System Security Manager | SSCC [System Security Competence Centre]
- Maintain, improve, and enforce existing system security standards and requirements for all Frequentis products, projects, and services.
- Develop, maintain and distribute new system security requirements to ensure ongoing compliance with ISO/IEC 27001, NIS2, CIS Controls/Benchmarks, and industry best practices.
- Monitor relevant changes in international system security standards, legislation, and accreditations, ensuring Frequentis remains compliant.
- Ensure that non-conformities are tracked, documented, and improvements are addressed or residual risks are accepted.
- Support the certification and continuous improvement of Frequentis AG’s ISMS.
- Provide guidance and enablement to the Project Security Manager in Delivery, Security Champions in Development and collaborate closely with the security agents from the (Strategic) Business Units
- Conduct security risk assessments and evaluate vulnerability scans, reporting and communicating findings clearly to relevant stakeholders.
- Support the definition, implementation, and review of security concepts, risk assessments and technical security deliverables.
- Nice to have: Experience or knowledge of security tools (Static Application Security Testing (SAST) – SonarQube, Coverity, Software Composition Analysis (SCA) – BlackDuck, Dynamic Application Security Testing (DAST) – OWASP ZAP, Burp Suite Pro & Vulnerability Scanning – Nessus Pro)
- Secure Software Development Lifecycle (S-SDLC) Processes and principles e.g., OWASP SAMM
Security Testing & Assurance
- Coordinate and review penetration testing and vulnerability management activities for products.
- Lead or support security assessments (audits, reviews, tests) to ensure that Frequentis system security processes are applied and followed.
- Design and deliver security training programs and courses for Frequentis employees, fostering a culture of security awareness and best practice.
- Enable teams to integrate security into daily work through targeted enablement, coaching, and practical guidance.
- Organize and facilitate courses on a range of security technologies, standards, and practices, tailored to both technical and non-technical audiences.
- Own the definition and maintenance of the Frequentis System Security Standard, including policies, guidelines, processes, and baseline security requirements.
- Regularly review and update security documentation and templates to reflect evolving threats, technologies, and compliance requirements.
- Proactively identify areas for process optimization and drive improvements across system security processes.
Required Qualifications & Experience
- Education: Degree in Informatics, Computer Science, IT Security, or a related technical field (or equivalent experience).
- Experience: Several years in IT/Information Security with hands‑on DevSecOps/SDLC enablement and product security exposure.
- Standards/Regulation: Practical application of ISO/IEC 27001/2, NIS2; awareness of Cyber Resilience Act (CRA) for product organizations.
- AppSec & SDLC: Working knowledge of OWASP ASVS, OWASP Top 10, OWASP SAMM; experience with ASPM concepts and rollout.
- Tooling: Familiarity with SAST (SonarQube, Coverity), SCA (Black Duck), DAST (OWASP ZAP, Burp Suite Pro, Invicti/Netsparker); vulnerability scanning (e.g., Nessus Pro).
- Ways of Working: Strong communication and stakeholder management; ability to coach teams and drive adoption across global, cross‑functional environments.
- Language & Travel: Fluency in English; additional languages are a plus. Willingness to travel internationally (~20%).
Certifications (Nice to Have)
- CISSP, CSSLP, ISO 27001 (Lead Implementer/Auditor), CompTIA Security+
Mindset & Competencies
- Proactive, self‑driven, and outcome‑oriented with high personal initiative.
- Analytical and pragmatic—able to solve complex security problems and facilitate risk‑based decisions.
- Team player with a coaching mindset and a passion for continuous improvement.
We offer a range of benefits focused on work-life balance, professional development and flexibility.
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | |
PRIVATE MEDICAL | SPORT | LUNCH | EXTRA | EXTRA | PUBLIC TRANSPORT | CERTIFICATIONS | TRAININGS | UNEQUAL | WORK | PRIVATE | |
INSURANCE | PACKAGE | TICKETS | VACATION DAYS | WINTER HOLIDAY | SUBSCRIPTION | WORKING HOURS | FROM HOME | PENSION |
We offer a range of benefits focused on work-life balance, professional development and flexibility.
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | |
PRIVATE MEDICAL | SPORT | LUNCH | EXTRA | EXTRA | PUBLIC TRANSPORT | CERTIFICATIONS | TRAININGS | UNEQUAL | WORK | PRIVATE | |
INSURANCE | PACKAGE | TICKETS | VACATION DAYS | WINTER HOLIDAY | SUBSCRIPTION | WORKING HOURS | FROM HOME | PENSION |

Sonia-Oana Campean-Diaconescu
Human Resources | sonia.diaconescu@frequentis.com | Social media contact