bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesOnventisIT Compliance & Information Security Manager (m/f/d)

IT Compliance & Information Security Manager (m/f/d)

Onventis · Stuttgart, GER · Hybrid · Active · Personio

Job facts

FieldValue
CompanyOnventis
TitleIT Compliance & Information Security Manager (m/f/d)
Normalized title-
Department / teamInformation Security / IT
LocationStuttgart, GER
Work modelHybrid / Hybrid
Employment typeFull Time
Salary-
Statusactive
ATS providerPersonio
Posted / first seen2026-05-13 / 2026-05-30
Changed / last seen2026-05-30 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Onventis.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Personio.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Department jobsActive postings in Information Security.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyOnventis
Sourcece41e279-7065-4c3a-8049-1892cec9c972
ATS providerPersonio

Description

Let’s Start with our Story Every great career begins somewhere, and this one starts here. We are a team that believes in big ideas, bold moves and the people behind them. This is where you could be part of something exciting! Onventis is the European Source-to-Pay Intelligence. For more than 25 years, Onventis has supported mid-sized enterprises at six locations in making their procurement and finance processes more sovereign. Through its modular SaaS product portfolio, Onventis connects an end-to-end source-to-pay process with a European operating model in a protected data environment. Today, around 1.2 million users from over 1,000 companies with 4.5 million suppliers process an annual transaction volume of 40 billion euros via the Onventis Network. Why This Role Matters As   IT Compliance & Information Security Manager, you play a key role in ensuring trust, compliance, and operational resilience across our organization. You will ensure that the company systematically meets its internal and external requirements for information security, IT compliance, and regulatory resilience. In doing so, you will further develop the ISMS, coordinate documentation and audits, and translate requirements from ISO 27001, NIS2, DORA, SOC/audit requirements such as ISAE 3402, and relevant AI governance guidelines into practical processes for a modern SaaS business model. Your Role at a Glance As our  IT Compliance & Information Security Manager (m/f/ d), you will be responsible for managing and continuously developing our Information Security Management System (ISMS) and extending it into an integrated management framework that meets regulatory, legal, and customer requirements. You will: Operate and further develop the Information Security Management System (ISMS) based on ISO/IEC 27001 and ensure robust policies, standards, controls, and evidence. Analyze new regulatory requirements and translate them into concrete measures, roadmaps, and internal control mechanisms, particularly in the context of NIS2, DORA, data protection, IT governance, and AI-related requirements. Coordinate internal and external audits, certifications, and customer reviews, prepare supporting documentation, and serve as the primary point of contact for auditors, customers, business units, and management. Conduct risk analyses, assess control gaps, and track measures through to sustainable implementation in collaboration with Engineering, Cloud Operations, Legal, Data Protection, and Product teams. Maintain and improve the IT-related internal control system, including documentation, effectiveness checks, exception handling, and management reporting. Evaluate service providers, cloud providers, and security-related solutions with regard to compliance, risk, and security requirements throughout their entire lifecycle. Plan and coordinate awareness, training, and communication initiatives to ensure that regulatory and security-related requirements are effectively embedded within the company. Support the structured classification of AI use cases and AI systems within the company and ensure that usage, documentation , control, and monitoring obligations under the EU AI Act are appropriately addressed. Your Experience and Skills We are looking for someone who brings: Several years of professional experience in information security, IT compliance, IT risk management, IT audit, or GRC in a technology-driven environment. Practical experience with ISMS according to ISO/IEC 27001, as well as a good understanding of regulatory requirements such as DORA, NIS2, GDPR, and comparable frameworks. Experience in preparing for and supporting internal and external audits and reviews. Ability to translate regulatory requirements into pragmatic processes, controls, and product/operational measures for a SaaS model. Strong communication skills in German and English to collaborate effectively with Engineering, IT, Legal, Data Protection, Customer Success, Sales, and Management. A structured, well-documented, and implementation-oriented approach to work with a high degree of personal responsibility. Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or comparable qualifications are desirable. Our Commitment to You Our CORE values bring our varied cultural background and products together and more importantly, ensure how we invest in our people. At Onventis, you can expect a performance focused culture where your achievements are recognized, your goals are prioritized and your career accelerates. We offer more than just a job and we show it with real benefits: Flexibility : Hybrid work model with modern tools and equipment Mobility : Free parking, Job Ticket, JobRad leasing Health & Wellbeing : Urban Sports membership, fresh fruit, drinks, and meal subsidies Career Growth : Structured onboarding, training programs, language courses Culture: Friendly team spirit, clear structures, regular team events & gatherings

