Information Security Consultant (DORA / ISMS) - Specialist - Financial Services

Publicis Groupe
München, Germany
27 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
German
Job source

Tech stack

Cyber Security Information Systems Computer Networks IT Management Information Systems Security Architecture Professional Requirements Management Information Security Management System

Job description

We help unlock value through a start-up mindset combined with modern, proven methods. Our approach integrates strategy, consulting, and customer experience with agile engineering and creative problem-solving to deliver measurable business outcomes. Guided by our core values and our purpose, helping people thrive in the brave pursuit of what?s next?our global team of more than 20,000 professionals across 53 offices brings together expertise in technology, data science, consulting, and customer-centricity. By combining these capabilities, we enable our clients to accelerate their businesses through the design and delivery of products and services that their customers truly value. Overview In this role, you support the Information Security functions of banking clients and contribute to the operation, maintenance, and continuous improvement of their Information Security Management System (ISMS). You work in close collaboration with internal stakeholders across business and technology teams, supporting the implementation and adherence to defined security policies, standards, and controls. Within a regulated financial environment, you take responsibility for specific security-related activities, contribute to risk assessments and compliance processes, and help ensure alignment with relevant regulatory and internal requirements. Responsibilities Organize, structure, and maintain the task backlog of the Information Security function in a clear and traceable manner. Independently execute defined information security tasks, using established ISMS tools, methods, and processes. Support operational teams and employees in embedding information security requirements into daily activities and workflows. Collaborate closely with the Information Security Officer and relevant stakeholders to align on priorities and deliverables. Contribute to the operation and continuous improvement of established ISMS processes, including requirements management and threat analysis, structural analysis (including information networks), and protection needs assessments. Support the definition and implementation of target security measures, including the development of security concepts and their practical application. Conduct target-versus-actual analyses and contribute to risk assessments and risk treatment activities. Prepare, maintain, and ensure high-quality reporting and documentation in line with ISMS standards and regulatory requirements. Responsibilities Organize, structure, and maintain the task backlog of the Information Security function in a clear and traceable manner. Independently execute defined information security tasks, using established ISMS tools, methods, and processes. Support operational teams and employees in embedding information security requirements into daily activities and workflows. Collaborate closely with the Information Security Officer and relevant stakeholders to align on priorities and deliverables. Contribute to the operation and continuous improvement of established ISMS processes, including requirements management and threat analysis, structural analysis (including information networks), and protection needs assessments. Support the definition and implementation of target security measures, including the development of security concepts and their practical application. Conduct target-versus-actual analyses and contribute to risk assessments and risk treatment activities. Prepare, maintain, and ensure high-quality reporting and documentation in line with ISMS standards and regulatory requirements.

Requirements

Professional experience in relevant areas such as security and risk management (including risk assessment and treatment), protection of information and assets, information security governance, information security incident management, and auditing of information systems and processes. Proficiency in German at a fluent level (minimum C2). At least one recognized certification in information security or information security risk management, such as: ISACA CRISC, CISM, or CISA ISO/IEC 27001 Lead Auditor (ISC) CISSP or T.I.S.P. Certified IT-Grundschutz Consultant (Certifications must be verifiable and provided as part of the application.) Nice to Have Active engagement in relevant professional or industry associations. Contributions to publications or thought leadership in the field of information security. Strong project management skills combined with a structured and analytical working style. Practical experience in designing, implementing, and operating Information Security Management Systems (ISMS). Experience in developing and maintaining security architectures. Solid background in IT governance and IT management. Strong understanding of regulatory frameworks and compliance requirements, in particular BAIT, DORA, and CRA. Additional information An inclusive workplace that promotes diversity and collaboration.

Benefits & conditions

Competitive compensation and benefits package. Flexibility to support work-life balance. Comprehensive health benefits for you and your family. Generous paid leave and holidays. Wellness program and employee assistance. As part of our dedication to an inclusive and diverse workforce, Publicis Sapient is committed to Equal Employment Opportunity without regard for race, color, national origin, ethnicity, gender, protected veteran status, disability, sexual orientation, gender identity, or religion. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures.

About the company

Publicis Sapient is a digital transformation partner supporting established organizations in achieving a future, digitally enabled state, both in how they operate and how they deliver value to their customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:18 min

Evaluating distributed computation networks for AI model execution

Idan Gazit · Coffee With Developers

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

Videos

See all

Related articles

See all