharge and come back with fresh energy.
  • Keep growing: We invest in your personal and professional development.
  • Get rewarded for impact: Performance bonuses are tied to agreed objectives and key results.
  • A warm welcome: Every new team member gets a welcome goodie bag.
  • Good people, good times: From summer and Christmas parties to regular team gatherings, we make time to celebrate together.
  • A mission that matters: Work on challenges with tangible impact on public safety and national security.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

IT Security Manager Related jobs

Other jobs at Orcrist Technologies

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.