Full job record

Job IDfacbd9d38c66bf80ab9f9327064996d9c50a11fc
Org IDe2a6a48c-0aaf-43b6-bdb1-60fee52319ec
Source IDce41e279-7065-4c3a-8049-1892cec9c972
Board IDce41e279-7065-4c3a-8049-1892cec9c972
Providerpersonio
Provider Job Key2633592
TitleIT Compliance & Information Security Manager (m/f/d)
Normalized Title
Statusactive
Activeyes
Location TextStuttgart, GER
DepartmentInformation Security
TeamIT
Employment Typefull_time
Workplace Typehybrid
Remote Policyhybrid
Country
Region
City
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://onventis.jobs.personio.de/job/2633592?language=en
Apply URLhttps://onventis.jobs.personio.de/job/2633592?language=en
First Seen At2026-05-30 06:06:12Z
Last Seen At2026-06-06 07:58:11Z
Last Checked At2026-06-06 07:58:11Z
Last Changed At2026-05-30 06:06:12Z
Inactive At
Source Posted At2026-05-13 13:49:53Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=personio/board=onventis.de/date=2026-06-06/2026-06-06T07-58-11-210Z-7204d7e71dc489ad0812490c755ab423c70b5ee637162ede344f6c154461ba2c.json
Event Fields
{
  "content_hash": "a1ea0909d0fa37b76b25c828ca1a087bc7f999a71af0ef614b46b64ee58f7d0e",
  "source_hash": "eef810c3e024755834164fbe6b64ba89f2cccd866d55ec7c9e0e27ca1266d469",
  "last_changed_at": "2026-05-30T06:06:12.594Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Stuttgart, GER",
    "city": null,
    "region": null,
    "country": null,
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T07:58:11.758Z",
  "launch_scope": {
    "reason": "personio_production_catalog",
    "included": true,
    "location": {
      "raw": "Stuttgart, GER",
      "city": null,
      "region": null,
      "country": null,
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": []
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "2633592",
  "name": "IT Compliance & Information Security Manager (m/f/d)",
  "office": "Stuttgart, GER",
  "keywords": [],
  "schedule": "full-time",
  "createdAt": "2026-05-13T13:49:53+00:00",
  "seniority": "experienced",
  "department": "Information Security",
  "occupation": "systems_analysis__it",
  "subcompany": "Onventis Holding GmbH",
  "employmentType": "permanent",
  "jobDescriptions": [
    {
      "name": "Let’s Start with our Story",
      "value": "Every great career begins somewhere, and this one starts here. We are a team that believes in big ideas, bold moves and the people behind them. This is where you could be part of something exciting! <br><br>Onventis is the European Source-to-Pay Intelligence. For more than 25 years, Onventis has supported mid-sized enterprises at six locations in making their procurement and finance processes more sovereign. Through its modular SaaS product portfolio, Onventis connects an end-to-end source-to-pay process with a European operating model in a protected data environment. Today, around 1.2 million users from over 1,000 companies with 4.5 million suppliers process an annual transaction volume of 40 billion euros via the Onventis Network."
    },
    {
      "name": "Why This Role Matters",
      "value": "As<strong> </strong>IT Compliance & Information Security Manager, you play a key role in ensuring trust, compliance, and operational resilience across our organization.<br><br>You will ensure that the company systematically meets its internal and external requirements for information security, IT compliance, and regulatory resilience. In doing so, you will further develop the ISMS, coordinate documentation and audits, and translate requirements from ISO 27001, NIS2, DORA, SOC/audit requirements such as ISAE 3402, and relevant AI governance guidelines into practical processes for a modern SaaS business model."
    },
    {
      "name": "Your Role at a Glance",
