Cyber Security Lead (m/f/d)
Lead cyber security across a multi-country e-commerce and production group, from our online shops to our production floors, with senior ownership and a direct line to leadership.
NOW HIRING · FULL-TIME · COLOGNE
Cyber Security Lead
(m/f/d)
Take our cyber security to the next level across a global, AI-first e-commerce and production group.
● Cologne ● Full-time ● Start: asap
Security is already a priority at TCG, and we are investing to take it further. We are looking for a Cyber Security Lead to strengthen and lead our information security across the group: our shops, our production sites, and the platforms that connect them.
About TCG
In 2004, our founders flew to China for the Canton Fair. No plan B, no investors. The Customization Group is now a global leader in mass customization and print-on-demand e-commerce, manufacturing personalised products in Germany, Poland, the USA and Latvia and selling through 20+ own shops and 1,000+ partner stores. 750+ people, 40+ nationalities.
The Role
You lead cyber security across the group, building on the processes and controls already in place and raising the bar further. The scope covers our own online shops, internal platforms, cloud and on-premise infrastructure, and the production sites across several countries. You work closely with IT, development, legal and management as the central point for all things security.
In short: Senior ownership of cyber security for a multi-country group, with a direct line to leadership and a clear mandate to strengthen it further.
What You Will Do
→ Drive the security roadmap. Review our current setup, sharpen priorities, and keep the plan moving with the business.
→ Strengthen detection and response. Further develop our incident response process, from monitoring and triage through to containment, recovery and lessons learned.
→ Harden our platforms. Work with development and infrastructure teams on secure architecture, access management, vulnerability management and penetration testing.
→ Manage third-party risk. Review vendors, partners and integrations, and make sure the people we work with meet our standards.
→ Keep us compliant. Translate GDPR, NIS2 and customer requirements into practical controls, and support audits and customer security questionnaires.
→ Build awareness. Make security part of how 750+ people work, through training, clear policies and being approachable.
→ Use automation and AI. We are an AI-first company that builds its own internal tools, so there is room to automate monitoring, reporting and routine checks.
Who We're Looking For
Sounds like you?
→ 5+ years in cyber security, with hands-on experience in incident response, security operations or security consulting.
→ Broad technical grounding across cloud and on-premise environments, networks, identity and web application security.
→ Incident experience. You have been in the room when something went wrong and know how to lead calmly through it.
→ Regulatory fluency. Comfortable with GDPR and NIS2; familiarity with ISO 27001 or similar frameworks.
→ Pragmatic judgement. You can tell the difference between a real risk and a theoretical one, and explain both to non-technical leaders.
→ Continuous improvement mindset. You take what works, find what can be better, and make it happen.
→ English at a professional level; German is a plus.
Probably not a fit if...
→you want a purely advisory role, here you own outcomes
→you only want to work on greenfield projects, here you build on and improve what is already running
→you see security mainly as saying no, here the job is making it safe to say yes
Nice to have: a certification such as CISSP, CISM, OSCP or ISO 27001 Lead Implementer/Auditor · experience in e-commerce or manufacturing environments · a forensics background
What We Offer
A competitive salary, plus a benefits package that includes:
→ Real ownership — you lead and further develop security for a global group, with direct access to leadership
→ International exposure — teams across Germany, Poland, Latvia, the USA, the UAE and Vietnam
→ Latest tooling — including the internal AI tools we build in-house
→ Local benefits — health coverage, paid leave & local perks
How We Hire
1
Apply, two minutes. Your CV is enough to start, no cover letter needed.
2
Call with recruiting. A first conversation about the role, the setup, and the salary range, openly, before you invest more time.
3
Interview with the hiring manager. A conversation about how you think, how you work, and the technical and leadership side of the role.
4
A quick conversation with the team. If that goes well, you meet the people you would be working with day to day.
5
Offer. If it is a fit on both sides, we make you an offer and take it from there.
Ready to lead security with us?
Send your CV. No cover letter needed. If your experience and mindset fit, we will talk within a few days.
The Customization Group · Columbus · Cologne · Leipzig · Berlin · Munich · Szczecin · Riga · Dubai · Saigon · thecustomizationgroup.com
We welcome applications from all backgrounds. What matters is your foundation and your willingness to learn.
- Department
- IT
- Locations
- Cologne
- Employment type
- Full-time