About this role
Job title: Lead Auditor Information Security (BSI/ISO 27001)
About the Role The Diehl Group seeks an experienced Information Security Audit professional to coordinate and manage supplier and internal audits. You will oversee security in supplier relationships, align with other audit managers on the Audit Program, and drive continuous improvement through documented audits and remediation.
What You'll Do
- Coordinate and operate all supplier audits and internal information security audits
- Ensure regular monitoring, review, and assessment of security in supplier relationships; closely align with Audit Program
- Create detailed audit plans per round with defined criteria; conduct audits per BSI guidelines (BSI-Grundschutz, ISO 27001) and internal security policies
- Derive appropriate actions from audit findings; coordinate and monitor remediation; ensure open items are closed sustainably
- Perform continuous controls to verify effectiveness of security measures; track improvement plans for internal measures and supplier compliance
What We're Looking For
- Completed IT-related degree or similar with IT security focus; extensive experience with BSI IT-Grundschutz, ISO 27001 or comparable IT security standards in an audit context
- Strong communication skills in German and English (min C1)
- ISO-27001 Lead Auditor certification; ideally also CISM, CISA and/or TISAX Lead Auditor; BSI IT Grundschutz Berater certification
- Industry experience in an officially registered company; high willingness to travel up to 50%
Nice to Have
- Experience in a defence-related or regulated environment would be advantageous
Compensation & Benefits
- Tarifliche Vergütung; Flexible working hours; Company canteen; Corporate health management