Logo-of-Deutsche-Börse-Group-hiring-for-jobs-in-Deutschland-on-GrabJobs

Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d)

icon briefcase Auftragstyp : Vollzeit

Anzahl der Bewerber

 : 

000+

Click to reveal the number of candidates who applied for this job.
icon loader
Jetzt bewerben
icon loader Jetzt bewerben

Let AI Supercharge Your Job Hunt!

JobCopilot scans 500,000+ company career sites daily to find jobs for you

Never miss an opportunity Save hours by auto-filling applications forms Land more interviews with tailored applications
happy man
thunder iconActivate JobCopilot

Arbeitsbeschreibung - Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d)


Group Company: Deutsche Börse AG 

 



Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d) 


Full-time | unlimited


 


Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 15,000 colleagues around the globe, we actively shape the future of financial markets. Join our One Global Team!


 



Your area of work: 


The Chief ICT Risk Office (CISO) combines IT & IS Risk Management in the 2nd Line of Defense. The department’s mandate is to set the IT and IS (ICT) risk governance and framework, set the control objectives, control review methodology and risk assessment methodology, conduct independent risk assurance of 1st LoD ICT controls (IT and IS controls), and independently monitor and report on the level of ICT risks as well as to drive transformation and collaboration.In this role, you will be part of ICT Risk Assurance team, performing continuous monitoring and oversight to confirm that our ICT controls are well-designed, correctly implemented, and operating effectively to protect the organization.


Your responsibilities: 



  • Design and implement risk-based assurance plans aligned with internal and regulatory requirements

  • Lead and execute IT & IS assurance assessments to evaluate risks across applications, infrastructure, cloud platforms, and network/security processes

  • Ensure IT systems and processes comply with relevant laws, regulations, and standards, including DORA, MaRisk, CSSF, NIST, ISO 27000, etc.

  • Test the effectiveness of IT General Controls (ITGC) and cybersecurity controls across Access Management, SDLC & Change Management, Encryption, Third‑Party Risk, Patch & Vulnerability Management, SIEM, Penetration Testing, IT Operations, and other security domains to identify gaps and improvement areas

  • Prepare high‑quality assurance reports with clear observations, identified risk, and actionable recommendations for management; effectively communicate complex technical issues to both technical and non‑technical stakeholders

  • Track and monitor remediation actions, validate closure, and ensure sustainability of corrective measures

  • Collaborate with IT, Security teams, and other cross-functional stakeholders to provide risk insights or guidance on risk and control expectations for new and existing systems

  • Contribute to the continuous improvement of assurance methodologies, frameworks, and processes

  • Stay updated with emerging cyber threats, industry trends, evolving technologies, cloud risks, and changes in the regulatory landscape


Your profile: 



  • A minimum of 6+ years of dedicated experience in IT/ cyber audit, or second-line assurance, or cybersecurity implementation or GRC role, with a proven track record of leading complex audits/assurance reviews or implementation projects from planning to reporting

  • Bachelor’s or Master’s degree in IT, Information Security, Risk Management, or a related field

  • Practical experience in various security domains, such as:

    • Cloud Security

    • Network Security

    • Vulnerability Management

    • Penetration Testing

    • SIEM / SOC /CERT

    • Encryption

    • Identity & Access Management / Privileged Access Management (PAM)

    • Software Development & Change Management

    • Artificial Intelligence (AI) Risk / AI Governance



  • Strong knowledge of IT governance and control frameworks such as COBIT, CSA‑CCM, ISO/IEC 27000 series, ITIL, and relevant EU regulations

  • Certifications such as CISA, ISO 27001 LA/LI, CISM, CISSP, CRISC are preferred

  • Experienced in audit/assurance techniques, developing risk-based testing strategies, sampling methodologies, and mentoring junior team members

  • Ability to identify root causes, understand cross-domain risk impacts, and translate complex technical and regulatory issues into business implications

  • Strong communication, negotiation, and influencing skills; comfortable presenting findings and building credibility with senior stakeholders

  • Strong understanding of the Three Lines of Defense model

  • Languages: Excellent command of English (written and spoken)



 


Deutsche Börse Group embraces an international climate, whereby diversity is universal. This is evident across the board, be it through our diverse workforce, routine responsibilities or other areas of activities and scope of application. We are looking for employees who enjoy working in a dynamic and flexible environment and are willing to put forward innovative ideas for the company. An open mindset, a proactive approach and self-motivation are prerequisites. 
We offer our employees an attractive remuneration package. Benefits include a high level of trust and autonomy in modern, centrally located workplaces where corporate culture and values are exercised regularly. 



We value diversity and therefore welcome all applications - regardless of gender, nationality, ethnic and social origin, religion/belief, disability, age, sexual orientation and identity.



Have we piqued your interest? Then we encourage you to apply now!


 


Do you have questions about the application process or this position?


Please contact us at [email protected] or by phone 069-211-11810. We look forward to getting to know you!



Deutsche Börse Group, Human Resources
https://careers.deutsche-boerse.com/


 



Original job Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Jetzt bewerben
Share Job
Share Job

Auto-Apply to Senior Specialist: IT Audit & Cyber Risk Jobs with your AI JobCopilot

thunder icon Auto-Apply with AI

Similar Senior Specialist: IT Audit & Cyber Risk Jobs in Germany

GrabJobs ist das führende Jobportal in Germany und verbindet Sie schnell mit Tausenden von -Jobs! Finden Sie die besten -Jobs in Germany, bewerben Sie sich mit einem Klick und sichern Sie sich noch heute einen Job!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.