Information Security Officer – GRC & Security (m/f/d) - #2678915

PACE Aerospace & IT


Date: vor 1 Stunde
Stadt: Berlin
Gehalt: €75 - €90 / Jahr
Vertragstyp: Ganztags
Arbeitsplan: Volle Tag
PACE Aerospace & IT
Information Security Officer – GRC & Security

Location: Berlin (hybrid)

  • Team: IT
  • Reports to: Head of IT


Type: Full-time

  • Seniority: Mid–Senior (Individual Contributor with full ownership)


Salary: 75k - 90k EUR/y

About PACE

PACE Aerospace Engineering and Information Technology GmbH, part of the TXT e-Solutions Group, is a globally recognized software company specializing in innovative solutions for the aviation industry.

Since 1995, we have been developing software for aircraft design, configuration, route analysis, virtual training, and fuel efficiency. With locations in Berlin, the USA, Canada, and Singapore, we collaborate closely with leading aircraft manufacturers, airlines, and research partners.

Why this role exists

We are strengthening our information security function and are looking for a hands-on Information Security Officer to take ownership of security governance, risk and compliance at PACE.

This is primarily a GRC and security governance role, with enough hands-on involvement to ensure that risks, vulnerabilities and security alerts are actually followed through.

You will build and operate our ISMS, strengthen our ISO 27001 setup, coordinate CMMC Level 2 and NIST SP 800-171 readiness, establish core security processes, and provide practical security oversight across IT, cloud and software development.

What You’ll Own

  • Information Security Management System (ISMS)


Build and operate a practical ISO 27001-aligned ISMS covering policies, controls, risk management, audits and continuous improvement.

  • ISO 27001


Support PACE's participation in the current TXT Group ISO 27001 certification

  • CMMC Level 2 & NIST SP 800-171


Act as the internal owner for CMMC Level 2 readiness and the C3PAO assessment, supported by external specialists where needed.

  • Core security processes


Establish and improve risk management, incident response, business continuity, supplier security, vulnerability management and security awareness.

  • Security operations


Improve how security alerts, vulnerabilities and incidents are reviewed, prioritized and followed through to remediation.

  • Cloud & software security governance


Establish pragmatic security governance for AWS, Azure and software development, including access management, CI/CD, vulnerabilities, software supply chain and use of AI.

  • Security coordination & reporting


Work across IT, engineering, business teams, TXT Group and external partners to clarify responsibilities, drive remediation and make security risks visible to management.

  • Business & customer security support


Support customer security questionnaires, RFPs, audits and due-diligence requests by coordinating accurate, consistent responses and providing evidence of PACE's security controls.

Must-have Qualifications

  • 5+ years of experience in information security, GRC, security management or a similar role.
  • Practical experience with ISO 27001 and operating an ISMS.
  • Experience with security risk management, policies, controls and audits.
  • Good understanding of incident management, vulnerability management and business continuity.
  • Enough technical depth to work effectively with IT, cloud and software engineering teams.
  • Familiarity with Microsoft 365, Azure, AWS, endpoint security and identity management.
  • Ability to turn security and compliance requirements into pragmatic, workable processes.
  • Strong English communication and documentation skills.
  • Comfortable working independently and driving topics across multiple teams.


Nice to have

  • Experience with CMMC or NIST SP 800-171.
  • ISO 27001 Lead Implementer / Lead Auditor, CISM, CISSP or similar certification.
  • AWS or Azure security experience.
  • Secure software development / DevSecOps knowledge.
  • Experience with Microsoft security tooling, Intune or endpoint security.
  • Aerospace, defence or other regulated-industry experience.
  • German language skills.


What Success Looks Like

  • PACE has a practical, functioning ISMS with clear ownership and continuous improvement.
  • PACE is ready for its CMMC Level 2 assessment, with NIST SP 800-171 requirements systematically implemented and evidenced.
  • Core security processes such as risk, incident, vulnerability and business continuity management are established and actively used.
  • Security risks across corporate IT, cloud environments and software development are visible, prioritized and acted upon.
  • Security responsibilities between PACE, TXT Group and individual business teams are clearly understood.
  • Management has a clear view of the most important information security risks, priorities and improvement activities.


How We Work & Where

  • Hybrid: 2 days/week remote; 3 days/week on-site.
  • Office: Modern office near Uber Arena in Berlin.
  • Small team, high ownership and direct access to decision-makers.
  • We use external specialists where deep expertise is needed; you own PACE's information security governance and coordinate security activities across the business.
  • We value practical security over compliance theater.


#pace

Wie bewerbe ich mich?

Um sich für diesen Job zu bewerben, müssen Sie auf unserer Website autorisieren. Wenn Sie noch kein Konto haben, registrieren Sie sich bitte.

Veröffentlichen Sie einen Lebenslauf

Ähnliche Jobs

Senior Associate - Internal Communications, Operations (all genders)

JPMorganChase,
vor 1 Stunde
Job Description As we're launching Chase bank in Germany, we're looking for a Senior Associate, Internal Communications to support our Operations business in Berlin as we scale-up. You'll be responsible for keeping our customer-facing colleagues and support teams informed and...
JPMorganChase

Test Manager Communication Management (m/w/d)

citema systems GmbH,
vor 1 Stunde
Driving Digital Technologies. Den digitalen Wandel begleiten und aktiv mitgestalten – unsere Mission bei citema. Mit unseren innovativen Ansätzen beraten und unterstützen wir unsere Kunden in den Technologiefeldern Cyber Security, KI und Blockchain. Ebenso gehört die Umsetzung system- und sicherheitsrelevanter...
citema systems GmbH

DevOps Engineer

Thales,
vor 2 Stunden
Location: Berlin, Germany We Say HI* DevOps Engineer (w/m/d) Thales ist ein weltweit führender Anbieter von Spitzentechnologien für die Bereiche Verteidigung, Luft- und Raumfahrt sowie Cyber Security und Digital Identity. Deutsche Unternehmen und die öffentlichen Verwaltungen hierzulande sind bereit, ihre...
Thales