INFORMATION SECURITY MANAGER (f/m/d)

Frankfurt am Main

360T

Offering the complete suite of FX Trading Solutions, taking care of 2,900 buy-side customers and more than 200 liquidity providers across 75 different countries.

View all jobs at 360T

Apply now Apply later

Your Role

As Information Security Manager and part of the Security & Privacy Governance team, you will steer our ISO 27001:2022 certified information‑security‑management system (ISMS), drive compliance with the EU Digital Operational Resilience Act (DORA), and align our controls to international regulations such as the CFTC System Safeguards Requirements and Singapore’s MAS Technology Risk Management (TRM) Guidelines. 

Your Responsibilities

Governance & ICT Risk

  • ISMS Ownership: Maintain and enhance our ISO 27001:2022 ISMS and policy framework.
  • DORA Alignment:  Implement the act’s requirements on ICT-risk governance, incident reporting and third-party oversight ahead of the 17 Jan 2025 go-live.  
  • Global Regulatory Mapping — ensure our control set also meets CFTC System Safeguards for automated trading systems and MAS TRM principles on governance, access control and cloud security.  
  • ICT-Risk Assessments: Run risk analyses in line with regulations, best practices, Three-Lines-of-Defence model, reporting residual risk to senior management.
Engineering & Operations (First-Line Enablement)

  • Security-by-Design Reviews: Advise product teams on secure architecture, zero-trust networking and segregation of duties.
  • Control Lifecycle: Define, monitor and improve technical controls (vulnerability management, hardening baselines, privileged access) together with Development, Infrastructure, and SRE teams.
  • Tooling Strategy: Manage, use, and optimise our threat intelligence, security events, intrusion detection, deception, and similar platforms. Ensure coverage, effectiveness, efficiency and automation.
Detection & Response

  • Incident ResponseManage the NIST-aligned lifecycle (prepare, detect, contain, eradicate, recover, lessons learned) and meet the multi-jurisdiction requirements and timelines set by our regulators and expected by our clients.
  • Assess & Improve: Use threat intelligence, vulnerability reports, and similar news sources to assess changes in landscape, threats, and best practices, and provide thoughtful, innovative, and practical guidance to improve our processes and systems.
  • Table-Top & Purple-Team Drills: Coordinate regular exercises to validate controls and drive continuous improvement.
People & Culture

  • Awareness & Training: Deliver engaging security-awareness sessions and micro-learnings for developers, sales and operations staff.
  • Client & Audit Liaison: Help answer RFPs, coordinate ISO/DORA and other audits, and support due-diligence requests from counterparties worldwide.

Your Profile

  • University degree in computer science or a comparable education
  • 5+ years of experience in the IT security domain. Certifications are a plus (CISSP, CRISC, CISM, ISO27001 Lead Implementer or Auditor)
  • Working knowledge in implementing and maintaining security certifications (ISAE3402, SOC1, SOC2, ISO2700x) and maintaining compliance to national and international security, data protection, and privacy standards, laws and regulations
  • Experience in the development of practical security processes, policies and standards. Ability to work with multiple, sometime conflicting goals and priorities
  • Experience in the management of information security issues and incidents
  • Excellent analytical and conceptual thinking, able to understand, structure and prepare/explain complex topics on the appropriate level, depending on context and recipient
  • Track record of taking responsibility, working independently and without much supervision
  • Highly motivated to learn about new topics, technologies, and business cases
  • Highly proficient in spoken and written English (CEF C1 or above) is mandatory. Very good command of German language (CEF B2 or above) is desirable

Our Offer

  • Clear career concept
  • Performance appraisals on a regular base
  • Possibility to switch between Software Development teams according to interests, projects, and skills.
  • 360T Academy
  • Frankfurt office located directly in the city center
  • Social gatherings
We offer an outstanding opportunity for a highly motivated individual to participate in the growth of a successful technology company in the financial sector. The position is based in Frankfurt am Main and is available immediately.

How to Apply

If your background and qualifications meet these specifications, please forward your application including your salary expectation and the earliest starting date by clicking the “Apply” button.

Contact

Irune Del Buey
People & Culture Manager

Send email
Grüneburgweg 16-18
60322 Frankfurt am Main
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0
Category: Leadership Jobs

Tags: Audits Automation CISM CISSP Cloud Compliance Computer Science CRISC Governance Incident response Intrusion detection ISMS ISO 27000 ISO 27001 NIST Privacy Risk assessment Risk management SOC 1 SOC 2 Strategy Threat intelligence Vulnerability management

Perks/benefits: Career development Team events

Region: Europe
Country: Germany

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.