Information Security Manager (m/f/d) - Ownership in Open Finance

Remotely

Berlin

Hybrid

EUR 90.000 - 130.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Impact & Ownership
Hybrid work model across Berlin andMun
Personal growth budget
Open banking culture & team

Zusammenfassung

Qwist seeks an Information Security Manager to own the ISMS under ISO 27001 and manage the ICT risk function under DORA. You will classify ICT incidents, drive risk framing, and oversee third-party risk, reporting to the Management Board.

You'll partner with Engineering, Platform and DevOps to embed security into development, support business continuity, and lead internal and external audits. Fluency in German and English is essential.

Qualifikationen

  • A degree in information security, computer science, law/compliance or a comparable qualification.
  • Solid hands-on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities.
  • Experience working directly with software engineering, product or DevOps teams in a technology-led environment.
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is welcome -- we'll support you in becoming an expert here.
  • A strong hands-on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment.
  • Confident communication in German and English, with both technical and non-technical audiences.

Aufgaben

  • ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments -- including preparing and steering certification and surveillance audits.
  • Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Security Operations: Initiate penetration tests, run security incident response from triage through post‑incident review, and strengthen security awareness across the company through training and workshops.

Kenntnisse

Information security
ICT risk management
Audits
Security operations
Stakeholder management
German & English communication

Ausbildung

Degree in information security, computer science, law/compliance

Tools

ISO 27001 ISMS
DORA framework

Jobbeschreibung

Your Role

You don't just want to manage information security and ICT risk but you want to drive it? As Information Security Manager (m/f/d) you own our ISMS under ISO 27001 and hold the ICT Risk Management Function under DORA from risk assessment to ICT incident classification and third-party risk oversight. You work closely with Engineering and Platform to embed security directly into our development processes, and you're the central point of contact for internal and external audits. You report directly to the Management Board and work closely with our Chief Legal Officer. We're not looking for administrators, but people who take ownership and want to grow with us.

What You'll Do
  • ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments -- including preparing and steering certification and surveillance audits.
  • Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Security Operations: Initiate penetration tests, run security incident response from triage through post‑incident review, and strengthen security awareness across the company through training and workshops.
What You Bring
  • A degree in information security, computer science, law/compliance or a comparable qualification, plus relevant professional experience in information security and ICT risk management
  • Solid hands‑on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities
  • Experience working directly with software engineering, product or DevOps teams in a technology‑led environment
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is explicitly welcome -- we'll support you in becoming an expert here
  • A strong hands‑on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment
  • Confident communication in German and English, with both technical and non‑technical audiences
What We Offer
  • Impact & Ownership: Direct reporting lines to C-level and an environment where your ownership is valued and strengthened.
  • Flexibility: A modern, hybrid working model across our Berlin and Munich locations. We work in a hybrid setup, with a strong focus on teamwork and efficient collaboration.
  • Personal growth: We support your development with a personal budget, semi‑annual feedback, and clear growth paths.
  • Pioneering spirit: Become part of a team with genuine passion for the future of open banking.

Diversity is welcome! Don't tick every single box? At Qwist we value diverse perspectives and experiences. If you're excited about this role but your background doesn't perfectly match every point, we encourage you to apply anyway. You might be exactly who we're looking for!

Qwist is proud to be an equal‑opportunity employer that values diversity. We do not discriminate on the basis of race, religion, ethnic or national origin, gender identity, sexual orientation, age, marital status, or disability status.

About Us

Qwist is a leader in Open Finance, helping organizations unlock, analyze, and leverage financial data. With 100 employees across Europe and more than 100 clients -- including leading banks, insurers, and automotive platforms -- we provide regulated, secure access to 99% of all bank accounts in the DACH region and beyond.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist • Berlin

Hybrid
EUR 90.000 - 120.000
Hybrid work model
Personal development budget
Clear growth paths
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist GmbH • Deutschland

Hybrid
EUR 90.000 - 120.000
Hybrid work model
Personal growth budget
Semi-annual feedback
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist GmbH • Berlin

Hybrid
EUR 90.000 - 130.000
Impact & Ownership
Flexibility - Hybrid
Personal growth
+1
ICT Risk Assessment Manager
ICT Risk Assessment Manager

N26 • Berlin

Vor Ort
EUR 90.000 - 140.000
Work from home budget
Relocation package with visa support
Premium N26 subscription
Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

Idealworks • München

Hybrid
EUR 70.000 - 110.000
Hybrid working model
30 vacation days
Bonus scheme
+4
Information Security Manager (f/d/m)
Information Security Manager (f/d/m)

synetics Gesellschaft für Systemintegration mbH • Deutschland

Hybrid
EUR 90.000 - 130.000
Remote-first
Senior Key Account Manager – SaaS (m/w/d)
Senior Key Account Manager – SaaS (m/w/d)

Qwist • Berlin

Hybrid
EUR 70.000 - 90.000
Flexible Arbeitszeitgestaltung
30 Urlaubstage pro Jahr
Budget für persönliche Weiterentwicklung
+2
ICT GRC – Risk & Compliance Manager
ICT GRC – Risk & Compliance Manager

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 135.000
Dev budget
Work from home budget
Wellness discounts
+5
ICT GRC – Risk & Compliance Manager Berlin
ICT GRC – Risk & Compliance Manager Berlin

N26 • Berlin

Hybrid
EUR 90.000 - 120.000
Personal development budget
Work from home budget
Fitness & wellness discounts
+3
Information Security Specialist (m/f/d)
Information Security Specialist (m/f/d)

And E • Ismaning

Vor Ort
EUR 70.000 - 110.000
32 days annual leave
Flexible working hours
Home office policy