Verlag C.H.BECK | Germany | 81xxx, 80xxx München | Temporary contract | Full time / Home office | Published since: 21.01.2026 on stepstone.de
IT-Security & Compliance Engineer (m/f/d)
2 years Munich with professional experience The C.H.BECK media group has been a traditional family company for reliability, innovation and highest quality for over 250 years. It is characterized by a broad portfolio ranging from legal and intellectual publications to modern online databases to digital platforms and AI-based solutions for the legal world of the future. The company combines centuries-old expertise with state-of-the-art technology to offer innovative and high-quality solutions. .
* After clicking the Read more button, the original advert will open on our partner's website, where you can see the details of this vacancy and contact information. If you need a translation of this text, after returning to our website it will be prepared and you can read it by clicking the Show full translation button.
Your tasks • Your profile • What we offer
The body is limited to two years and includes the following tasks: Construction, operation and further development of a Group-wide ISMS according to ISO/IEC 27001:2022 and ISO/IEC 42001 Introduction and further development of structured and partially automated compliance processes, e.g. for proofs, controls and audit preparation Integration of regulatory requirements (DORA, EU AI Act, NIS2, GDPR) into existing compliance structures Preparation, coordination and monitoring of internal and external audits, with a focus on automation and lower detection effort Maintaining the risk and asset register and implementing standardised risk assessments in the IT, AI and project context Implementation of AI governance in accordance with ISO/IEC 42001 and the establishment of AI risk management across the entire life cycle. Implementation of EU AI Act requirements for high-risk AI systems Implementation of requirements for IT risk management, business continuity, disaster recovery and incident management as part of legal requirements Development, harmonisation and care of group-wide safety guidelines Close cooperation with IT, law, data protection, purchasing, sales and external auditors and preparation of regular management reports
Complete degree in economic law, IT law, law & compliance or comparable qualification Insufficient professional experience in IT law, data protection, compliance, regulatory or interface roles between law and IT Knowledge of relevant standards and regulators, in particular: ISO/IEC 27001, ISO/IEC 42001, GDPR, EU AI Act, DORA, NIS2 Detectable further education in the field of information security, ideally as ISO/IEC 27001 Practitioner, Lead Implementer or Lead Auditor Experience in the analysis of regulatory requirements, compilation of compliance documentation as well as supervision of internal and external audits Impressed communication strength and safe occurrence to auditors, departments and management Structured, independent and solution-oriented mode of operation with high analytical capability Very good knowledge of German and English Advantage: Experience with GRC/TPRM tools (e.g. OneTrust, Vanta, Drata) as well as interest in automation and RegTech approaches
Working environment: leading media company in the heart of Schwabing Development: Individual offers for professional and personal development Health: Sports and Health Care - Cooperation with EGYM Work-Life-Balance: Working time options through 37.5 hours/week full time in sliding time and home office Social Events: After-Work-Beer, Internal House Fair for employees, Summer and Winter Festival Goodies: fare and lunch grant, parking with e-load infrastructure, book discount & much more! !
Location
![]() | Verlag C.H.BECK | |
| 80801 München | ||
| Germany |
The text of this ad was translated from German into English using an automatic translation system and may contain semantic and lexical errors. Therefore, it should be used for introductory purposes only. For more detailed information, see the original text of the ad at the link below.
For more information read the original ad