Enterprise Security Risk Manager | Data Engineer
WIENER STADTWERKE GmbH
Job Summary
In this role, you will lead the enterprise-wide planning, management, and development of Enterprise Security Risk Management (ESRM) as a central security service. You will take end-to-end responsibility for ESRM methodologies, processes, standards, and KPIs, ensuring they align with corporate goals. A key focus is the functional ownership of the GRC system CRISAM, where you will manage operations, customization, and data quality. You will act as a strategic advisor to management, preparing risk reports and decision-making documents while ensuring compliance with regulatory requirements such as ISO standards and the NIS 2 directive. This position is ideal for a professional with deep expertise in security risk management who wants to contribute to the resilience of a large, complex organization. You will work in a collaborative environment that values diversity and provides state-of-the-art infrastructure for your daily tasks.
Required Skills
Education
University degree in Computer Science, Information Security, Business Informatics, Risk Management, or a comparable field.
Experience
- Professional experience in security or enterprise risk management.
- Practical experience in developing and advancing security risk management strategies and frameworks within complex corporate environments.
- Proven experience in utilizing and developing GRC tools, specifically CRISAM.
- Experience in applying relevant international standards and regulatory requirements.
Languages
Additional
- Must be able to work in a regulated environment. No specific work permit or security clearance mentioned, but eligibility to work in the location is implied.
More Jobs from WIENER STADTWERKE GmbH
Security Auditor | Data Engineer
May 7, 2026
As a Security Auditor, you will play a pivotal role in ensuring the integrity and compliance of orga...
Security Incident Response Manager | Data Engineer
Mar 16, 2026
As a Security Incident Response Manager, you will lead and develop the Security Incident Management ...