ISMS Operations and Risk Manager | ISMS-Betrieb und Risikomanager*in (m/w/d)

Uniklinikum Freiburg

Freiburg im Breisgau, Baden-Württemberg, Deutschland
Published Feb 26, 2026
Full-time
Permanent

Job Summary

This role is central to the University Medical Center Freiburg's mission of securing critical IT infrastructure within a high-stakes medical environment. As an ISMS Operations and Risk Manager, you will be responsible for the day-to-day management of the Information Security Management System, with a specific focus on risk assessment and tracking security measures. You will act as a key consultant for department heads and employees on IT security matters, evaluate security protocols for new IT projects, and maintain the organization's ISMS software tools. A significant portion of the role involves preparing interdisciplinary decision-making materials for the hospital board and coordinating both internal and external audits. This position is particularly attractive for professionals looking to work in a 'KRITIS' (Critical Infrastructure) environment where IT security directly impacts patient care. The role offers a modern technical infrastructure, flexible family-friendly working hours, and extensive professional development opportunities within a dedicated team.

Required Skills

Education

Completed vocational training in the IT field or equivalent professional qualification and expertise.

Experience

  • Professional experience in the development and operation of Information Security Management Systems (ISMS)
  • Experience in communication, documentation, and the implementation of organizational security measures
  • Proven expertise in risk management processes and tracking security measures
  • Practical experience in coordinating and organizing interdisciplinary projects or committees
  • Experience in evaluating IT projects for security compliance and architectural integrity

Languages

German (Fluent)

Additional

  • The position is located in Freiburg, Germany. Applicants must be able to support organizational responses to security incidents and participate in committee work for the hospital board.