Group Information Security Risk Manager (f/m/d)

Uniper SE
Düsseldorf

COMMON_NOT_TRANSLATED

We are Uniper

At Uniper, we are pro-actively transforming the world of energy whilst at the same time ensuring security of energy supply. As an internationally operating company, we work in very diverse teams with the greatest possible working time flexibility for our employees. Our corporate culture is characterized by equal opportunities, mutual appreciation, and respect. With us, you will be able to develop new business models, work on technological solutions for a modern, sustainable, and future-oriented energy supply as well as pro-actively help to shape changes. Interested? Then we will look forward to meeting you!

Your responsibilities

We are seeking a highly skilled Group Information Security Risk Manager to join our Group Information Security team. You will be responsible for risk management and ensuring regulatory compliance (including NIS2, DORA, Cyber Resilience Act, ISO/IEC 27001, and the NIST Cybersecurity Framework). As a central point of contact for information and cyber risks, you will advise and oversee the business lines and ensure that all information security risks are appropriately managed. This role reports directly to the CISO and requires at least 5+ years of experience in information security and risk management, ideally in critical infrastructure or the energy sector.

Key Responsibilities:

Governance: Develop the information security risk framework (policies, guidelines, processes). Independently review the effectiveness of security controls and measures implemented by the first lines and initiate corrective actions where necessary.
Risk Management: Identify, assess, and monitor information and cyber risks across the entire Uniper Group. Develop risk treatment plans and oversee the implementation of mitigation measures.
Compliance: Ensure compliance with all relevant legal and regulatory requirements (e.g., NIS2 Directive, DORA, KRITIS etc.) as well as internal policies and industry standards (ISO/IEC 27001, NIST-CSF).
Management Reporting: Prepare and present regular reports on the information security status and risk profile to top management and the Board of Management. Develop clear KPI/KRI dashboards to visualize trends and progress in risk and compliance. Escalate critical risks to the CISO and, if necessary, to the Board of Management.
Technical Risk Management: Conduct and support technical risk analyses and security assessments (e.g., threat and vulnerability assessments, risk analyses for various services and systems). Evaluate new technologies, systems, and changes (change risk assessments) from an information security perspective.
Third-Party Risk Management: Assess security risks related to service providers and partners. Ensure external partners meet security and compliance requirements through contract reviews, security evaluations, and ongoing monitoring of critical vendors.

Your profile


• University degree in (business) informatics, information security, engineering, or a comparable field. Additional certifications in information security/risk management (e.g., CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor) are desired.
• At least 5 years of relevant experience in information security, IT risk management, or IT compliance. Experience in a corporate environment or with critical infrastructure (KRITIS), preferably in the energy sector, is desirable.
• Regulatory Expertise: In-depth knowledge of relevant cybersecurity laws and regulations: e.g., EU NIS2 Directive, Digital Operational Resilience Act (DORA), Cyber Resilience Act (EU regulation for digital products), national IT Security Act/BSI Act, and common standards/frameworks (ISO/IEC 27001/27002, NIST-CSF, BSI IT-Grundschutz). Proven experience in implementing these requirements in a corporate setting.
• Information Security Expertise: Deep knowledge of information security methods and techniques: from risk analysis methodologies (e.g., ISO 27005) and vulnerability management to business continuity management (ISO 22301) and incident response. Familiarity with cloud security principles and basic understanding of OT security in industrial environments.
• GRC and Process Knowledge: Experience in using governance, risk & compliance (GRC) tools or ISMS platforms. Experience with risk analysis tools and ticketing systems is a plus.
• Fluent in both German and English (spoken and written). The role requires communication with German-speaking teams and authorities as well as reporting in an international corporate environment.
• Experience working with international teams or projects is an advantage. Cultural awareness and the ability to roll out global security standards across the group are important.

Your benefits

At Uniper, we not only reward our employees with attractive salaries, an excellent company pension and health related benefits for their hard work and dedication to shaping the future energy transition. You can also expect a supportive working culture that offers a wide range of creative and innovative ideas. We enable various flexible working arrangements, whilst also supporting with home office equipment.

Through regular training and workshops, together we work towards visualising yourself in our company as if it were your own. We support you in highlighting your individual potential, achieving your personal goals, and reaching your ambitions. We invite you to become part of our diverse company with international colleagues from more than 80 countries. As an employer, Uniper has committed itself to providing special support to certain areas:

Work-Life-Balance / New Normal:

  • Choosing how, where, and when to work in accordance with your team and the requirements of your job
  • Modern and ergonomic equipment for your workplace (home & office)
  • Support to balance private life and work: Sabbaticals, part-time possibilities, family service

Mobility:

  • Car and bike leasing offer (deferred compensation)
  • E-car charging stations at almost all Uniper locations

Health offers:

  • Flu vaccination
  • Preventive health services
  • Employee assistance program

Company pension:

  • Employer-funded contributions to a modern pension system
  • Possibility of self-funded contributions with employer-funded matching

Trainings:

  • Lifelong training
  • Coaching

Our employees are the reason for our success. Therefore, you will find many other benefits at the local level to help you reach your potential. Energy evolutionary wanted!

