Information Security Manager
Indexed description
HAMBURG and LUEBECK
Role Purpose
Founded in 1921, OLDENDORFF CARRIERS combines its history as a German shipowner with the network of one of the world's leading drybulk operators. We currently control some 750 chartered and owned vessels of 67 mio tdw, and we carry around 330 mio tons of raw materials and semi-finished products across the seven seas each year. Our customers can expect 100% performance. All the way.
As part of our ongoing journey towards a modern and innovative Technology organization, we are looking to further strengthen our Information Security Team. We are searching for an Information Security Manager who will play an integral part in shaping Oldendorff's digital future - and in keeping it secure.
Job Responsibilities:
- Build, develop, and operate the Information Security Management System and support the Safety Management System, taking ownership of its continuous improvement.
- Implement and manage regulatory requirements (e.g., KRITIS, NIS2, IMO), ensuring they are reflected in the organization's security governance.
- Develop, maintain, and continuously improve the full set of information security policies, standards, and procedures, translating complex requirements into clear, actionable documents.
- Own the information security risk management process across the organization and its third-party suppliers and service providers: identify and assess risks, and define, track, and monitor mitigation measures.
- Act as information security partner for internal departments, advising on governance, risk, and compliance topics and actively promoting a strong security culture across the organization.
- Support audits and internal revisions, ensuring continuous compliance and driving improvements based on findings and evolving requirements.
What You Bring Along
- Degree in Computer Science, Information Security, or a comparable qualification.
- In-depth experience in information security management, with good knowledge of relevant standards and frameworks (e.g., ISO/IEC 27001, NIST CSF).
- Technical understanding of IT systems, security architectures, and security solutions, enabling you to assess risks, set requirements for and evaluate the effectiveness of security measures.
- A structured, analytical, and risk-based working approach with a high level of ownership and motivation to drive improvements.
- Confident communicator able to explain governance requirements clearly to IT teams, business stakeholders, management, and external parties, and comfortable collaborating across cultures, time zones, functions, and levels of seniority.
- A proactive team player able to work independently, drive topics forward, and follow up on actions with persistence and professionalism.
- Willingness to travel occasionally or visit vessels as part of global information security activities.
- Fluency in written and spoken English.
Nice-to-have
- Certifications such as CISM, ISO/IEC 27001 Implementer/Auditor, or ISA/IEC 62443.
- Exposure to audit, compliance, or IT governance activities.
- Basic understanding of maritime or Operational Technology (OT) regulated environments and familiarity with related frameworks (e.g., IEC 62443, KRITIS).
What we offer
- A collaborative, international working environment with flat hierarchies.
- Fast decision-making and a strong culture of ownership.
- Plenty of room for initiative, new ideas, and personal growth.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search