Technology Risk & Security Manager (m/f/d)
In Germany - Berlin| Bonn | Cologne| Frankfurt/Main | Hamburg | Munich
This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating withinthe company’s Technology Demand Intake Process, which is closely connected toimplementation and lifecycle governance.
This individual will focus on reviewing technical concepts, stand‑aloneproducts, services, and AI-enabled solutions that the company plans toimplement or integrate into its complex global enterprise technology landscape,including SaaS, PaaS, SAP, and AI-enabled platforms.
You will be responsible for assessing and governing new technology demands,services, platforms, and AI-enabled solutions through the organization’stechnology intake process. The role ensures that security, compliance, architecture, operational, andbusiness risks are identified, clearly documented, and addressed througheffective and practical mitigation measures.
What makes us special:
- Advance your career with exciting professional opportunities in our thriving company with a startup feel.
- Voice your unique ideas in a corporate culture defined by openness and integrity.
- Enjoy the opportunity to work from abroad (workation).
- Feel at home working with our helpful, enthusiastic colleagues who have great team spirit.
- Broaden your perspective with our extensive training curriculum and learning programs (e.g. LinkedIn Learning).
- Speak your mind in our holistic feedback and development processes (e.g. 360-degree feedback).
- Satisfy your need for adventure with our opportunities to live and work abroad in one of our many international offices
- Enjoy our benefits, such as hybrid working, daycare allowance, corporate discounts, and wellbeing support (e.g. Headspace).
- Unwind in our break areas where you can help yourself to the healthy snacks and beverages provided.
- See another side of your coworkers at our frequent employee events and highly anticipated World Meeting and Holiday Party.
How you will create an impact:
- Manage theend-to-end Technology Demand Intake and Risk Assessment process for newtechnologies, platforms, tools, and AI-enabled solutions.
- Assess security,compliance, operational, vendor, and architecture risks; identifymitigation strategies and recommend risk treatment decisions.
- Prepareexecutive-ready reports and present findings to IT leadership, governanceboards, and risk committees.
- Partner withSecurity, IT, Architecture, Procurement, Legal, Privacy, Audit, andbusiness stakeholders to evaluate and approve technology solutions.
- Ensure newtechnologies comply with security policies, controls, and integrationrequirements.
- Maintain riskdocumentation, exception records, control evidence, and governancereporting while continuously improving intake processes.
- Stay current onemerging technologies, AI, cybersecurity trends, regulatory requirements,and industry control frameworks.
- Translatebusiness requirements into security and compliance recommendations thatenable timely technology decisions.
- Communicatecomplex technical concepts through presentations, decision papers, andexecutive-facing materials.
- Facilitatecollaboration across IT architecture, infrastructure, business teams,vendors, and other stakeholders.
- Support vendorassessments, RFPs, technical evaluations, and solution reviews.
- Contribute tocross-functional IT projects by identifying dependencies, risks, andprocess improvements.
- Work effectivelyin agile, global project environments with multiple priorities and tighttimelines.
About you:
- Experience inacomplexglobal environment, comparable consulting or serviceindustries is preferred.
- Bachelor’sDegree required – preferred in the area of Technology, MIS, Cybersecurity,etc.
- 5+ years ofexperience in technology risk, cybersecurity, IT governance, GRC, ITaudit, security architecture, or technology consulting.
- Strong knowledgeof cybersecurity, technology risk management, compliance, enterprise ITgovernance, and emerging AI-enabled technologies.
- Experienceassessing SaaS, cloud, third-party, and AI-enabled solutions, with theability to identify risks, mitigation strategies, and implementationrequirements.
- Experienceimproving governance processes, workflows, standards, and risk managementpractices.
- Knowledgeofsecurity and governance frameworks such as ISO 27001, SOC 2, ITIL, orsimilar.
- Experience withsecurity controls, risk assessments, compliance, audit support, andgovernance approval processes.
- Ability toevaluate platform architecture, integrations, identity and accessmanagement, data flows, encryption, logging, monitoring, and operationalsecurity.
- Understanding ofenterprise architecture, cloud security, vendor risk management, andsecure technology implementation.
- Strongstakeholder management skills with experience working across IT, Security,Architecture, Compliance, Privacy, Legal, Procurement, Audit, and businessteams.
- Experience preparing executive-level presentations, risk reports, and decision-readydocumentation, and presenting recommendations to senior leadership.
- Experience evaluating third-party vendors, cloud platforms, SaaS solutions, andmanaged services within global IT environments.
- Experiencesupporting technology onboarding, vendor risk assessments, procurement,RFPs, and cross-functional technology initiatives.
- Ability to manage risks, remediation activities, project dependencies, andimplementation progress across the technology lifecycle.
- CISSP, CISM,CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalentcertification (or comparable hands‑on experience).
About Simon‑Kucher
Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. As a trusted commercial advisor focused on unlocking better growth, we combine deep consulting expertise, growth specialization, and technology to scale lasting impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value. With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist. simon‑kucher.com
We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.
Better growth starts here. With you.