- Company Name
- OneSource Consulting
- Job Title
- Security Manager
- Job Description
-
**Job Title**
Senior Information Security Manager
**Role Summary**
Lead the design, implementation, and governance of the organization’s information security program, ensuring compliance with ISO 27001:2022, NIS2, ISAE 3000, and MVS OPDE. Manage the entire ISMS lifecycle, including documentation, audits, and continuous improvement, while overseeing operational security functions, supplier security, vulnerability management, and business continuity planning.
**Expactations**
• Deliver a robust security posture aligned with regulatory and industry standards.
• Maintain comprehensive ISMS documentation and policy lifecycle.
• Lead audit readiness, corrective actions, and continuous improvement.
• Coordinate security requirements across a multi‑supplier ecosystem.
• Provide actionable security reports to senior management and steering committees.
**Key Responsibilities**
- Develop and maintain security strategy and governance framework.
- Create, update, and manage ISMS documentation (ISMS Manual, SoA, compliance records).
- Own the full policy lifecycle: drafting, stakeholder review, legal review, publication, communication, and periodic ISMS review.
- Ensure compliance with ISO 27001:2022, NIS2, ISAE 3000, MVS OPDE, and related standards.
- Collaborate with suppliers to secure their compliance with security requirements.
- Integrate security design into the Configuration Management Database (CMDB).
- Oversee operational security processes: access control, monitoring, incident response.
- Contribute to SOC development and harmonize monitoring requirements.
- Manage vulnerability assessments, remediation plans, and monitoring tools.
- Develop country‑specific continuity scenarios and support BCM/DR plan creation, monitoring, and testing.
- Lead user training, awareness activities, and maintenance of security materials.
- Prepare for and lead internal and external audits; manage corrective actions and continuous improvement.
- Provide regular security posture reports to management and steering committees.
**Required Skills**
- In‑depth knowledge of ISO 27001:2022, NIS2, ISAE 3000, MVS OPDE and other security frameworks.
- ≥5 years of security management experience in complex, documentation‑heavy environments.
- Expertise in security risk management, audit processes, and continuous improvement.
- Proven experience in operational security: access control, incident response, monitoring.
- Familiarity with supplier security, ITSM evaluation, and hosting/data‑center security.
- Proficiency with vulnerability management and monitoring tools.
- Advanced SharePoint Online skills.
- Understanding of the energy sector ecosystem (ENTSO‑E, TSOs, RCCs).
- Fluent in English.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, or related field (preferred).
- ISO 27001 Lead Implementer / Lead Auditor certification (mandatory).
- NIS2‑related cybersecurity certification (preferred).
- Additional certifications such as CISSP, CISM, CEH, CompTIA Security+ (valuable).