Information Risk and Security Manager at Commerz Real AG
berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

30 Nov, 26

Salary

0.0

Posted On

01 Sep, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description





  • Contact person for security management (SIM) and assumption of responsibility for the flow of information on information risks and risk treatment plans towards the "Information Security and Risk Management" business unit
  • Consulting/management and participation within the business unit in the definition, planning and implementation of department-specific security measures as well as related procedures, threat analyses and tools.
  • Contact person as a risk team member for both employees of their own business unit regarding questions about risk management and for the central risk management department of Finanz Informatik.
  • Evaluation, establishment and assessment of potential risk concentrations, support with risk management tasks such as recording risk reports and risk-relevant topics, and ensuring a functioning risk management process within the responsible department.
  • Development, implementation and further development of suitable measures for risk management, as well as monitoring the effectiveness of implemented measures.
  • Development, refinement and communication of guidelines for Business Continuity Management (BCM) as well as the associated guidelines, process descriptions and supporting tools.
  • Participation in the collection of possible, sensible emergency measures to safeguard the emergency scenarios of Finanz Informatik, creation and updating of emergency plans, and the execution of emergency tests and exercises.

Profile:


  • Successfully completed studies in (business) informatics with a focus on information security and/or risk management, or comparable qualification. 
  • At least six years of relevant professional experience in the fields of information security and technology, as well as related regulatory requirements.
  • Very good experience in implementing regulatory and legal requirements for banks (MaRisk, DORA and BSIG/KritisV) 
  • Extensive knowledge of the interrelationship between information security and the topics of business continuity management (BCM) and data protection (BDSG, GDPR)
  • Excellent abstract and analytical skills and the ability to present and document complex issues in an understandable way.
  • Teamwork and problem-solving skills combined with an independent, structured and agile way of working
  • A high degree of initiative, conflict resolution skills, and clear communication.
  • Du identifizierst, analysierst und bewertest IT- und Informations-Risiken
  • Du berätst die Fachabteilungen und -bereiche hinsichtlich Sicherheitsvorgaben bei der Konzeption und Einführung neuer IT-Dienste, Produkte und Plattformen
  • Du arbeitest an der Konzeption, Implementierung, Überwachung und Verbesserung eines Information Security Management Systems (ISMS) mit, das als gesteuerter Regelkreis funktioniert (Planung, Konzeptüberprüfung, Implementierung und Einführung im PDCA-Zyklus). Des Weiteren definierst und operationalisierst du in diesem Kontext Vorgaben zur kontinuierlichen Verbesserung der IT-Sicherheit und überprüfst diese
  • Du stellst die Einhaltung von gesetzlichen und konzernweit gültigen Sicherheitsanforderungen und Richtlinien (z.B. DORA, MaRisk, NIS 2, ISO27001) sicher
  • Du führst proaktive Bedrohungs- und Risikoanalysen durch
  • Du hilfst bei der Behandlung von Risiken und dokumentierst Maßnahmen im Risikomanagement
  • Du steuerst und koordinierst externe Dienstleister und Partner, gegebenenfalls inklusive regulatorisch notwendigem Outsourcing-Management
  • Du bist mit verantwortlich für das SOC, SIEM und Vulnerability Management

Dein Profil


  • Du hast bereits mehrere Jahre Berufserfahrung in einer vergleichbaren Position
  • Du verfügst über Kenntnisse in IT Security Prozessen, IT Service Management / Security Management Frameworks (ITIL, ISO/ IEC 27001)
  • Du hast Lust für Deine Themen Verantwortung zu übernehmen und Deine Ideen einzubringen
  • Deine Deutsch- und Englischkenntnisse sind in Wort und Schrift sehr gut
  • Du hast ein abgeschlossenes Studium der (Wirtschafts-)Informatik, IT-Sicherheit oder eine vergleichbare Ausbildung
  • Bestenfalls hast du bereits einschlägige Zertifizierungen wi


How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities
Loading...