Director Global IT Security (m/f/d
Verfasst am 2026-08-07
-
IT/Informationstechnik
Cyber-Sicherheit, Informationssicherheit & Datenschutz, Sicherheits-Manager, Netzwerksicherheit
About CTS EVENTIM
CTS EVENTIM is one of the world’s leading providers of ticketing and live entertainment. We connect millions of fans with unforgettable live experiences and provide promoters, venues, artists and partners with powerful technology, services and platforms. Our technology landscape includes high-traffic consumer platforms, international ticketing systems, B2B and SaaS solutions, enterprise systems, data platforms, cloud services and scalable infrastructure. IT Security is a strategic enabler of trust, resilience, product quality and continued growth across the CTS EVENTIM Group.
YourRole As Director Global IT Security (m/f/d)
You will lead the continuous hardening of CTS EVENTIM’s group-wide technology landscape and shape the next stage of our security maturity across technology, people and processes. Reporting directly to the CTO, you will own and further develop the security function across Product Security, Enterprise Security, Governance, Risk & Compliance (GRC) and Security Operations. A key focus will be strengthening shift-left security across Engineering and Product.
You will establish developer-friendly guardrails, practical security standards and strong security capabilities within engineering teams, while protecting high-traffic ticketing platforms against bot attacks, automated abuse and other adversarial traffic patterns.
- Define and execute a group-wide IT security strategy and roadmap aligned with business goals, technology strategy and international growth.
- Drive the hardening of customer-facing platforms, B2B and SaaS products, enterprise systems, cloud services, infrastructure, identity platforms, APIs, development environments and third-party integrations.
- Build and mature the security operating model across Product Security, Enterprise Security, GRC and Security Operations, including policies, controls, risk management and measurable outcomes.
- Establish practical Dev Sec Ops and shift-left capabilities, including secure coding, threat modelling, security champions, code and infrastructure scanning, CI/CD security and secure release gates.
- Lead the security approach for high-traffic, business-critical ticketing platforms, including bot management, WAF/CDN controls, DDoS protection, rate limiting, behavioural analytics, anomaly detection and incident playbooks.
- Lead Security Operations and incident readiness, including monitoring, detection engineering, escalation paths, exercises, post-incident reviews and continuous improvement.
- Own the security-related GRC agenda and support compliance and audit readiness in line with relevant frameworks and regulations, including ISO 27001, NIST CSF, GDPR and NIS2-related expectations.
- Shape the responsible use of AI in cyber defence and security operations, while establishing appropriate governance, human oversight, auditability and safeguards for sensitive information.
- Lead, develop and scale the IT Security team and strengthen security awareness and behaviour across the organisation.
- At least 10 years of experience in cybersecurity, information security or IT security, including significant leadership responsibility in a technology-driven, high-scale or digital platform environment.
- Proven experience leading security across complex IT landscapes covering customer-facing platforms, APIs, cloud services, on-premises infrastructure, enterprise systems, identity platforms and software development environments.
- A strong track record in building or maturing security functions across Product Security, Enterprise Security, GRC and Security Operations.
- Deep expertise in application and product security, enterprise security, identity and access management, vulnerability management, secure architecture, incident response and security monitoring.
- Strong practical understanding of Dev Sec Ops , secure SDLC, software supply chain security, developer enablement and security automation.
- Experience protecting high-traffic websites, e-commerce, marketplaces, ticketing platforms, SaaS products or similarly business-critical consumer platforms, including hands‑on familiarity with bot management and automated abuse…
Um nach Stellen zu suchen, sie anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie hier, um eine Suche zu starten: