Senior Specialist: IT Audit & Cyber Risk (2nd Line)

Deutsche Börse AG
Frankfurt am Main, Germany
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Identity and Access Management Information Technology Audit IT Management Information Technology Operations Network Security Systems Development Life Cycle Security Information and Event Management
+6 more
Software Engineering Software Vulnerability Management IT General Controls (ITGC) Cyber Threat Analysis Marisk Information Technology

Job description

The Chief ICT Risk Office (CISO) combines IT & IS Risk Management in the 2nd Line of Defense. The department’s mandate is to set the IT and IS (ICT) risk governance and framework, set the control objectives, control review methodology and risk assessment methodology, conduct independent risk assurance of 1st LoD ICT controls (IT and IS controls), and independently monitor and report on the level of ICT risks as well as to drive transformation and collaboration.In this role, you will be part of ICT Risk Assurance team, performing continuous monitoring and oversight to confirm that our ICT controls are well-designed, correctly implemented, and operating effectively to protect the organization., * Design and implement risk-based assurance plans aligned with internal and regulatory requirements

  • Lead and execute IT & IS assurance assessments to evaluate risks across applications, infrastructure, cloud platforms, and network/security processes
  • Ensure IT systems and processes comply with relevant laws, regulations, and standards, including DORA, MaRisk, CSSF, NIST, ISO 27000, etc.
  • Test the effectiveness of IT General Controls (ITGC) and cybersecurity controls across Access Management, SDLC & Change Management, Encryption, Third-Party Risk, Patch & Vulnerability Management, SIEM, Penetration Testing, IT Operations, and other security domains to identify gaps and improvement areas
  • Prepare high-quality assurance reports with clear observations, identified risk, and actionable recommendations for management; effectively communicate complex technical issues to both technical and non-technical stakeholders
  • Track and monitor remediation actions, validate closure, and ensure sustainability of corrective measures
  • Collaborate with IT, Security teams, and other cross-functional stakeholders to provide risk insights or guidance on risk and control expectations for new and existing systems
  • Contribute to the continuous improvement of assurance methodologies, frameworks, and processes
  • Stay updated with emerging cyber threats, industry trends, evolving technologies, cloud risks, and changes in the regulatory landscape

Requirements

  • A minimum of 6+ years of dedicated experience in IT/ cyber audit, or second-line assurance, or cybersecurity implementation or GRC role, with a proven track record of leading complex audits/assurance reviews or implementation projects from planning to reporting
  • Bachelor’s or Master’s degree in IT, Information Security, Risk Management, or a related field
  • Practical experience in various security domains, such as:

  • Cloud Security
  • Network Security
  • Vulnerability Management
  • Penetration Testing
  • SIEM / SOC /CERT
  • Encryption
  • Identity & Access Management / Privileged Access Management (PAM)
  • Software Development & Change Management
  • Artificial Intelligence (AI) Risk / AI Governance

Strong knowledge of IT governance and control frameworks such as COBIT, CSA-CCM, ISO/IEC 27000 series, ITIL, and relevant EU regulations

Certifications such as CISA, ISO 27001 LA/LI, CISM, CISSP, CRISC are preferred

Experienced in audit/assurance techniques, developing risk-based testing strategies, sampling methodologies, and mentoring junior team members

Ability to identify root causes, understand cross-domain risk impacts, and translate complex technical and regulatory issues into business implications

Strong communication, negotiation, and influencing skills; comfortable presenting findings and building credibility with senior stakeholders

Strong understanding of the Three Lines of Defense model

Languages: Excellent command of English (written and spoken)

About the company

Ready to make a real impact in the financial industry? At Deutsche Börse Group, we’ll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 16,000 colleagues around the globe, we actively shape the future of financial markets. Join our One Global Team!, Deutsche Börse Group is one of the world’s leading exchange organisations and an innovative market infrastructure provider. With our products and services, we ensure that capital markets are fair, transparent, reliable, and stable. Together, we develop state-of-the-art IT solutions and offer our IT systems all over the world. Play a key role in our mission: to create trust in the markets of today and tomorrow.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.xing.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

Videos

See all

Related articles

See all