Your contact

If you have any questions, please do not hesitate to contact us at:

[email protected]

Attention! Please apply via the button in this portal. Application documents that reach us by post will not be returned and, like those we receive by e-mail, can unfortunately not be considered!

--

As an employer, Uniper is committed to diversity and equal opportunities. Therefore, we encourage applications from suitably qualified individuals whose capabilities match the role requirements regardless of gender, origin, disability, age, religion, ideology, sexual identity or marital status. We live inclusion and support flexible working.

Veröffentlicht am 2026-01-16

Empfohlene Jobs

Facharzt:Fachärztin (m/w/d) für Psychiatrie/ Psychosomatik für Ambulanz

calm Tageskliniken GmbH
Düsseldorf

Freu dich auf Ein interdisziplinäres Team aus ärztlichen und Psychologischen Psychotherapeuten sowie Spezialtherapeuten (Sport, Kreativ u. v. m.) Flache Hierarchien, die ein hohes Maß an Selbsts…

Details Anzeigen
Veröffentlicht am 2025-03-27

Operativer Einkauf (m/w/d)

Page Personnel
Düsseldorf

Aufregender Job mit steigender Verantwortung Abgeschlossene kaufmännische Berufsausbildung im Industrieumfeld FIRMENPROFIL: Mein Kunde ist ein produzierendes Industrieunternehmen im Großra…

Details Anzeigen
Veröffentlicht am 2025-12-22

(Junior) Influencer Marketing Manager DACH (m/w/d)

creamy fabrics by Multiecom
Düsseldorf

WHY CFAB/ CREAMY? Bei cfab / creamy fabrics geht es nicht nur um Kleidung. Es geht um Haltung, Ausdruck und echtes Empowerment. Wir sind mehr als ein Label – wir sind eine Bewegung für Vielf…

Details Anzeigen
Veröffentlicht am 2026-01-28

Experte Customer Support (m/w/d)

Hays AG
Düsseldorf

Ihre Aufgaben: Prozessberatung im Bereich Customer Support (Reklamationen / Garantien / Angebote) Begleitung der Einführung von Dynamics 365 Change Management Beratung von Händlern und En…

Details Anzeigen
Veröffentlicht am 2025-12-20

Teamassistenz/Office Assistent (m/w/d)

Promedis24 GmbH
Düsseldorf

Willkommen bei Promedis24 – Werde Teil unseres Teams! Weißt du, was Promedis24 so besonders macht? Wir lieben genau das, was wir tun. Als spezialisierter Personaldienstleister im Gesundheits- und So…

Details Anzeigen
Veröffentlicht am 2026-01-29

Schülerpraktikum im elektrotechnischen Bereich (m/w/d)

BAUER Elektroanlagen
Düsseldorf

Ein spannendes Praktikum. Für spannende Menschen. Wenn Du herausfinden möchtest, ob ein vielseitiger und zukunftssicherer Beruf im Elektrohandwerk das Richtige für Dich ist, bist Du bei BAUER ge…

Details Anzeigen
Veröffentlicht am 2025-04-07

Teamlead (m/w/d) für Freizeit-Erlebniswelt

7th Space GmbH
Düsseldorf

Willkommen im 7th Space - DER Erlebniswelt für Virtual-Reality-Games, virtuelle Escape Games und vieles mehr! Wir machen Geburtstagsfeiern, Familienausflüge, JGAs und Betriebsfeiern zu etwas ganz Beso…

Details Anzeigen
Veröffentlicht am 2026-01-25

(Kreditoren-) Buchhalter (m/w/d)

Jobactive GmbH
Düsseldorf

(Kreditoren-) Buchhalter (m/w/d) Für unseren Kunden, ein etabliertes Straßenbauunternehmen, suchen wir aktuell einen (Kreditoren-) Buchhalter (m/w/d) in Düsseldorf. Wichtiges vorab: Unbef…

Details Anzeigen
Veröffentlicht am 2025-12-12

Lagermitarbeiter (m/w/d)

Helmut Ratz Getränkehandel
Düsseldorf

Wir sind ein familiengeführtes Unternehmen, bei welchem der Mitarbeiter nicht nur irgendeine Nummer ist, sondern mit in die Familie aufgenommen wird. Wir arbeiten alle gemeinsam und ziehen dabei an e…

Details Anzeigen
Veröffentlicht am 2025-06-15

Field Service Engineer (m/w/d) - Ingenieur, System Engineering / Admin

Prosystems IT
Düsseldorf

Ihre Aufgaben Begleitung von Rollout-Projekten Erbringen von IMAC/R-Tätigkeiten bei unseren Kunden Installation, Umzug sowie Abbau der Hardware Fehlerbeseitigung und technische Wartung de…

Details Anzeigen
Veröffentlicht am 2026-01-20