Manager ICT Third Party Risk

MAM Gruppe

Frankfurt

Vor Ort

EUR 90.000 - 120.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

MAM Gruppe in Frankfurt is seeking a Manager ICT & Information Security Third Party Risk for its 2nd Line of Defence. You will independently assess and challenge the security and technology risks posed by external providers, aligning with regulatory requirements.

The role collaborates with Information Security, IT, Procurement and Risk committees to ensure third parties meet DORA, NIS2, ISO 27001 and MaRisk standards, and to prepare risk reporting for senior management.

Qualifikationen

  • Several years of experience in Information Security, ICT, Third Party or Cyber Risk.
  • 2nd Line of Defence experience is highly desirable; banking/financial services experience advantageous.
  • Knowledge of TPRM processes and third-party security assessments.
  • Familiarity with ISO 27001, DORA, NIS2 and EBA requirements.

Aufgaben

  • Independently review and challenge Information Security and ICT risk assessments for third-party providers.
  • Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners.
  • Challenge the 1st Line on identified risks, controls, remediation and risk acceptance.
  • Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience.
  • Support the TPRM and Information Security Risk frameworks.
  • Monitor third-party incidents, vulnerabilities, control weaknesses and remediation.
  • Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk.
  • Prepare risk reporting for senior management and risk committees.
  • Support internal audits and regulatory assessments.

Kenntnisse

Information Security
ICT
Third Party Risk
Cyber Risk
Risk Management
Stakeholder Communication

Jobbeschreibung

Manager ICT & Information Security Third Party Risk – 2nd Line of Defence | Frankfurt

Our client, a banking organisation in Frankfurt, is seeking a Manager ICT & Information Security Third Party Risk for its 2nd Line of Defence. The role covers independently assessing and challenging the security and technology risks posed by external providers, working closely with Information Security, IT, Procurement, Operational Risk and senior stakeholders to ensure third parties meet the organisation's security, risk and regulatory requirements.

The role:
  • Independently review and challenge Information Security and ICT risk assessments for third-party providers.
  • Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners.
  • Challenge the 1st Line on identified risks, controls, remediation and risk acceptance.
  • Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience.
  • Support the TPRM and Information Security Risk frameworks.
  • Monitor third-party incidents, vulnerabilities, control weaknesses and remediation.
  • Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk.
  • Prepare risk reporting for senior management and risk committees.
  • Support internal audits and regulatory assessments.
What you'll need:
  • Several years' experience in Information Security, ICT, Third Party or Cyber Risk.
  • 2nd Line of Defence experience highly desirable; banking/financial services experience advantageous.
  • Knowledge of TPRM processes and third-party security assessments.
  • Familiarity with ISO 27001, DORA, NIS2 and EBA requirements.
  • Knowledge of cloud security, IAM, vulnerability and incident management, and cyber resilience.
  • Ability to independently challenge the 1st Line and communicate risk to senior stakeholders.
  • Fluent German and English.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d)
Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d)

Deutsche Börse Group • Frankfurt

Vor Ort
EUR 90.000 - 120.000
ICT Risk Solution Architect (f/m/d)
ICT Risk Solution Architect (f/m/d)

Deutsche Börse Group • Frankfurt

Vor Ort
EUR 90.000 - 120.000
CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)
CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)

360T • Frankfurt

Vor Ort
EUR 90.000 - 130.000
Established security organization and
360T Academy
Offices located directly in the city •
ICT Risk Governance Specialist (f/m/d)
ICT Risk Governance Specialist (f/m/d)

Deutsche Börse AG • Eschborn

Hybrid
EUR 70.000 - 100.000
Enterprise Risk Manager (m/f/d)
Enterprise Risk Manager (m/f/d)

Selby Jennings • Frankfurt

Vor Ort
EUR 90.000 - 150.000
Security Incident Manager - ICT Risk Department
Security Incident Manager - ICT Risk Department

MAM Gruppe • Frankfurt

Hybrid
EUR 70.000 - 90.000
Competitive compensation package
Performance-based bonus
Work-life balance
+1
Head of Third Party Governance
Head of Third Party Governance

JCW Group • Berlin

Vor Ort
EUR 70.000 - 90.000
Cyber Risk Manager
Cyber Risk Manager

MAM Gruppe • Bayern

Hybrid
EUR 60.000 - 80.000
Flexible working model
Inclusive work culture
Career development opportunities
+3
Senior IT Risk Manager
Senior IT Risk Manager

Barclay Simpson • Frankfurt

Hybrid
EUR 120.000 - 180.000
Third Party Risk Management Product Owner (m/f/x)
Third Party Risk Management Product Owner (m/f/x)

Liebherr-IT Services GmbH • Kirchdorf an der Iller

Hybrid
EUR 90.000 - 120.000
Attraktive Vergütung und Sozialleistungen
Flexibles und hybrides Arbeiten
Betriebliche Altersvorsorge
+2