> Markdown version of [/jobs/ext/123854-senior-ict-risk-manager](https://www.wearedevelopers.com/jobs/ext/123854-senior-ict-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # (Senior) ICT Risk Manager - **Company:** Raisin GmbH - **Location:** Berlin, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Information Security Management System - **Published:** May 15, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=2178f3335d9c17c3 ## About the Role Do you have experience in Risk management?, * Experience in Information Security, ICT Risk Management, or related fields. * Strong understanding of frameworks like ISO 2700X, NIST, DORA, or equivalent. * Background in financial services, payments, or other regulated environments is a plus. * Excellent interpersonal skills with the ability to influence, consult, and engage stakeholders at various levels. * Ability to structure complex risk topics and drive initiatives independently. * Analytical and structured working style with hands-on project management skills. * Knowledge of modern ICT and cybersecurity technologies, particularly in cloud and infrastructure settings. ## Description The Information Security function is part of the 2nd Line of Defence within our Compliance department. Its purpose is to define the methodological framework, policies, and procedures for managing ICT and information security risks across the organisation. We promote best practices for ICT risk governance and information security management to strengthen the bank's overall resilience posture, in line with the Digital Operational Resilience Act (DORA) and related regulatory requirements. This team provides independent oversight and challenge to the 1st Line of Defence by assessing, advising, and monitoring the implementation of ICT risk and security controls. Our working style is collaborative and aligned with our values of integrity, transparency, and accountability. We are committed to fostering an inclusive environment that values diverse perspectives and supports professional growth. Your Responsibilities * Review and challenge ICT risk assessments, including protection needs analyses, gap and maturity assessments, and target-actual comparisons. * Contribute to the development and maintenance of the Information Security Management System (ISMS) in line with regulatory and corporate requirements. * Develop, maintain, and enhance information security measures, controls, and policies aligned with ISO/IEC 2700x, DORA, and related frameworks. * Support internal and external reviews, audits, and assessments, including those of third-party service providers. * Review contractual arrangements to ensure compliance with ICT risk and information security standards. * Communicate security risks, requirements, and expectations to business and technology stakeholders. * Prepare management reports and presentations for executive stakeholders and oversight bodies. * Monitor emerging regulatory requirements and translate them into actionable improvements for the ISMS and ICT risk framework. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [Where to Find German Tech Jobs](https://www.wearedevelopers.com/magazine/366-where-to-find-german-tech-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)