      "value": "As our<strong> IT Compliance & Information Security Manager (m/f/</strong>d), you will be responsible for managing and continuously developing our Information Security Management System (ISMS) and extending it into an integrated management framework that meets regulatory, legal, and customer requirements.<br><br>You will:<br><ul><li>Operate and further develop the Information Security Management System (ISMS) based on ISO/IEC 27001 and ensure robust policies, standards, controls, and evidence.</li><li>Analyze new regulatory requirements and translate them into concrete measures, roadmaps, and internal control mechanisms, particularly in the context of NIS2, DORA, data protection, IT governance, and AI-related requirements.</li><li>Coordinate internal and external audits, certifications, and customer reviews, prepare supporting documentation, and serve as the primary point of contact for auditors, customers, business units, and management.</li><li>Conduct risk analyses, assess control gaps, and track measures through to sustainable implementation in collaboration with Engineering, Cloud Operations, Legal, Data Protection, and Product teams.</li><li>Maintain and improve the IT-related internal control system, including documentation, effectiveness checks, exception handling, and management reporting.</li><li>Evaluate service providers, cloud providers, and security-related solutions with regard to compliance, risk, and security requirements throughout their entire lifecycle.</li><li>Plan and coordinate awareness, training, and communication initiatives to ensure that regulatory and security-related requirements are effectively embedded within the company.</li><li>Support the structured classification of AI use cases and AI systems within the company and ensure that usage, documentation , control, and monitoring obligations under the EU AI Act are appropriately addressed.</li></ul>"
    },
    {
      "name": "Your Experience and Skills",
      "value": "We are looking for someone who brings:<br><br><ul><li>Several years of professional experience in information security, IT compliance, IT risk management, IT audit, or GRC in a technology-driven environment.</li><li>Practical experience with ISMS according to ISO/IEC 27001, as well as a good understanding of regulatory requirements such as DORA, NIS2, GDPR, and comparable frameworks.</li><li>Experience in preparing for and supporting internal and external audits and reviews.</li><li>Ability to translate regulatory requirements into pragmatic processes, controls, and product/operational measures for a SaaS model.</li><li>Strong communication skills in German and English to collaborate effectively with Engineering, IT, Legal, Data Protection, Customer Success, Sales, and Management.</li><li>A structured, well-documented, and implementation-oriented approach to work with a high degree of personal responsibility.</li><li>Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or comparable qualifications are desirable.</li></ul>"
    },
    {
      "name": "Our Commitment to You",
      "value": "Our CORE values bring our varied cultural background and products together and more importantly, ensure how we invest in our people. At Onventis, you can expect a performance focused culture where your achievements are recognized, your goals are prioritized and your career accelerates. <br><br>We offer more than just a job and we show it with real benefits:<br><br><strong>Flexibility</strong>: Hybrid work model with modern tools and equipment <br><strong>Mobility</strong>: Free parking, Job Ticket, JobRad leasing <br><strong>Health & Wellbeing</strong>: Urban Sports membership, fresh fruit, drinks, and meal subsidies <br><strong>Career Growth</strong>: Structured onboarding, training programs, language courses <br><strong>Culture:</strong> Friendly team spirit, clear structures, regular team events & gatherings"
    }
  ],
  "occupationCategory": "it_software",
  "recruitingCategory": "IT"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/facbd9d38c66bf80ab9f9327064996d9c50a11fc?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/e2a6a48c-0aaf-43b6-bdb1-60fee52319ecJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/ce41e279-7065-4c3a-8049-1892cec9c972JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/facbd9d38c66bf80ab9f9327064996d9c50a11fc/eventsJSON