Senior Information Security Officer (German)
Munich, Bavaria, Germany · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Hawk
Hawk is a global leader in AI-enhanced anti-money laundering (AML) and fraud detection technology. Our solutions combine traditional rule-based systems with transparent AI to help banks and payment providers worldwide enhance AML compliance and fraud prevention, effectively identifying suspicious activity while minimizing false positives. Joining Hawk means being part of a culture built on mutual trust, support, and passion, with ample opportunities for professional growth and impactful work.
Your Role and Mission
We are looking for a highly experienced and technically adept Senior Information Security Officer to strengthen our Information Security team. This role is crucial for sustaining customer trust, aiding pre-sales and sales processes, and ensuring compliance with security standards such as ISO 27001.
You will serve as a vital technical liaison, bridging communications between customers, auditors, internal teams, and our security tools. From handling security inquiries and RFPs to enhancing our Information Security Management System (ISMS) and improving endpoint and access security, you will help protect Hawk’s platforms, data, and operations.
Fluency in German is essential due to frequent interactions with German-speaking clients.
Primary Responsibilities
- Collaborate with Sales and Pre-Sales teams to address security questionnaires, RFPs, and due diligence requests.
- Engage in customer discussions to clarify Hawk's security framework, including technical, compliance, and infrastructure-related queries.
- Confidently represent the company’s security capabilities to regulated financial institutions.
- Maintain and refine Hawk's ISMS in alignment with ISO 27001 standards through policy management, audits, risk assessments, and corrective actions.
- Assist with internal audits and evidence collection to ensure certification readiness.
- Oversee the security of Hawk’s corporate tools, infrastructure, and third-party integrations.
- Conduct vendor security assessments and participate in due diligence for security-related tools.
- Collaborate closely with Engineering, IT, and Information Security teams to enhance platform and enterprise security baselines.
- Communicate complex technical security matters effectively across teams and to customers and auditors.
- Contribute to internal security awareness, documentation accuracy, and process improvements.
Professional Profile
- At least 5 years of practical experience in Information Security or IT Security within B2B technology or SaaS environments.
- Proven capability in managing and enhancing an ISMS compliant with ISO 27001, including policy development, risk analysis, audit participation, and certification upkeep.
- Familiarity with compliance frameworks such as SOC 2, DORA, and NIS 2.
- Strong foundation in IT security principles including authentication, endpoint protection, encryption, and basic networking.
- Technical proficiency across major operating systems such as macOS, Windows, and Linux.
- Experience working with external auditors, certification bodies, and regulatory authorities.
- Relevant certifications are advantageous (ISO 27001 Lead Implementer/Auditor, CISSP, CISM, CRISC, CompTIA Security+).
- Fluent in both German and English for communication with diverse stakeholders.
- Effective at explaining complex security topics clearly to technical and non-technical audiences.
- Strong attention to detail in documentation, ensuring audit-readiness and consistency.
Additional Skills and Benefits
- Experience with identity and access management platforms like JumpCloud or Okta.
- Knowledge of mobile device management (MDM) systems and enterprise security platforms.
- Exposure to third-party risk management and SaaS security tools.
- Experience managing security engagements with regulated financial clients.
- Understanding of GDPR compliance in security contexts.
- A proactive, structured, collaborative work style capable of managing multiple priorities in a fast-moving environment.
Level
Senior