Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist GmbH

Deutschland

Hybrid

EUR 90.000 - 120.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid work model
Personal growth budget
Semi-annual feedback

Zusammenfassung

Qwist GmbH is seeking an Information Security Manager (m/f/d) to own the ISMS under ISO 27001 and lead ICT risk management under DORA. You will work with Engineering, Platform and Legal to embed security into development and ensure audit readiness.

You will report to the Management Board and drive risk classification, incident handling, third-party risk oversight and security awareness across the company.

Qualifikationen

  • Proven ISO 27001 ISMS ownership and ongoing compliance.
  • Experience collaborating with software engineering, product or DevOps teams.
  • Excellent German and English communication for technical and non-technical audiences.
  • Hands-on knowledge of DORA and related frameworks (MaRisk or similar).

Aufgaben

  • Own ICT risk management function under DORA, classify incidents and oversee reporting.
  • Develop and maintain ISMS in line with ISO 27001 and prepare audits.
  • Own audit evidence and coordinate internal and external audits.
  • Embed security into development processes with Engineering & Platform teams.
  • Support business continuity planning and disaster recovery activities.

Kenntnisse

ISO 27001 ISMS
DORA knowledge
Audits coordination
DevOps collaboration
Penetration testing
German-English
ICT risk management
Regulatory compliance

Ausbildung

Information security degree
Computer science degree
Law/compliance degree

Jobbeschreibung

Your Role

You don't just want to manage information security and ICT risk but you want to drive it? As Information Security Manager (m/f/d) you own our ISMS under ISO 27001 and hold the ICT Risk Management Function under DORA from risk assessment to ICT incident classification and third-party risk oversight. You work closely with Engineering and Platform to embed security directly into our development processes, and you're the central point of contact for internal and external audits. You report directly to the Management Board and work closely with our Chief Legal Officer. We're not looking for administrators, but people who take ownership and want to grow with us.

What You'll Do
  • ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments – including preparing and steering certification and surveillance audits.
  • Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Security Operations: Initiate penetration tests, run security incident response from triage through post-incident review, and strengthen security awareness across the company through training and workshops.
What You Bring
  • A degree in information security, computer science, law/compliance or a comparable qualification, plus relevant professional experience in information security and ICT risk management.
  • Solid hands‑on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities.
  • Experience working directly with software engineering, product or DevOps teams in a technology‑led environment.
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is explicitly welcome – we'll support you in becoming an expert here.
  • A strong hands‑on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment.
  • Confident communication in German and English, with both technical and non‑technical audiences.
What we offer
  • Impact & Ownership: Direct reporting lines to C-level and an environment where your ownership is valued and strengthened.
  • Flexibility: A modern, hybrid working model across our Berlin and Munich locations.We work in a hybrid setup, with a strong focus on teamwork and efficient collaboration.
  • Personal growth: We support your development with a personal budget, semi‑annual feedback, and clear growth paths.
  • Pioneering spirit: Become part of a team with genuine passion for the future of open banking.
Diversity is welcome!

Don't tick every single box? At Qwist we value diverse perspectives and experiences. If you're excited about this role but your background doesn't perfectly match every point, we encourage you to apply anyway. You might be exactly who we're looking for!

Qwist is proud to be an equal‑opportunity employer that values diversity. We do not discriminate on the basis of race, religion, ethnic or national origin, gender identity, sexual orientation, age, marital status, or disability status.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Remotely • Berlin

Hybrid
EUR 90.000 - 130.000
Impact & Ownership
Hybrid work model across Berlin andMun
Personal growth budget
+1
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist • Berlin

Hybrid
EUR 90.000 - 120.000
Hybrid work model
Personal development budget
Clear growth paths
Information Security Manager (m/f/d) - Ownership in Open Finance
Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist GmbH • Berlin

Hybrid
EUR 90.000 - 130.000
Impact & Ownership
Flexibility - Hybrid
Personal growth
+1
Information Security Officer (m/f/d)
Information Security Officer (m/f/d)

Idealworks • München

Hybrid
EUR 70.000 - 110.000
Hybrid working model
30 vacation days
Bonus scheme
+4
Information Security Manager (f/d/m)
Information Security Manager (f/d/m)

synetics Gesellschaft für Systemintegration mbH • Deutschland

Hybrid
EUR 90.000 - 130.000
Remote-first
ICT Risk Assessment Manager
ICT Risk Assessment Manager

N26 • Berlin

Vor Ort
EUR 90.000 - 140.000
Work from home budget
Relocation package with visa support
Premium N26 subscription
Information Security Specialist (m/f/d)
Information Security Specialist (m/f/d)

And E • Ismaning

Vor Ort
EUR 70.000 - 110.000
32 days annual leave
Flexible working hours
Home office policy
ICT GRC – Risk & Compliance Manager
ICT GRC – Risk & Compliance Manager

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 135.000
Dev budget
Work from home budget
Wellness discounts
+5
ICT GRC – Risk & Compliance Manager Berlin
ICT GRC – Risk & Compliance Manager Berlin

N26 • Berlin

Hybrid
EUR 90.000 - 120.000
Personal development budget
Work from home budget
Fitness & wellness discounts
+3
Information Security Manager (gn)
Information Security Manager (gn)

i-doit Group • Düsseldorf

Hybrid
EUR 90.000 - 130.000
Remote-first
Flexible hours
Team events
+2