Working at impunix AG
Are you looking for a job in information security or data protection? Then apply now and help make organisations in Switzerland more secure.Focus on schools, local communities and healthcare
Place of work: Based in Winterthur, with flexible assignments visiting clients across German-speaking Switzerland
Start: with immediate effect or by agreement | Contract: permanent
Contact: impunix AG, Micha Strässler
Would you like to provide practical support to organisations in effectively protecting their information, systems and personal data? Do you work in a structured way, take responsibility and have the ability to explain complex issues in a way that makes sense in everyday life?
As a Chief Information Security Officer (CISO), you will support our clients in establishing, operating and further developing their information security. You will work alongside senior management, school boards, local authorities, IT managers, external IT service providers and data protection officers.
You have several years’ experience in information security or a related field. You are already familiar with the education, local government or healthcare sectors, or you are willing to learn the ropes in a targeted manner.
Your responsibilities
You will manage several accounts simultaneously and will regularly visit clients on site. This includes:
- Establishment, operation and further development of information security management systems in accordance with ISO/IEC 27001, BSI Grundschutz, NIST CSF or comparable standards
- Carrying out security needs analyses, risk analyses, gap assessments and maturity assessments
- Coordination of penetration tests and technical security audits in collaboration with ethical hackers
- Drawing up and reviewing security policies, guidelines, role and authorisation frameworks, and ISDS documentation
- Assessment of ICT environments in collaboration with internal and external IT operators
- Advice for staff, managers, school boards, local councils and executive boards
- Reporting on the current state of information security, as well as necessary measures and decisions
- Support in the event of information security incidents and vulnerability reports
- Planning and implementation of awareness-raising measures and training courses
- Supporting projects to ensure that safety-related aspects are taken into account at an early stage
What you’ll need
Personal
You communicate directly and clearly, even when issues are still unresolved. You recognise for yourself where action is needed and don’t wait for every task to be assigned to you. You are curious about new topics and organisations, keep your promises and treat people as equals.
Technical
- Several years’ experience in information security, IT governance, IT risk management, data protection or IT operations
- Knowledge of standards such as ISO/IEC 27001, BSI Basic Protection, NIST CSF or CIS Controls
- An understanding of ICT infrastructures, cloud services, Microsoft 365, identity and access management, and networks
- Excellent written and spoken German
- An advantage: experience in the public sector or in healthcare
- An advantage: certifications such as ISO 27001 Lead Implementer, CISSP, CISM or CISA
- An interest in or experience of ethical hacking, penetration testing and vulnerability analysis using tools such as Kali Linux, OpenVAS/Greenbone, Nmap, Burp Suite, Metasploit or similar tools would be an advantage
How we work
We take responsibility. We ask for clarification when we don’t understand something. And we treat people as equals, whether we’re speaking to a school board, an IT manager or staff members without a technical background.
Trust is built not only on expertise, but also on reliability, clarity and respectful collaboration.
About us
Impunix supports more than 100 organisations in the areas of data protection, information security and legal affairs. Our ISV clients are primarily from the public sector, including schools, local authorities, social institutions and the healthcare sector. We help them to identify risks, implement measures and raise staff awareness.
Here’s what we offer you
- Meaningful mandates with an impact on education, administration and healthcare
- Varied assignments offering plenty of scope for creativity and direct contact with decision-makers
- An interdisciplinary team with expertise in data protection, information security and law
- Flexible working arrangements and modern tools
- Support for further training and certification
- Flat hierarchies, a high degree of personal responsibility and an open team culture
Interested?
We look forward to receiving your application, including your CV and a short statement explaining what appeals to you about the role, what drives you, and why you would like to help shape information security in schools, local authorities and healthcare organisations. You can send us your application via this Link send.
Workload 60-80% on an hourly wage basis
Place of work: Based in Winterthur, with flexible assignments visiting clients across German-speaking Switzerland
Start: with immediate effect or by agreement | Contract: permanent
Contact: impunix AG, Micha Strässler
You can submit your application via the following Form Submit your application. We look forward to hearing from you!
Would you like to provide practical support to organisations in effectively protecting their information, systems and personal data? Do you work in a structured way, take responsibility and have the ability to explain complex issues in a way that makes sense in everyday life?
As a Junior Information Security Officer (ISV) – equivalent to a CISO – you will support our experienced ISVs and assist our clients in establishing, operating and further developing their information security. You will work alongside senior management, school boards, local authorities, IT managers, external IT service providers and data protection officers.
You have an interest in or experience of information security, IT or a related field. You are already familiar with the education, local government or healthcare sectors, or you are willing to learn the ropes in a targeted manner.
Your responsibilities
You will support our ISVs in managing their clients. This includes:
- Establishment, operation and further development of information security management systems in accordance with ISO/IEC 27001, BSI Grundschutz, NIST CSF or comparable standards
- Carrying out security needs analyses, risk analyses, gap assessments and maturity assessments
- Coordination of penetration tests and technical security audits in collaboration with ethical hackers
- Drawing up and reviewing security policies, guidelines, role and authorisation frameworks, and ISDS documentation
- Assessment of ICT environments in collaboration with internal and external IT operators
- Advice for staff, managers, school boards, local councils and executive boards
- Reporting on the current state of information security, as well as necessary measures and decisions
- Support in the event of information security incidents and vulnerability reports
- Planning and implementation of awareness-raising measures and training courses
- Supporting projects to ensure that safety-related aspects are taken into account at an early stage
What you’ll need
Personal
You communicate directly and clearly, even when issues are still unresolved. You recognise for yourself where action is needed and don’t wait for every task to be assigned to you. You are curious about new topics and organisations, keep your promises and treat people as equals.
Technical
- An interest in or experience of information security, IT governance, IT risk management, data protection or IT operations
- Willingness to undertake further training in standards such as ISO/IEC 27001, BSI Basic Protection, NIST CSF or CIS Controls
- An understanding of ICT infrastructures, cloud services, Microsoft 365, identity and access management, and networks
- Excellent written and spoken German
- An advantage: experience in the public sector or in healthcare
- An advantage: an openness to certifications such as ISO 27001 Lead Implementer, CISSP, CISM or CISA
- An interest in or experience of ethical hacking, penetration testing and vulnerability analysis using tools such as Kali Linux, OpenVAS/Greenbone, Nmap, Burp Suite, Metasploit or similar tools would be an advantage
How we work
We take responsibility. We ask for clarification when we don’t understand something. And we treat people as equals, whether we’re speaking to a school board, an IT manager or staff members without a technical background.
Trust is built not only on expertise, but also on reliability, clarity and respectful collaboration.
About us
Impunix supports more than 100 organisations in the areas of data protection, information security and legal affairs. Our ISV clients are primarily from the public sector, including schools, local authorities, social institutions and the healthcare sector. We help them to identify risks, implement measures and raise staff awareness.
Here’s what we offer you
- Meaningful mandates with an impact on education, administration and healthcare
- Varied assignments offering plenty of scope for creativity and direct contact with decision-makers
- An interdisciplinary team with expertise in data protection, information security and law
- Flexible working arrangements and modern tools
- Support for further training and certification
- Flat hierarchies, a high degree of personal responsibility and an open team culture
Interested?
We look forward to receiving your application via the form linked above.