newboxes
newboxes
11 – 50 Employees
ConsultingEnterpriseSaaS
newboxes helps organizations navigate technological progress and organizational change through consulting, software, and operational expertise. Its work spans research and development, DevOps, software development, product compliance, agile systems engineering, IT services, and after-sales support. Working alongside client teams, the company helps turn complex projects into practical improvements by strengthening workflows, supporting delivery, and identifying opportunities for greater growth, agility, and organizational resilience.

Information Security & Compliance Manager at newboxes (Hybrid, Munich)

Lead ISO 27001, GDPR, and emerging AI compliance for newboxes’ cloud-native industrial platform. Work in a hybrid role with teams across Germany and India.

Description

  • Manage and continuously improve the ISO 27001-aligned ISMS, covering risk management, policies, and audits
  • Support preparation for further certifications, including BSI C5
  • Implement GDPR controls, including records of processing activities, data protection impact assessments, and data processing agreements
  • Develop and apply data classification and information protection frameworks
  • Handle customer security questionnaires and supplier audits
  • Convert compliance and security obligations into practical IT security requirements for architecture and development
  • Coordinate priorities and monitor implementation progress across the team
  • Work with interdisciplinary colleagues in Germany and India
  • Build the security and compliance foundations of the master.ing cloud-native platform

Requirements

  • A university degree or comparable vocational qualification, combined with professional experience in information security, compliance, or IT
  • Some experience with ISMS, ISO 27001, or audits, preferably in software, industrial, or consulting settings
  • Foundational knowledge of GDPR and cloud security controls such as access management, encryption, and logging
  • Motivation to rapidly learn areas including NIS2, the Cyber Resilience Act, BSI C5, and evolving AI-system regulations
  • A careful, organized working style and determination to carry initiatives through
  • Confident communication with developers and customer CISOs
  • Fluent German and good English
  • Preferred: ISO 27001 Lead Implementer or Lead Auditor certification, CISM, CISSP, or CIPP/E, plus knowledge of export controls and security classification requirements

Benefits

  • Work in a demanding environment at a growing company
  • Take on substantial autonomy and ownership
  • Access defined opportunities for professional growth
  • Collaborate with experienced specialists from the industry
  • Enjoy a modern workplace with an international perspective
  • Use a hybrid setup combining project-based onsite work with remote work

Related Jobs

SPERTON - Where Great People Meet

Sales Executive, Elevators and Car Parking Systems

SPERTON - Where Great People Meet
51 – 200 Employees

Drive elevator and car parking system sales across Mumbai’s Western Region. Build client and dealer relationships, and manage deals from initial enquiry through project execution.

Open