Dein persönlicher KI-Karriere-Agent
Information Security Manager - Ownership in Open Finance (m/w/x)
Managing ISO 27001 ISMS and DORA ICT risk for open finance. ISO 27001 ISMS hands-on experience required. Direct C-level reporting, ownership valued.
Deine Match-Analyse
Warum dieser Job zu dir passt
Mögliche Lücken
Tipps für deine Bewerbung
Anforderungen
- Degree in information security, computer science, law/compliance, or comparable qualification
- Relevant professional experience in information security and ICT risk management
- Solid hands-on experience operating ISO 27001 ISMS
- Ownership of ISO 27001 ISMS documentation, controls, and compliance activities
- Experience working with software engineering, product, or DevOps teams
- Experience in a technology-led environment
- Knowledge of DORA
- First practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT)
- Strong hands-on mentality
- Analytical thinking
- Ability to manage multiple topics and stakeholders
- Ability to manage topics and stakeholders in a dynamic environment
- Confident communication in German with technical audiences
- Confident communication in German with non-technical audiences
- Confident communication in English with technical audiences
- Confident communication in English with non-technical audiences
Aufgaben
- Own the ISMS under ISO 27001
- Hold the ICT Risk Management Function under DORA
- Perform risk assessments
- Classify ICT incidents
- Oversee third-party risk
- Embed security into development processes
- Act as central contact for audits
- Report directly to the Management Board
- Work closely with the Chief Legal Officer
- Maintain the ICT risk framework
- Maintain the information register
- Develop ISMS in line with ISO 27001 Annex A
- Define baseline controls
- Run continuous maturity assessments
- Prepare and steer certification audits
- Prepare and steer surveillance audits
- Own audit evidence for DORA and ISO 27001
- Run internal self-audits
- Coordinate with external audit partners
- Coordinate with internal audit
- Work closely with Software Engineering, Platform, and DevOps
- Embed security and compliance into development processes
- Support business continuity planning
- Support disaster recovery planning
- Conduct annual continuity testing
- Assess and classify new ICT services under DORA
- Review ICT third-party contractual requirements
- Initiate penetration tests
- Run security incident response
- Conduct post-incident reviews
- Strengthen security awareness through training
- Strengthen security awareness through workshops
Berufserfahrung
Ausbildung
Sprachen
Tools & Technologien
Benefits
- Direct reporting lines to C-level
- Efficient collaboration
- Ownership valued
- Semi-annual feedback
- Pioneering spirit
- Hybrid working model
- Teamwork focus
- Personal development budget
- Clear growth paths
- Expertise support
Von Nejo automatisch aufbereitet
Nejo hat diesen Job automatisch von der Website des Unternehmens Qwist GmbH erfasst und die Informationen auf Nejo mit Hilfe von KI für dich aufbereitet. Trotz sorgfältiger Analyse können einzelne Informationen unvollständig oder ungenau sein. Bitte prüfe immer alle Angaben in der Originalanzeige! Inhalte und Urheberrechte der Originalanzeige liegen beim ausschreibenden Unternehmen.
Zur Originalanzeige bei Qwist GmbHÜber das Unternehmen
Qwist is a leader in Open Finance, helping organizations unlock, analyze, and leverage financial data.
Nejo bewertet ihn, und bringt ihn danach gemeinsam mit dir in Bestform.
Noch nicht perfekt?
- NFONInformation Security Manager (m/w/x)Vollzeitmit HomeofficeBerufserfahrenMünchen, Berlin, Mainz, Mannheim
- N26Information Security Controls Manager - Cloud & AI Governance (m/w/x)Vollzeitmit HomeofficeManagementBerlin
- SPREAD GmbHInformation Security & Compliance Officer (m/w/x)Vollzeitmit HomeofficeBerufserfahrenBerlin
- Dussmann GroupInformation Security Manager (m/w/x)Vollzeitmit HomeofficeBerufserfahrenBerlin
- N26ICT Risk Assessment Manager (m/w/x)Vollzeitmit HomeofficeBerufserfahrenBerlin