Senior Cybersecurity Risk Manager (f/m/d)
Prague, CZ
Deutsche Börse
Die offizielle Website der Gruppe Deutsche Börse mit Informationen zum Unternehmen und den Bereichen Investor Relations, Media, Karriere, Nachhaltigkeit und Regulierung.
Area of work:
The Group Security department directly contributes to execution of the Deutsche Börse Group cybersecurity strategy. As a central service provider for the Group entities, Group Security is responsible to protect information assets in terms of safety, integrity, confidentiality, authenticity and availability by enforcing information security controls based on the relevant regulatory requirements and the international standards like ISO 2700x-series on the Information Security Management System.
In this position, you have a unique opportunity to be part of an expanding department at the core of a thrilling global business.
The Information Security Risk Management team is responsible for the enforcement of the Information Security Framework in close collaboration with CISO and other central functions like Group Risk, Compliance Management and Data Privacy.
In the advertised position you will be focused on the Cyber Risk Management, our core competence, consulting our business partners and management on IT Security Risk Management matters. Beside that you will support various Information Security related projects ensuring robustness and the state-of-the-art solutions following the regulatory requirements and the best industry practices.
Your strong interpersonal skills with the ability to build trust with business and technology stakeholders at all levels will be the driving force behind your work in a friendly, co-operative and supportive environment.
Your responsibilities:
- You consult the departments and management on Cybersecurity Risk Management matters.
- You manage and lead the Information Risk Management service delivery.
- You consult Business Owners on the Cybersecurity Risk Assessments, assuring proper risk identification and assessment in accordance with the Information Security Framework, and monitoring the risk remediation.
- You contribute to strategic Cyber Security projects like Cloud Security.
- You develop and maintain the Information Risk Management methodology - process - tooling to meet the business strategy, regulatory requirements and the best industry practices.
- You maintain trusted relationships with our business stakeholders, e.g. Risk Owner(s), Chief Information Security Officer, Compliance Officer(s), Technical Information Security Officer(s), and Internal/External Audit.
Your profile:
- Master degree in Information Technology, Cybersecurity, Business Informatics or comparable education
- 5+ years of experience in IT risk management, Cybersecurity, GRC, IT Audit or similar
- Certifications like ITIL, CISM, CRISC, CISA, PMP or similar is an advantage
- Knowledge of general legal and regulatory frameworks in the financial industry, for example EBA Guidelines on ICT and security risk management, DORA, NIS2, and industry standards like ISO/IEC 2700x or NIST
- Strong analytical skills, critical thinking, ability to identify problems and propose solutions
- Autonomous and resilient, with strong planning and organization skills
- Exceptional communication and stakeholder management skills, both verbal and written in English (German would be considered an asset)
Location: Prague
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CISA CISM CISO Cloud Compliance CRISC ITIL Monitoring NIS2 NIST Privacy Risk assessment Risk management Strategy
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.