Your Role
As Deputy Cyber & Information Security and ICT Risk, you support the oversight and further development of 360T’s Cyber & Information Security and ICT Risk framework.
In this Second Line of Defense role, you provide independent oversight, challenge and advice while supporting operational and regulatory excellence across the 360T Group. You act as a deputy to the responsible function lead and provide support and coverage across key governance, risk and oversight activities.
Our approach is based on full compliance in both word and spirit, continuous assessment of regulatory, legal and technological developments, constructive engagement with regulators and market participants, and the conviction that operational and regulatory excellence is a key competitive advantage.Your Responsibilities
Strategy & Governance- Support the development and continuous enhancement of the Group’s Cyber & Information Security and ICT Risk strategy, policies and oversight framework in alignment with 360T’s business strategy.
- Help ensure alignment with applicable legal and regulatory requirements, established standards and relevant industry best practices.
- Support the translation of regulatory requirements, business objectives and risk considerations into appropriate governance and oversight measures.
- Contribute to regular reporting to Management and relevant governance bodies on the risk profile, First Line roadmaps, control environment, testing activities and significant incidents.
- Deputize for the responsible function lead in relevant committees, meetings and governance activities as required.
- Identify and assess emerging ICT and cyber risks and recommend appropriate mitigation, challenge or escalation.
Organization & Risk Oversight
- Support the oversight of the Information Security Management System (ISMS), related policies and governance processes through which the First Line implements the security and ICT risk strategy.
- Support the governance and ongoing operation of the Global ICT Risk and Security Committee.
- Perform independent Second Line monitoring and reviews of relevant processes, systems and controls to assess their adequacy and effectiveness, while operational ownership remains with the First Line.
- Act as an interface to the Group Risk Management framework and contribute to the consistent identification, assessment, monitoring and reporting of ICT and cyber risks.
- Support awareness of Cyber & Information Security and ICT Risk topics across the Group and provide subject-matter expertise for relevant training and awareness initiatives.
- Engage with industry peers, interest groups and external experts to monitor developments and relevant market practices.
- Oversee and challenge incident management, disaster recovery and business continuity readiness from a Second Line perspective, including monitoring post-incident remediation and compliance with regulatory notification requirements.
- Advisory & Challenge
- Provide independent advice to Management and stakeholders on Cyber & Information Security and ICT Risk matters.
- Support the Management Board in defining and evolving relevant policies and risk requirements.
- Help assess and resolve potential conflicts between business objectives, operational requirements and information security considerations.
- Define and maintain appropriate risk and control criteria and provide Second Line requirements, including for physical security where relevant.
- Act as an internal subject-matter expert while maintaining independence from operational First Line responsibilities.
- Recommend appropriate controls and risk mitigation measures and independently monitor their implementation.
- Advise and challenge stakeholders on ICT and security requirements relating to new systems, software, outsourcing arrangements and material changes.
- Support oversight of the ICT third-party risk framework, including due diligence standards, criticality assessments, concentration risks and exit considerations, and independently challenge First Line assessments and outcomes.
- Review and challenge disaster recovery and business continuity arrangements for adequacy and alignment with 360T’s risk appetite and applicable regulatory requirements.
Testing & Assurance
- Support oversight of Cyber & Information Security and ICT Risk testing activities, including compliance testing, control assessments, evaluations and certifications.
- Conduct independent Second Line reviews of relevant technical, organizational and physical security measures.
- Assess identified weaknesses and remediation activities and escalate material risks or deficiencies where appropriate.
- Contribute to the continuous improvement of the Cyber & Information Security and ICT Risk control and assurance framework.
Your Profile
- Professional experience in Cyber Security, Information Security, ICT Risk, Technology Risk, IT Governance or a comparable risk and control function, ideally within a regulated financial-services environment.
- Good understanding of information security and ICT risk management frameworks, governance models and internal control systems.
- Familiarity with relevant regulatory requirements and industry standards affecting financial institutions and technology-driven financial-market infrastructures.
- Experience with risk assessments, control reviews, incident oversight, third-party risk, business continuity and/or disaster recovery is an advantage.
- Ability to independently assess and challenge risks and controls while working constructively with First Line stakeholders.
- Strong analytical and communication skills with the ability to translate complex technical and regulatory topics into clear risk-based recommendations.
- Confidence in communicating with senior management and stakeholders across technical, business, risk and compliance functions.
- A structured, pragmatic and solution-oriented approach combined with a high degree of integrity and sound professional judgment.
- Very good command of English; German language skills are an advantage.
Our Offer
- Established and certified security organization and culture, stable and growing multinational company
- Regular performance appraisals, close interaction with all business functions and management
- Growth, development, and learning opportunities, including our internal „360T Academy“
- Offices located directly in the city center
- Multinational and multicultural environment, social gatherings and activities
How to Apply
If your background and qualifications meet these specifications, please forward your application including your salary expectation, earliest starting date by clicking the “Apply” button.
Contact
Irune Del Buey
People & Culture Manager
Send email
Grüneburgweg 16-18
60322 Frankfurt am Main
