You will be part of the team responsible for establishing and managing holistic frameworks for compliance, risk management and certification governance of SAP Datacenters, both own and co-locations, with tasks like:
- Develop and implement a compliance framework to ensure datacenter operations adhere to German regulatory requirements such as BSI-Grundschutz, IT-Sicherheitsgesetz (IT-SiG), KRITIS, and other applicable local laws
- Lead efforts to achieve and maintain key datacenter-related certifications, including BSI C5, ISO 27001, EN 50600, ISO 27001, NIST CSF, PCI DSS, SOC 1, SOC 2, C5 and KRITIS, certifications.
- Depends on the need, act as the primary contact for regulatory bodies such as BSI (Federal Office for Information Security), TÜV, and other compliance authorities for datacenter-related requirements
- Ensure datacenters meet mandated security standards for physical infrastructure, personnel access control, and visitor management as required by German regulators
- Identify and mitigate compliance risks related to datacenter operations, ensuring adherence to government security frameworks and industry best practices
- Define internal policies and provide training to datacenter teams to ensure compliance awareness and operational alignment with German regulatory expectations
- Datacenter facilities and service providers comply with contractual obligations and regulatory requirements for operating cloud infrastructure
- Support or drive on on-going projects and programs
What you bring
- Master’s/bachelor’s degree in computer science, or similar with focus on information security and cloud compliance or a computer degree and related work experience in information security and cloud compliance
- 10+ years working experience with DC infrastructure, its certification and compliance
- Experience creating processes including workflows design, work descriptions and documentation
- Experience in establishing a compliance management system and compliance frameworks
- Experience with mentoring individuals on compliance, DC infrastructure, and DC operational issues
- Knowledge about information security, compliance standards ISO 27001, NIST CSF, PCI DSS, SOC 1, SOC 2, C5, KRITIS
- Experience in project management is an advantage
- Experience in auditing is an advantage
- Proficiency in English and German
- Experience working in a global and dynamic environment
Job Segment:Cloud, ERP, Data Center, Information Security, Compliance, Technology, Legal