ISO - Information Security Officer (w/m/x)

Österreichische Akademie der Wissenschaften (OeAW)Vienna, State of ViennaOn-siteFull-timeStaff, 8–12 yearsListed 2 days ago

Apply now

About this role

ISO - Information Security Officer (w/m/x)

Your responsibilities

Your responsibilities

- You establish, operate and continuously develop the information security management system (ISMS) of the Austrian Academy of Sciences (ÖAW) in line with ISO/IEC 27001.

- You act as the central point of contact and coordination for all organisation-wide matters relating to information security management.

- You prepare decision papers and recommendations on appropriate information security measures for the Presidential Board and the Directorate for Institutes and Infrastructure (DII).

- You maintain the ISMS documentation framework and steer the drafting, consultation, approval and periodic review of strategies, policies, standards and procedures.

- You coordinate information security risk management, support the identification and assessment of risks, and monitor the implementation of approved risk treatment measures.

- Together with the relevant technical units, you define requirements for logging, security monitoring and incident management, and verify that these are implemented appropriately and remain effective.

- You plan and coordinate internal and external information security audits, security reviews and penetration tests, and follow up on the resulting actions.

- You produce regular reports on the risk landscape, security incidents, control effectiveness, the status of measures and the maturity of the ISMS for the Presidential Board and the DII, and you prepare the ISMS management review.

- You design and coordinate target-group-specific training and awareness programmes and help advance the ÖAW's information security culture.

- You monitor the implementation and effectiveness of the security measures in place and track deviations and improvement measures in a documented and auditable way.

- You work closely with the Legal and Compliance Department as well as with other internal teams and external partners to ensure compliance with legal requirements and sector-specific standards.

Your profile

Your profile

- A completed degree from a university or university of applied sciences, ideally in computer science or business informatics with a focus on information security, or equivalent knowledge acquired in previous roles.

- At least five years of relevant professional experience in comparable positions (information security manager, IT security, IT operations, IT audit).

- Sound knowledge of ISO/IEC 27001 and ISO/IEC 27002, combined with hands-on experience in establishing, operating or further developing an information security management system (ISMS).

- Experience in identifying, assessing and treating information security risks.
Experience with policies, control assessments, audits, management reporting and the tracking of corrective actions.

- A solid understanding of modern IT and security architectures, in particular cloud security, identity and access management (IAM), system hardening, network security, security monitoring and zero trust.

- Knowledge of the relevant legal and regulatory requirements, in particular data protection and, where applicable, the NIS2 Directive and its Austrian implementation (Network and Information System Security Act, NISG).

- The ability to present technical and organisational matters in a way that suits the audience, from specialist units to governing bodies.

- Strong advisory, facilitation, communication and presentation skills.
A structured, self-directed and solution-oriented way of working.

Desirable :

- Experience in complex or decentralised organisations and in project and stakeholder management, ideally supported by a certification such as IPMA or PRINCE2.

- Certifications such as ISO/IEC 27001 Lead Implementer or Lead Auditor, CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), or qualifications in COBIT or ITIL.

Language skills

- German : fluent, spoken and written (at least level C1 of the Common European Framework of Reference for Languages, CEFR (https://europass.europa.eu/en/common-european-framework-reference-language-skills)).
English : good command (at least level B2 of the CEFR (https://europass.europa.eu/en/common-european-framework-reference-language-skills)).

What we offer

- A key role in an innovative, internationally oriented environment.

- A workplace in central Vienna, with flexible working hours and the option to work from home.

- Attractive benefits, including additional days of annual leave, paid lunch breaks and staff discounts for employees of the Austrian Academy of Sciences (ÖAW).

The minimum gross annual salary for this position is EUR 70,000 on a full-time basis. For part-time employment, the salary is adjusted in proportion to the agreed working hours. Depending on your qualifications and professional experience, we are prepared to offer a higher, market-based salary.

How to apply

If working carefully and to deadline comes naturally to you, if you take the initiative your tasks require and represent your unit professionally and constructively, we look forward to receiving your application. Please send us your curriculum vitae, a cover letter and your references by 9 October 2026 .

Contact

Akademie-Rechenzentrum | [email protected]
Zentrale Verwaltung | 1010 Vienna, Austria
Österreichische Akademie der Wissenschaften | Austrian Academy of Sciences | https://www.oeaw.ac.at/