Technology Risk & Security Manager (m/f/d)

Cornerstone OnDemand Ltd.

Deutschland

Vor Ort

EUR 90.000 - 150.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid working
Wellbeing support
Training programs (LinkedIn Learning)

Zusammenfassung

Simon-Kucher is a global consultancy seeking a Technology Risk & Security Manager to bridge business demand, IT architecture, cybersecurity, and governance across major German offices. You will assess security, compliance, and operational risks for new technologies and AI-enabled solutions and present findings to IT leadership.

The role requires 5+ years in technology risk or cybersecurity and a strong background in ISO 27001, SOC 2, and cloud security.

Qualifikationen

  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.

Aufgaben

  • Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.

Kenntnisse

Cybersecurity
IT governance
GRC
Security architecture
Vendor risk management
Stakeholder management
Executive presentations
ISO 27001
SOC 2
Cloud security

Ausbildung

Bachelor's Degree

Tools

ISO 27001 Lead Implementer/Auditor
ITIL
GRC tools

Jobbeschreibung

Technology Risk & Security Manager (m/f/d)
In Germany - Berlin| Bonn | Cologne| Frankfurt/Main | Hamburg | Munich

This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating withinthe company’s Technology Demand Intake Process, which is closely connected toimplementation and lifecycle governance.

This individual will focus on reviewing technical concepts, stand‑aloneproducts, services, and AI-enabled solutions that the company plans toimplement or integrate into its complex global enterprise technology landscape,including SaaS, PaaS, SAP, and AI-enabled platforms.

You will be responsible for assessing and governing new technology demands,services, platforms, and AI-enabled solutions through the organization’stechnology intake process. The role ensures that security, compliance, architecture, operational, andbusiness risks are identified, clearly documented, and addressed througheffective and practical mitigation measures.

What makes us special:
  • Advance your career with exciting professional opportunities in our thriving company with a startup feel.
  • Voice your unique ideas in a corporate culture defined by openness and integrity.
  • Enjoy the opportunity to work from abroad (workation).
  • Feel at home working with our helpful, enthusiastic colleagues who have great team spirit.
  • Broaden your perspective with our extensive training curriculum and learning programs (e.g. LinkedIn Learning).
  • Speak your mind in our holistic feedback and development processes (e.g. 360-degree feedback).
  • Satisfy your need for adventure with our opportunities to live and work abroad in one of our many international offices
  • Enjoy our benefits, such as hybrid working, daycare allowance, corporate discounts, and wellbeing support (e.g. Headspace).
  • Unwind in our break areas where you can help yourself to the healthy snacks and beverages provided.
  • See another side of your coworkers at our frequent employee events and highly anticipated World Meeting and Holiday Party.
How you will create an impact:
  • Manage theend-to-end Technology Demand Intake and Risk Assessment process for newtechnologies, platforms, tools, and AI-enabled solutions.
  • Assess security,compliance, operational, vendor, and architecture risks; identifymitigation strategies and recommend risk treatment decisions.
  • Prepareexecutive-ready reports and present findings to IT leadership, governanceboards, and risk committees.
  • Partner withSecurity, IT, Architecture, Procurement, Legal, Privacy, Audit, andbusiness stakeholders to evaluate and approve technology solutions.
  • Ensure newtechnologies comply with security policies, controls, and integrationrequirements.
  • Maintain riskdocumentation, exception records, control evidence, and governancereporting while continuously improving intake processes.
  • Stay current onemerging technologies, AI, cybersecurity trends, regulatory requirements,and industry control frameworks.
  • Translatebusiness requirements into security and compliance recommendations thatenable timely technology decisions.
  • Communicatecomplex technical concepts through presentations, decision papers, andexecutive-facing materials.
  • Facilitatecollaboration across IT architecture, infrastructure, business teams,vendors, and other stakeholders.
  • Support vendorassessments, RFPs, technical evaluations, and solution reviews.
  • Contribute tocross-functional IT projects by identifying dependencies, risks, andprocess improvements.
  • Work effectivelyin agile, global project environments with multiple priorities and tighttimelines.
About you:
  • Experience inacomplexglobal environment, comparable consulting or serviceindustries is preferred.
  • Bachelor’sDegree required – preferred in the area of Technology, MIS, Cybersecurity,etc.
  • 5+ years ofexperience in technology risk, cybersecurity, IT governance, GRC, ITaudit, security architecture, or technology consulting.
  • Strong knowledgeof cybersecurity, technology risk management, compliance, enterprise ITgovernance, and emerging AI-enabled technologies.
  • Experienceassessing SaaS, cloud, third-party, and AI-enabled solutions, with theability to identify risks, mitigation strategies, and implementationrequirements.
  • Experienceimproving governance processes, workflows, standards, and risk managementpractices.
  • Knowledgeofsecurity and governance frameworks such as ISO 27001, SOC 2, ITIL, orsimilar.
  • Experience withsecurity controls, risk assessments, compliance, audit support, andgovernance approval processes.
  • Ability toevaluate platform architecture, integrations, identity and accessmanagement, data flows, encryption, logging, monitoring, and operationalsecurity.
  • Understanding ofenterprise architecture, cloud security, vendor risk management, andsecure technology implementation.
  • Strongstakeholder management skills with experience working across IT, Security,Architecture, Compliance, Privacy, Legal, Procurement, Audit, and businessteams.
  • Experience preparing executive-level presentations, risk reports, and decision-readydocumentation, and presenting recommendations to senior leadership.
  • Experience evaluating third-party vendors, cloud platforms, SaaS solutions, andmanaged services within global IT environments.
  • Experiencesupporting technology onboarding, vendor risk assessments, procurement,RFPs, and cross-functional technology initiatives.
  • Ability to manage risks, remediation activities, project dependencies, andimplementation progress across the technology lifecycle.
  • CISSP, CISM,CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalentcertification (or comparable hands‑on experience).
About Simon‑Kucher

Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. As a trusted commercial advisor focused on unlocking better growth, we combine deep consulting expertise, growth specialization, and technology to scale lasting impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value. With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist. simon‑kucher.com

We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.

Better growth starts here. With you.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Technology Risk & Security Manager (m/f/d)
Technology Risk & Security Manager (m/f/d)

Simon-Kucher • Bonn

Hybrid
EUR 90.000 - 120.000
Hybrid working
Daycare allowance
Corporate discounts
+1
Senior Manager, Information Compliance - Privacy & AI Governance (m/f/d)
Senior Manager, Information Compliance - Privacy & AI Governance (m/f/d)

Simon-Kucher • Hamburg

Hybrid
EUR 90.000 - 140.000
Hybrid working
Daycare allowance
Corporate discounts
+1
Senior Manager, Information Compliance - Privacy & AI Governance (m/f/d)
Senior Manager, Information Compliance - Privacy & AI Governance (m/f/d)

Simon-Kucher • Bonn

Hybrid
EUR 90.000 - 130.000
Hybrid working
Daycare allowance
Corporate discounts
+1
(Senior) Manager Technology & Industrials (m/f/d)
(Senior) Manager Technology & Industrials (m/f/d)

Cornerstone OnDemand Ltd. • Berlin

Hybrid
EUR 90.000 - 130.000
Hybrid working
Daycare allowance
Corporate discounts
+1
SAPS/4 Data Migration Consultant (m/w/d)
SAPS/4 Data Migration Consultant (m/w/d)

ITL Germany • Hamburg

Hybrid
EUR 120.000 - 170.000
Hybrid working
Daycare allowance
Corporate discounts
+1
AI Enablement Manager (m/w/d)
AI Enablement Manager (m/w/d)

Cornerstone OnDemand Ltd. • Berlin

Hybrid
EUR 90.000 - 120.000
Hybrid working
Daycare allowance
Corporate discounts
+1
Lead Software Engineer - Cloud & Data Platforms (m/f/d)
Lead Software Engineer - Cloud & Data Platforms (m/f/d)

Cornerstone OnDemand Ltd. • Deutschland

Hybrid
EUR 120.000 - 160.000
Hybrid work model
Training programs
Wellbeing support
(Senior) Manager - Insurance (m/w/d)
(Senior) Manager - Insurance (m/w/d)

Simon-Kucher • Köln

Vor Ort
EUR 120.000 - 180.000
Hybrid working
Daycare allowance
Corporate discounts
+1
(Senior) Manager - Insurance (m/w/d)
(Senior) Manager - Insurance (m/w/d)

Simon-Kucher • Hamburg

Hybrid
EUR 120.000 - 180.000
Hybrid working
Daycare allowance
Wellbeing support
(Senior) Manager - Insurance (m/w/d)
(Senior) Manager - Insurance (m/w/d)

Simon-Kucher • Frankfurt

Hybrid
EUR 90.000 - 140.000
Hybrid working
Wellbeing support
Training programs (e.g., LinkedIn)**
+1