IT Risk Management Specialist - Security Risk Management (f/m/d)

Prague, CZ

Applications have closed

Deutsche Börse

Die offizielle Website der Gruppe Deutsche Börse mit Informationen zum Unternehmen und den Bereichen Investor Relations, Media, Karriere, Nachhaltigkeit und Regulierung.

View all jobs at Deutsche Börse

 

Your area of work:

 

The Group Security department directly contributes to execution of the Deutsche Börse Group information security strategy. As a central service provider for the Group entities, Group Security is responsible to protect information assets, incl. suppliers, in terms of safety, integrity, confidentiality, authenticity and availability by enforcing information security controls based on the relevant regulatory requirements and follows the international standard ISO/IEC 27000-series on the Information Security Management System.

 

Your responsibilities:


In your position, you will provide IT security expertise in support to the business and in line with the key responsibilities:

 

  • You consult the departments and management on Cyber Risk Management matters
  • You manage and lead the Information Risk Management service delivery
  • You consult Business Owners on the IT Security Risk Assessments, assuring proper risk identification and assessment in accordance with the Information Security Framework, and monitoring the risk remediation
  • You develop and maintain the Information Risk Management methodology - process - tooling to meet the business strategy, regulatory requirements and the best industry practices
  • You maintain trusted relationships with our business stakeholders, e.g. Risk Owner(s), Chief Information Security Officer, Compliance Officer(s), Technical Information Security Officer(s), and Internal/External Audit
  • You manage Supplier relevant information security incidents by leading and coordinating investigations with stakeholders and documenting incident reports
  • You support the regular reporting on information security to the respective boards and committees
  • You manage and lead the Onsite Risk Assessments for Ecosystem partners

Your profile:

 

  • Bachelor's and/or Master’s degree in information technology, Cybersecurity, Business Informatics or comparable education
  • 5+ years of experience in IT risk management, Cybersecurity, IT Audit or similar
  • Certifications like ITIL, CISM, CRISC, CISA, PMP or similar is an advantage
  • Knowledge of general legal and regulatory frameworks in the financial industry, for example EBA Guidelines on ICT and security risk management, DORA, NIS2, and industry standards like ISO/IEC 2700x or NIST
  • Strong analytical skills, critical thinking, ability to identify problems and propose solutions
  • Autonomous and resilient, with strong planning and organization skills
  • Exceptional communication and stakeholder management skills, both verbal and written in English (German would be considered an asset)

 

 

You can look forward to our benefit package:

 

  • Hybrid Work and Flexible working hours
  • Work from abroad - 12 days of remote work from EU countries per year
  • Group Share Plan - discount on company shares
  • Pension fund contribution - 3% of your gross salary (5% after 5 years with us)
  • Health & Wellbeing - fully covered Multisport card, life & accident insurance, sick days and 100% salary contribution during sick leave (up to 56 days)
  • 25 vacation days
  • Mobility - fully covered public transport in Prague & free parking
  • Flexible Benefit Account (Pluxee) - 1200 per month
  • Personal Development - annual budget of €690 ... and way more!

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  3  0  0
Category: Compliance Jobs

Tags: Audits CISA CISM CISO Compliance CRISC ITIL Monitoring NIS2 NIST Risk assessment Risk management Security strategy Strategy

Perks/benefits: Flex hours Flex vacation

Region: Europe
Country: Czechia

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.