Universitätsspital Zürich
Zürich
Information Security Officer & IAM Governance Lead 80-100%
- 04 August 2026
- 80 – 100%
- Permanent position
- German (Fluent), English (Fluent)
- 8600 Zürich
About the job
Shape information security with impact: As part of the CSO/CISO team, you ensure that IAM governance works in everyday practice. You coordinate the central IAM governance committee, bring together medicine, nursing, administration and IT, and create solutions that combine security and clinical agility.
As an Information Security Officer, you also work on a variety of cyber and information security topics – from system assessments and project consulting to assessments and handling enquiries.
The University Hospital Zurich is one of the largest hospitals in Switzerland. Our over 8,600 employees and around 700 trainees are committed daily to the well-being of our patients.
As an Information Security Officer, you also work on a variety of cyber and information security topics – from system assessments and project consulting to assessments and handling enquiries.
The University Hospital Zurich is one of the largest hospitals in Switzerland. Our over 8,600 employees and around 700 trainees are committed daily to the well-being of our patients.
Information Security Officer & IAM Governance Lead 80-100%
01.10.2026 or by arrangement
Your main tasks
- Shape IAM governance: You are responsible for the further development and updating of IAM directives and policies and ensure that these are practical, understandable and in line with the CSO/CISO strategy.
- Establish and lead the IAM governance committee: You bring together medicine, nursing, administration and IT, moderate the dialogue and ensure that decisions are made and different interests between operational requirements and security are brought together in a solution-oriented manner.
- Manage governance processes: You define the scope, frequency and quality requirements for central IAM governance processes such as role recertifications and SoD checks and ensure their consistent implementation and follow-up.
- Assess exceptions and risks: You evaluate exemption requests, weigh security risks and operational requirements, and ensure comprehensible and audit-proof documentation of decisions.
- Ensure IAM compliance: You ensure compliance with legal, regulatory and internal requirements and support audits, reviews and the handling of security incidents in the IAM environment.
- Further develop IAM strategy: Together with the specialist departments and IT, you shape the IAM strategy further and translate it into understandable and binding requirements.
Your profile
- Education: Completed studies in (business) informatics, law or economics or a comparable qualification. Certifications in governance and audit environments (e.g. CISA, CISM, CRISC, ISO 27001 Lead Auditor) are a plus.
- IAM & governance: Several years of experience in IAM governance processes and/or IAM audits as well as sound understanding of relevant IAM concepts such as identity lifecycle, role and permission models, PAM, MFA and SSO.
- Professional experience: Experience in a control or oversight function, for example as a governance manager, IT auditor or risk manager.
- Working style: Analytical, structured and solution-oriented. You can prepare complex matters understandably and translate them into clear, comprehensible decisions.
- Stakeholder management: Confident in dealing with different stakeholders on a professional and technical level and enjoy bringing different perspectives together.
- Language skills: Very good German and English skills.
Our benefits
We are a small, well-coordinated team with high motivation and a clear mission: protecting the data, systems and employees of USZ. In the information security (ISO) environment, we work closely with a wide range of stakeholders to translate information security requirements and concepts into effective and practical solutions. This involves close collaboration with the Security Operations Center (SOC) team.
The team is characterised by open and trusting collaboration, short decision-making paths and a high degree of personal responsibility. New ideas and impulses are welcome and contribute to the continuous development of information security at USZ. Together we create sustainable solutions and make an important contribution to protecting the organisation.
The team is characterised by open and trusting collaboration, short decision-making paths and a high degree of personal responsibility. New ideas and impulses are welcome and contribute to the continuous development of information security at USZ. Together we create sustainable solutions and make an important contribution to protecting the organisation.
University Hospital Zurich
8600 Zurich
8600 Zurich