Job matched to your search
Information Security Officer – GRC & Security (m/f/d)
Txt Group · BE, DE
Free · Join 5,000+ job seekers using Qarera
How well do you match this role?
Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.
Job description
PACE Aerospace & Information Technology GmbH, as a part of the TXT e-Solutions Group, is an internationally renowned software company that specializes in the development of innovative solutions for the aviation industry. Our customers include many of the world's largest aircraft manufacturers and airlines.
Since its inception in 1995, PACE has been creating and developing software for airplane design & configuration, route network analysis, virtual training, and fuel efficiency improvements. PACE has an extensive network within the international academia community and partners in multiple national and European research projects. The company is based in Berlin, Germany, with subsidiaries in the USA, Canada and Singapore. As part of the stock-listed Milan-based TXT e-Solutions group, PACE is benefiting from an ecosystem of digital innovators in multiple industrial sectors.
Information Security Officer – GRC & Security (m/f/d):
Information Security Officer – GRC & Security
Location: Berlin (hybrid) • Team: IT • Reports to: Head of IT
Type: Full-time • Seniority: Mid–Senior (Individual Contributor with full ownership)
Salary: 75k - 90k EUR/y
About PACE
PACE Aerospace Engineering and Information Technology GmbH, part of the TXT e-Solutions Group, is a globally recognized software company specializing in innovative solutions for the aviation industry.
Since 1995, we have been developing software for aircraft design, configuration, route analysis, virtual training, and fuel efficiency. With locations in Berlin, the USA, Canada, and Singapore, we collaborate closely with leading aircraft manufacturers, airlines, and research partners.
Why this role exists
We are strengthening our information security function and are looking for a hands-on Information Security Officer to take ownership of security governance, risk and compliance at PACE.
This is primarily a GRC and security governance role, with enough hands-on involvement to ensure that risks, vulnerabilities and security alerts are actually followed through.
You will build and operate our ISMS, strengthen our ISO 27001 setup, coordinate CMMC Level 2 and NIST SP 800-171 readiness, establish core security processes, and provide practical security oversight across IT, cloud and software development.
What you’ll own
Information Security Management System (ISMS)
Build and operate a practical ISO 27001-aligned ISMS covering policies, controls, risk management, audits and continuous improvement.
ISO 27001
Support PACE's participation in the current TXT Group ISO 27001 certification
CMMC Level 2 & NIST SP 800-171
Act as the internal owner for CMMC Level 2 readiness and the C3PAO assessment, supported by external specialists where needed.
Core security processes
Establish and improve risk management, incident response, business continuity, supplier security, vulnerability management and security awareness.
Security operations
Improve how security alerts, vulnerabilities and incidents are reviewed, prioritized and followed through to remediation.
Cloud & software security governance
Establish pragmatic security governance for AWS, Azure and software development, including access management, CI/CD, vulnerabilities, software supply chain and use of AI.
Security coordination & reporting
Work across IT, engineering, business teams, TXT Group and external partners to clarify responsibilities, drive remediation and make security risks visible to management.
Business & customer security support
Support customer security questionnaires, RFPs, audits and due-diligence requests by coordinating accurate, consistent responses and providing evidence of PACE's security controls.
Must-have qualifications
5+ years of experience in information security, GRC, security management or a similar role.
Practical experience with ISO 27001 and operating an ISMS.
Experience with security risk management, policies, controls and audits.
Good understanding of incident management, vulnerability management and business continuity.
Enough technical depth to work effectively with IT, cloud and software engineering teams.
Familiarity with Microsoft 365, Azure, AWS, endpoint security and identity management.
Ability to turn security and compliance requirements into pragmatic, workable processes.
Strong English communication and documentation skills.
Comfortable working independently and driving topics across multiple teams.
Nice to have
Experience with CMMC or NIST SP 800-171.
ISO 27001 Lead Implementer / Lead Auditor, CISM, CISSP or similar certification.
AWS or Azure security experience.
Secure software development / DevSecOps knowledge.
Experience with Microsoft security tooling, Intune or endpoint security.
Aerospace, defence or other regulated-industry experience.
German language skills.
What success looks like
PACE has a practical, functioning ISMS with clear ownership and continuous improvement.
PACE is ready for its CMMC Level 2 assessment, with NIST SP 800-171 requirements systematically implemented and evidenced.
Core security processes such as risk, incident, vulnerability and business continuity management are established and actively used.
Security risks across corporate IT, cloud environments and software development are visible, prioritized and acted upon.
Security responsibilities between PACE, TXT Group and individual business teams are clearly understood.
Management has a clear view of the most important information security risks, priorities and improvement activities.
How we work & where
Hybrid: 2 days/week remote; 3 days/week on-site.
Office: Modern office near Uber Arena in Berlin.
Small team, high ownership and direct access to decision-makers.
We use external specialists where deep expertise is needed; you own PACE's information security governance and coordinate security activities across the business.
We value practical security over compliance theater.
#pace
More jobs in BE, DE
Browse related jobs
Don’t just read the job — see if you’ll get it.
Get your match score, a resume tailored to this exact role, and jobs like it — free.
Check my fit for this job