Who we are. What drives us. Where we're headed.
Have you gained some initial professional experience in information security and are now ready to take the next step? Take on more responsibility, gain a comprehensive understanding of information security, and further your professional development?
As a Junior Information Security Officer - GRC, you'll work closely with our CISO and gain broad insight into a bank’s information security. We don't expect you to know everything yet: a solid foundation, curiosity, and the desire to grow are what matter most to us.
Hamburg | Hybrid working with face-to-face interaction in the office (2 to 3 times a week)
YOUR RESPONSIBILITIES:
- Contributing to the further development and continuous improvement of our Information Security Management System (ISMS) and gradually taking on your own areas of responsibility
- Supporting the implementation of regulatory requirements and standards, particularly DORA, MaRisk, ISO 27001, and other relevant supervisory guidelines
- Planning, supporting, and tracking internal and external audits, as well as managing the resolution of findings and corrective actions
- Contributing to risk analyses, assessments of protection needs, and security and control evaluations
- Supporting the evaluation of ICT projects, cloud solutions, outsourcing initiatives, and new technologies from an information security perspective
- Further developing policies, processes, and security guidelines
- Working closely with, among others, IT, Risk Management, Compliance, Internal Audit, as well as external auditors and service providers
- Gradually taking on your own areas of responsibility and projects
YOUR PROFILE:
- Successfully completed (dual) degree in (Business) Computer Science, Business Law, IT Security, or a comparable qualification
- 1 to 2 years of relevant professional experience in the areas of Information Security, IT Risk, GRC, or IT Audit
- Initial practical experience with ISMS, information security risks, controls, audits, or regulatory requirements
- Good knowledge of regulatory requirements and standards such as DORA, MaRisk, ISO 27001, NIS2, or comparable frameworks
- Excellent written and spoken German and English skills
- Ability to communicate regulatory and security-related requirements in a pragmatic manner tailored to the audience
- Analytical and structured thinking, as well as a meticulous approach to work
- Initiative, a willingness to learn, and enthusiasm for familiarizing yourself with new topics
YOUR BENEFITS:
- Hybrid working model with flexible use of mobile working - you decide (from) where you work.
- 20 days of workation in another European country.
- Longing for your colleagues? Then we offer you attractive offices in an excellent location with a great view of the Elbe, including a gym and gaming room, height-adjustable desks, laptop bars and much more.
- You will enjoy 30 days of vacation per year and have the 24.12. and 31.12. off all day.
- Wherever you are - do unlimited sport throughout Germany with our partner EGYM Wellpass.
- Whether by e-bike, cargo bike or classic bike - with your leased company bike, you are environmentally friendly on the road.
- And when the weather is bad in Hamburg, you can use your Germany-wide job ticket, which we subsidize.
- We also take out supplementary insurance for preventive check-ups and dental treatment for you.
- A corporate culture that promotes personal development and combines the energy and innovation of a FinTech with the business orientation of a bank.