Über die Stelle
Permanent consulting role for financial-sector clients who have to prove their resilience, not just claim it. You review policies and controls, judge what a proposed change does to operational and cyber risk, and help stand up the controls and tooling that make a recovery story credible. AI drafts the assessments; you own the verdict.
Ihre Aufgaben
- Review information security policies, controls and change requests, and say plainly which ones do not hold
- Assess what a proposed change does to operational and cyber risk before it ships, not after
- Support the implementation and day-to-day running of security and resilience controls and tooling
- Plan and risk-manage threat-led penetration testing, including engagements run under the TIBER-EU framework
- Develop cyber resilience strategy and translate it into controls someone can actually operate
- Prepare the evidence and reporting that supervisors, auditors and boards ask for
- Advise client security, risk and audit stakeholders up to CISO and CRO level
Die KI übernimmt · Sie verantworten
Die KI übernimmt
Control mapping and gap tables · First-draft assessments and findings · Evidence collection and collation · Policy comparison against frameworks
Sie verantworten
Risk judgment and the final verdict · What gets escalated and what does not · Client trust at CISO level · Defensibility in front of a supervisor
Ihr Profil
- Information security and cyber resilience in a regulated financial environment
- Policy and control assessment against recognised frameworks (ISO 27001, NIST CSF, BSI IT-Grundschutz)
- Operational and cyber risk analysis, including third-party and concentration risk
- Threat-led penetration testing: scoping, risk management and remediation follow-through
- Incident response, business continuity and recovery planning
- Comfortable writing for both engineers and boards, in English and German
Qualifikationen
- 5+ years in information security, cyber resilience or technology risk, ideally in banking, insurance or market infrastructure
- Practical experience of a regulatory or supervisory review, and of closing the findings from one
- A recognised certification is an advantage (CISSP, CISM, CRISC, ISO 27001 Lead Auditor)
- Degree in computer science, information security or a comparable field, or equivalent experience
- German C1 or better plus fluent business English