IT Security & Compliance Program Lead (m/f/d)

E.ON Drive Infrastructure
•Hybrid

About The Position

This is a senior individual contributor role within our central IT team, offering significant ownership and accountability without direct people management responsibilities. You will collaborate closely with Legal, Data Protection, Procurement, Product Owners, and business leaders across our country organizations. Security Operations, Workplace IT, and Data Protection are managed by dedicated specialist teams and partners.

Requirements

  • Five to eight years in information security governance, risk and compliance, ideally in a group with several legal entities or countries
  • Career started in IT operations, infrastructure, security operations or IT audit
  • Assessed suppliers beyond the questionnaire: worked through SOC 2 or ISO 27001 evidence, followed up exceptions and judged whether a vendor's answer holds up
  • Can decide within hours, with incomplete information, whether an incident is reportable and to whom
  • Run a compliance program end to end: plan, milestones, status reporting and closure, with senior stakeholders who were not security experts
  • Build trust with managing directors. Explain what an obligation means for them, what it costs and what you need, in a few minutes and without jargon
  • Hands-on experience implementing NIS2, KRITIS or comparable cybersecurity regulation, ideally across several countries
  • ISO 27001 Lead Implementer or Lead Auditor, or BSI IT- Grundschutz Practitioner.
  • CISM or CISA is welcome
  • Fluent English.
  • German is a strong advantage for working with the BSI
  • Based in Germany, ideally within reach of Essen, with occasional travel to our markets

Nice To Haves

  • Experience in energy, OT or IoT environments, or with business continuity

Responsibilities

  • Run IT security and compliance as one program across all markets, with milestones per country
  • Track the cybersecurity regulation in each market and keep authority registrations current
  • Give every country managing director a clear, regular view of where they stand
  • Maintain the risk register and report to management quarterly
  • Assess our critical suppliers together with procurement and assess the security terms in their contracts
  • Own incident reporting as the escalation contact for our managed SOC
  • Own the security policies and test that key controls work
  • Organize security training for management and awareness for all employees
  • Provide the security evidence for tenders and audits
  • Scope and steer external specialists for penetration tests and technical work
  • Act as IT contact for business continuity and crisis management

Benefits

  • Hybrid working with flexible working hours
  • Workation: flexibility to work temporarily from abroad – within the EU
  • Competitive salary with a performance-related bonus
  • Company pension scheme
  • Sustainable learning opportunities: training budget of 5,000 euros per year
  • Onboarding with welcome gifts and all the hardware you need
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service