Cloud ICT Risk Manager

Job type:Unbefristet
Stadt:Frankfurt
Region:Hessen
Branche:Cybersicherheit
Art des Kundenunternehmens:Inhouse
Stellenreferenz:8524
Veröffentlichungsdatum:März 23, 2026

Lernen Sie unseren Personalvermittler kennen

Über die Stelle

Cloud Security Expert 
Location: Frankfurt

A role that inspires you

Join a forward-looking organisation as Cloud Security Expert within the Second Line of Defence. In this independent oversight function, you will assess, challenge, and strengthen cloud security frameworks, ensuring that cloud environments are resilient, compliant, and aligned with enterprise-wide risk governance standards.

Key Responsibilities:

  • Act as a Second Line of Defence function providing independent oversight of cloud security risks.

  • Define and maintain cloud security policies, standards, and control frameworks.

  • Conduct independent risk assessments of cloud architectures, configurations, and deployments (e.g. AWS, Azure, GCP).

  • Review and challenge First Line cloud implementations and security controls.

  • Assess risks related to identity and access management, data protection, encryption, and network security in cloud environments.

  • Ensure alignment with regulatory and cybersecurity requirements.

  • Establish monitoring, reporting, and escalation mechanisms for cloud-related risks.

  • Support incident oversight and review root-cause analyses from a governance perspective.

  • Provide expert guidance and training on secure cloud adoption practices.

Your Profile:

  • Degree in computer science, cyber security, or a related technical discipline.

  • Several years of experience in cloud security, cyber risk, or security governance.

  • Strong knowledge of major cloud platforms (AWS, Azure, or GCP) and cloud security principles.

  • Experience with security frameworks and control standards (e.g. ISO 27001, NIST, CIS).

  • Familiarity with regulatory requirements in regulated environments is advantageous.

  • Analytical mindset with the ability to independently assess and challenge technical implementations.

  • Strong communication and stakeholder management skills.

  • Fluent English skills; German is an advantage.

What’s on Offer?

  • A high-impact Second Line role with organisation-wide visibility.

  • Opportunity to shape cloud security governance and risk oversight.

  • Collaboration with technical and risk teams in a modern cloud-driven environment.

  • Long-term development within a strategically important security function.

Weitere Stellenangebote dieses Personalvermittlers

German wide, Baden-Württemberg

Director Cyber Security

Director, Cyber Security Consulting Die Chance Bereit für eine Rolle, in der Ihr Name wirklich zählt, statt im Organigramm unterzugehen? Dies ist eine Director-Position mit echtem Gewicht: die Chance, eine Cyber-Security-Practice zu gestalten, Kundenbeziehungen selbst zu verantworten und Entscheidungen zu treffen, die wirklich etwas bewegen. Wenn Sie als Senior Consultant seit Jahren die Arbeit machen, aber nicht die Plattform dafür bekommen, ist das hier lesenswert. Die Aufgaben Sie leiten komplexe Cyber-Security-Beratungsprojekte in Deutschland und arbeiten mit Kunden aus verschiedenen Branchen zu Strategie, Risiko, Architektur und Programmsteuerung. Auf Director-Ebene bedeutet das ebenso viel Business Development wie Delivery: Beziehungen aufbauen, Chancen erkennen und Mandate gewinnen sowie umsetzen. Sie sind eine sichtbare Persönlichkeit im Markt, vertreten die Practice nach außen und entwickeln die Consultants um Sie herum intern weiter. Vielfalt ist garantiert: Kein Mandat gleicht dem anderen, und die Arbeit deckt das gesamte Spektrum der Cyber-Security-Beratung ab. Das Unternehmen Unser Mandant ist ein spezialisiertes Beratungsunternehmen mit einer starken Präsenz im deutschen Markt, bekannt für die Qualität seiner Beratungsarbeit und das Kaliber seiner Mitarbeiter. Dies ist kein Unternehmen, in dem Directors ihre Zeit mit PowerPoint-Verwaltung verbringen. Das Umfeld ist dynamisch, kollegial und für Menschen gemacht, die in ihrem Bereich wirklich Experten sind. Ihr Profil Umfangreiche Erfahrung in der Cyber-Security-Beratung mit nachgewiesener Erfolgsbilanz auf Senior-Ebene Nachgewiesene Fähigkeit, Business-Development-Chancen zu entwickeln und zu konvertieren Tiefe Kenntnis des deutschen Marktes und der Cyber-Security-Landschaft Muttersprachliches oder nahezu muttersprachliches Deutsch sowie sehr gutes Englisch Glaubwürdigkeit gegenüber C-Suite-Stakeholdern und die Sicherheit, voranzugehen Bewerbung Schicken Sie Ihren Lebenslauf an das Team von MAM Gruppe. Er muss nicht aktuell sein. Schicken Sie, was Sie haben, oder nehmen Sie einfach Kontakt für ein erstes Gespräch auf.
Weitere Informationen
Prague, Jihoceský kraj

