> Markdown version of [/jobs/ext/1224572-head-of-it-security-executive-director](https://www.wearedevelopers.com/jobs/ext/1224572-head-of-it-security-executive-director). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of IT Security - Executive Director - **Company:** Sumitomo Mitsui Banking Corporation - **Location:** Frankfurt am Main, Germany - **Experience:** Expert - **Salary:** €102,000.0 - €154,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management - **Published:** July 10, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=23d31579c0364da2 ## About the Role Significant leadership experience in IT or cyber security within financial services or regulated industries Strong knowledge of: Vulnerability management and security operations Security frameworks (NIST CSF, ISO 27001, CIS) Regulatory environments (Bafin / ECB, DORA, GDPR) Experience in audit engagement and regulatory remediation Qualifications Bachelor's degree in Information Security, IT, or related field (Master's preferred) Relevant certifications such as: CISSP, CISM, or CISA CRISC or equivalent risk-focused certification Competencies Customer Focus Driving Change Driving Results Embraces Diversity Enterprise Leadership Judgement and Decision Making Risk Management Strategic and Visionary Trust and Integrity What we offer ## Description The Head of IT Security SMBC EU AG is responsible for helping to define, implement, and oversee the organisation's end-to-end information and cyber security strategy, ensuring protection of critical assets, regulatory compliance, and operational resilience. This role provides leadership across SMBC EU AG ensuring alignment with enterprise risk frameworks and regulatory obligations (e.g. ECB, DORA, NIST, CRI). The anticipated annual salary range for this role is 102,000 - 154,000 €, with the final offer determined based on the candidate's skills, experience, role scope, location, and relevant market factors. In addition to base salary, the role may be eligible for a discretionary incentive award and a competitive benefits package, including core benefits such as pension provision. Business Area This role supports SMBC EU AG's continued growth and increasing regulatory expectations under ECB supervision. The Head of IT Security is responsible for maintaining an effective cyber and information security control environment and ensuring compliance with regulatory requirements. Working closely with the EMEA CISO and key stakeholders, the role oversees security risk management, regulatory engagement, audit activities, and the implementation of EMEA and Group security standards. Position Description Accountabilities & Responsibilities Work with the EMEA CISO to define and deliver a multi-year IT security strategy aligned to business objectives and regulatory expectations Act as the senior authority for cyber security risk across IT and business functions with the EU AG entity. Provide local SMBC EU AG executive-level reporting on security posture, risks, and remediation progress. Ensure effective identification, assessment, and remediation of security risks relevant to SMBC EU AG Drive continuous improvement aligned to industry frameworks (NIST CSF, CRI, ECB) Provide assurance that control effectiveness meets audit and regulatory expectations Collaborate with wider EMEA and Global SMBC Security teams to manage security risks relevant to SMBC EU AG Engage senior stakeholders across IT, Risk, Audit, and business units Provide clear communication on risks, incidents, and compliance status ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Climate vs. Weather: How Do We Sustainably Make Software More Secure?](https://www.wearedevelopers.com/videos/357-climate-vs-weather-how-do-we-sustainably-make-software-more-secure) ## Related Articles - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)