- You define and drive the information security strategy and roadmap for Chrono24, aligning with business objectives and regulatory requirements including ISO 27001,NIS2, and CRA.
- You own information security governance, risk management, and compliance across the organization, ensuring risk owners understand and act on their responsibilities.
- You lead and coordinate incident response, overseeing our Security Incident Response Team (SIRT) processes and ensuring readiness when it matters.
- You steer our vulnerability management program,coordinating internal scans, external assessments,and take responsibility for our bug bounty program.
- You build and run the security awareness program, including phishing campaigns, training, and fostering a security-conscious culture company-wide.
- You assess and manage third-party and vendor security risks, ensuring our partners and service providers meet our security standards.
- You drive audit readiness and compliance, coordinating ISO 27001 audits, NIS2 preparation, and collaboration with external auditors and your Information Security Officer.
- You contribute to business continuity management, ensuring security considerations are embedded in our continuity processes.
Your team
Your direct team consists of a Principal Security Engineer and an Information Security Officer. The Principal Security Engineer owns application security and our Secure Software Development Lifecycle (SSDLC), including secure coding standards, vulnerability management, penetration testing, and cryptography controls. The Information Security Officer manages ISMS operations, compliance documentation, and audit coordination. Beyond your direct team, you will work closely with Product & Technology, especially Platform Engineering, DevOps, and IT, to embed security into engineering practices.