Information Security Manager
Hybrid
Full Time
#Security
#Payments
#Cloud
#Audit Management
#ISO 27001
#PCI DSS
#Project Management
#Risk Assessment
#Compliance Reporting
#Cloud Native
At paymenttools, we are on a mission to transform the European payment landscape. With over 4.4 billion annual visitors across more than 15,000 REWE Group locations and travel agencies in 21 countries, we possess a deep understanding of what both consumers and merchants require for seamless transactions. Our core philosophy, #wesolvepayn, drives us to make payments invisible and reliable by integrating them with value-added services. We combine cutting-edge, cloud-native technology with rigorous security standards to protect sensitive data while fostering constant innovation.
About the Role
We are looking for a Senior Information Security Manager to join our team on a full-time basis. In this hybrid role, you will be the guardian of our security standards, ensuring that our innovative environment remains both agile and secure. You will serve as the essential bridge between our product teams and external auditors, managing our compliance posture and driving continuous improvement across our technical infrastructure.
Key Responsibilities
- Lead and manage the entire audit lifecycle, acting as the primary point of contact between external auditors and our internal product teams.
- Oversee thorough audit preparation, which includes gathering necessary evidence and clearly communicating technical requirements to stakeholders.
- Initiate and drive continuous improvement initiatives based on audit findings, risk assessments, and maturity analyses to keep our security posture ahead of the curve.
Requirements
To succeed in this role, you should bring a strong background in information security and a passion for maintaining high standards. We value the following qualifications:
- Proven experience in information security management, with a specific focus on coordinating and managing complex audits.
- Solid understanding of regulatory frameworks such as ISO 27001, PCI DSS, or KRITIS and EU-NIS directives.
- Strong project management skills, allowing you to lead complex processes effectively.
- Excellent communication skills, enabling you to translate technical security requirements for both internal teams and external auditors.
- Familiarity with security practices within a cloud-native development environment is a significant advantage.
- Professional certifications such as CISSP, CISM, or CEH are highly desirable.
- Fluency in English is required, while German language skills are considered a plus.
Location
This position is based in Germany and operates on a hybrid work model.
Compensation and Benefits
We believe in supporting our team members both professionally and personally. By joining us, you will have access to the following perks:
- Flexible working hours to help you balance your professional and personal life.
- An annual learning and development budget of 1,000 EUR, supplemented by access to internal training platforms.
- Comprehensive paid time off and insurance services.
- A 401k-style retirement provision plan.
- Commuter benefits, including a subsidized Deutschland-Ticket.
- Opportunities to connect with the team through regular company retreats and events.
Paymenttools
3 views
Markets