ICT Risk Manager

ICT Risk Manager Location: Prague / Hybrid Our client is seeking an ICT Risk Manager to join a Second Line of Defence function, supporting technology risk governance, oversight and regulatory compliance activities within a regulated environment. Key Responsibilities: Provide independent oversight of ICT, cyber and technology-related risks. Review and challenge risk assessments, controls and remediation activities. Support the development and enhancement of ICT risk frameworks and governance processes. Monitor technology, security, outsourcing and operational resilience risks. Contribute to regulatory compliance and risk reporting activities. Support third-party and vendor risk oversight initiatives. Collaborate with stakeholders across risk, technology, security and business functions. Your Profile: Several years of experience within ICT risk, technology risk, cyber risk or operational risk environments. Understanding of risk governance and Second Line of Defence responsibilities. Experience within banking, financial services or another regulated environment. Knowledge of ICT risk management, operational resilience and regulatory frameworks. Strong analytical, communication and stakeholder management skills. Relevant certifications such as CRISC, CISA or CISSP would be advantageous. Fluent English language skills. What’s on Offer? Opportunity to work within an international and regulated environment. Exposure to technology risk, resilience and governance initiatives. Flexible hybrid working model. Long-term development and progression opportunities.
Weitere Informationen
Prague, Jihomoravský kraj

Director - ICT Security Reporting

Director, ICT Risk and Security Reporting Most technology risk reporting roles exist to document what's already happened. This one exists to shape what happens next. The Opportunity This is a newly created Director-level position within the Risk function of one of Europe's leading international banks. You'll be joining at the point where the function is being built, not inherited, which means you'll have genuine influence over how ICT risk and security reporting is structured, governed, and matured from the ground up. The regulatory environment is as complex as it gets right now: DORA is live, EBA ICT guidelines are evolving, and banks are under real scrutiny on operational resilience. You'll be working at the centre of all of it, translating technical and cyber risk into intelligence that drives decisions at board and executive level. Critically, this isn't a back-seat reporting role. You'll be expected to challenge the first line, push back where data quality or risk transparency falls short, and bring an architectural view of technology risk that goes beyond compliance checklists. The business wants someone with enough credibility and backbone to be genuinely heard. There is a clear path upward for the right person. This is a role you can grow into a broader leadership position, in a bank that operates at international scale. The Role Own and evolve the ICT Risk and Security reporting framework across the bank Deliver board-level, executive, and risk committee reporting on technology and cyber risk Translate complex technical and security risk data into clear, actionable business narratives Develop risk metrics, KRIs, dashboards, and management information across ICT and cyber domains Identify emerging risks and systemic themes across technology, cyber, resilience, and third-party environments Challenge the first line on data quality, risk transparency, and governance consistency Support regulatory and governance obligations including DORA and EBA ICT guidelines Drive continuous improvement in reporting automation, data visualisation, and risk analytics Partner with senior stakeholders across Technology, Cyber Security, Risk, Compliance, and Internal Audit What You'll Need Significant experience in ICT Risk, Technology Risk, Cyber Risk, or Information Security Governance, ideally within banking or regulated financial services An architectural view of technology risk, with the ability to identify systemic issues, not just point-in-time findings Proven experience producing board-facing or executive-level risk reporting Strong working knowledge of DORA, EBA ICT guidelines, and operational resilience frameworks The credibility and confidence to challenge senior stakeholders and first-line teams Exceptional ability to communicate complex risk information clearly to non-technical audiences Relevant certifications such as CISA, CRISC, CISSP, or CGEIT are advantageous Fluent English required What's on Offer Competitive compensation package commensurate with Director-level seniority Company pension scheme and comprehensive risk coverage including accident insurance Car leasing and bike leasing schemes with tax advantages IT device leasing for personal use Hybrid working model based in Prague Clear scope for progression within an international banking group How to Apply Apply via the link below. Your CV doesn't need to be perfect, send what you have and we'll take it from there. If you'd prefer a conversation before committing to anything, just give us a call.
Weitere Informationen
Frankfurt, Hessen

Senior Manager Information Security

Senior Manager Information Security - Second Line of Defence Location: Frankfurt / Hybrid Our client is seeking a Senior Manager Information Security to support security governance, risk oversight and regulatory compliance activities within a highly regulated environment. This role sits within the Second Line of Defence and focuses on strengthening information security frameworks, controls and oversight processes across the organisation. Key Responsibilities: Support and oversee information security governance and risk management activities. Provide independent oversight and challenge of security controls and risk practices. Maintain and enhance security policies, standards and governance frameworks. Support risk assessments, control reviews and remediation activities. Collaborate with technology, risk, audit and compliance stakeholders. Monitor regulatory developments, emerging threats and security-related risks. Prepare reporting and presentations for senior stakeholders and governance committees. Contribute to operational resilience and third-party security oversight initiatives. Your Profile: Extensive experience within information security, cyber risk or technology risk environments. Strong background in security governance, risk oversight or Second Line of Defence functions. Understanding of regulatory frameworks and security standards within regulated environments. Knowledge of information security controls, operational resilience and cloud security governance. Strong stakeholder management and communication skills. Relevant certifications such as CISSP, CISM or CRISC would be advantageous. Fluent German and English language skills. What’s on Offer? Senior-level role within a complex and regulated environment. Exposure to security governance and risk management initiatives. Flexible hybrid working model. Long-term development and progression opportunities.
Weitere Informationen

Neueste Blogs

Alle Blogs anzeigen