CRIT Information Security Officer

Deutsche Börse AG
Frankfurt am Main, Germany
10 days ago
Apply on www.careerjet.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English, German

Tech stack

Artificial Intelligence Software Applications Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Technology Audit IT Management Python (Programming Language) Network Security Windows PowerShell Software Vulnerability Management Information Technology Outsourcing Information Technology
+1 more
CIS Benchmarks

Job description

  • The CRIT Information Security Officer is a key member of the CRIT Information Security Office, responsible for strengthening Eurex Clearing’s security posture through effective vulnerability management, network security controls, and automation - including the strategic use of AI technologies.
  • This role operates within a multidisciplinary team that manages IT audit readiness, remediation and finding management, IT Outsourcing, IT Compliance, IT resilience, and broader IT governance and risk reporting processes.
  • You will contribute to the organization’s overall security strategy and support consolidated IT and Information Security status reporting for executive leadership and the board of Eurex Clearing AG (ECAG).

Your responsibilities:

  • Understand and apply requirements of applicable regulations impacting Information Security and IT, with a particular focus on DORA, NIS2, and BSI-related standards.
  • Plan, execute, improve, and document vulnerability management and network security controls.
  • Maintain and structure technical Information Security documentation for IT applications and infrastructure, including IT suppliers within Clearing and Risk IT.
  • Maintain an overview of IT and non-IT assets relevant for IT asset management, including stakeholder interfaces to Group IT, Information Security, BCM, Outsourcing, and supplier monitoring processes.
  • Review and maintain IT Risk Management and IT Continuity Management processes and procedures for ECAG, including outsourced services.
  • Align with stakeholders to prevent gaps, issues, or regulatory findings related to the surveillance of IT suppliers.
  • Analyze automation potential and implement AI-based tools to enhance the team’s effectiveness.
  • Contribute to drafting IT and Information Security status reports for the executive board of Eurex Clearing AG.

Requirements

  • University or Master’s degree in Information Security, Computer Science, or a comparable qualification.
  • At least 2 years of relevant professional experience in IT or Information Security.
  • Strong understanding of security frameworks (ISO 27001, NIST, CIS Controls) and risk management methodologies.
  • Experience in scripting and automation (e.g. Python, PowerShell) and familiarity with AI-based security technologies.
  • Knowledge of audit processes and IT compliance requirements; experience with DORA and EMIT is an asset.
  • Experience preparing executive or board-level reporting.
  • Strong analytical skills combined with a hands-on, result-oriented working style.
  • Good communication, planning, and prioritization skills with intercultural competence.
  • Proficiency in written and spoken English; German language skills are an asset.

Nice to have:

  • Expertise in IT process standards such as ITIL or COBIT.
  • Hands-on experience with AI tools in a professional or security context.
  • Familiarity with ISO 2700x, DORA, NIS2, or BSI frameworks beyond foundational knowledge.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all