Apply Edge Start your job search

Chief Information Security Officer

BME - Building Materials Europe · North Rhine-Westphalia, Germany

Apply & track with Apply Edge

Purpose of the RoleReporting to the Group CISO, the Regional Information Security Officer DACH is accountable for implementing, maintaining, and continuously improving BME’s information-security charter, standards, policies, processes, and procedures across the DACH region. The role supports the Group CISO in developing and delivering the Group information-security strategy and roadmap, while ensuring practical adoption and measurable impact at OpCo level.Working closely with BME OpCo management, IT Leads, and Security Champions, the RISO establishes and chairs OpCo Information Security Management Forums. These forums provide quarterly oversight of security strategy, performance, compliance, risks, priorities, and resource requirements. The RISO acts as a trusted security advisor and escalation point for the region, driving measurable risk reduction, embedding security into day-to-day operations, and enabling OpCos to make informed, risk-based decisions.Key Tasks and ResponsibilitiesTranslate the BME Group information-security strategy, charter, and roadmap into OpCo-specific governance structures, security calendars, roadmaps, and implementation plans.Establish, chair, and coordinate the OpCo Information Security Management Forums, involving OpCo management, IT leadership, and Security Champions.Support OpCo management teams in evaluating security performance, overseeing compliance, and ensuring that adequate resources are available for continual improvement.Partner with the Group Director Security and IT Operations on the development, implementation, and ongoing improvement of the BME Group security strategy and roadmap.Act as the primary regional contact for information-security matters, providing clear, pragmatic, and business-focused advice to senior stakeholders.Ensure BME information-security policies, standards, processes, and procedures are documented, implemented, communicated, and maintained across DACH OpCos.Monitor OpCo compliance with the BME Information Security Charter and underlying standards and policies; identify gaps and drive appropriate remediation.Define, monitor, and report meaningful security KPIs, control effectiveness, material risks, incidents, exceptions, and remediation progress to OpCo management and Group Information Security.Lead and facilitate information-security risk assessments, define pragmatic mitigation plans, and ensure timely follow-up of material risks and control gaps.Coordinate regional adoption and effective use of Group security services, including detection and response, vulnerability management, security monitoring, and incident-response capabilities.Support the handling, coordination, investigation, and follow-up of security incidents, security requests, and crisis-management activities.Drive security testing activities, including vulnerability assessments, penetration testing, and red-team exercises, and support secure practices throughout the software-development lifecycle.Support third-party cyber-risk management, including supplier security assessments, contractual security requirements, and risk treatment plans.Drive delivery of regional and OpCo security initiatives, ensuring actions have clear owners, milestones, dependencies, and measurable outcomes.Prioritise improvement activities in line with Group objectives and OpCo risk exposure, including identity and access management, privileged access, user-access reviews, secure MFA, vulnerability and patch management, trusted-device controls, endpoint management, network security, cloud security, backup and recovery testing, and end-of-life remediation.Roll out and promote the BME security-awareness programme, helping to build a sustainable culture of security, accountability, and secure behaviours.Support Security Champions in their role as OpCo-level operational contacts for Group Security and the RISO. Security Champions report locally into OpCo IT, with a functional connection to the RISO.Key Functional CompetenciesMinimum five years of experience in a complex information-security role.Hands-on security experience and willingness to get involved in security operations and engineering activities.Strong understanding of information-security governance, risk, controls, compliance, incident response, vulnerability management, and security monitoring.Ability to translate Group security strategy and standards into pragmatic OpCo-level implementation plans.Excellent analytical and communication skills, with the ability to explain security risks, priorities, and required actions clearly to senior stakeholders.Outstanding organisational skills, attention to detail, and the ability to manage multiple initiatives, timelines, and dependencies across OpCos.Ability to work and influence effectively in a federated organisation, building trust with OpCo management, IT Leads, Security Champions, and Group functions.Action-oriented and result-driven, with a high sense of urgency and a strong mindset to get things done thoroughly.Trustworthy, discreet, and respectful of confidentiality.Proficient in German and English, with excellent written and verbal communication skills.LocationThe position is located at Bauking in Dortmund, North Rhine-Westphalia, Germany. Alternatively, the SHK office, located in Kiel, Schleswig-Holstein, Germany. In both cases a hybrid policy is in place that combines weekly on-site presence with travelling to BME HQ based Schiphol, Amsterdam, the Netherlands.Please note that BME does not offer visa sponsorship. Candidates must live already in Germany. Fluent in German and English is required.