JobBobsStellensuche in Echtzeit, weltweitLive

ICT GRC – ICT Governance Senior Manager

N26 · Berlin · 2026-09-16

lead
Beim Arbeitgeber bewerben

Über diese Stelle

About the opportunity

As ICT Senior Governance Manager, you will own the strategic direction, execution, and continuous evolution of ICT Governance within the CISO Office (2nd Line of Defense), including oversight of Firewall Governance as part of your team's remit. You'll operate with full autonomy and accountability, both for the frameworks the function owns and for the people who run them day to day.

You will act as a trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities while enabling the organisation to innovate responsibly. As the primary escalation point for audit findings and regulatory reviews, you'll represent ICT Governance in high-stakes conversations and make sure your team has the context and support to do the same in their own areas.

Just as important as the governance mandate is the team behind it: you will lead and develop ICT Governance and Firewall Governance professionals, building a team others want to be part of. As regulatory and technological demands keep evolving, you'll help modernise how governance gets done - exploring AI-enabled approaches to compliance monitoring and control assurance. If you want the scope of a strategic governance mandate and the accountability of leading a team, this is your opportunity.

In this role, you will:

• Own, define, and continuously evolve the ICT/Information Security governance documentation framework within the CISO Office - policies, standards, procedures, work instructions, and process flows - and establish clear accountability models across 1st and 2nd line functions.

• Own and strategically develop the Target Measure Catalogue (TMC), ensuring its completeness, regulatory alignment, and accurate mapping to relevant regulations and standards.

• Drive enterprise-wide integration of TMC requirements into 1st-line procedures, and oversee change management as the TMC and regulatory landscape evolve.

• Ensure governance controls remain comprehensively and traceably mapped to relevant regulations (MaRisk, DORA, AI Act, CRA, PSD3) and standards (ISO 27001/27002, NIST), proactively translating regulatory developments into governance enhancements.

• Drive DORA-related activities to strengthen operational resilience across the ICT landscape.

• Act as subject matter expert for ICT Governance during regulatory reviews, supervisory interactions, and audits.

• Own end-to-end delivery of IT audit-related requests for the CISO Office, acting as primary escalation and decision authority for findings, and ensuring timely, sustainable remediation with clear reporting to senior stakeholders.

• Provide governance oversight of firewall and network security controls delivered by the team - rule reviews, segmentation assurance, control testing - ensuring they meet internal policy and regulatory expectations.

• Lead, manage, and grow the ICT Governance team, spanning ICT Governance and Firewall Governance - own hiring, onboarding, task delegation, and day-to-day performance.

• Own team planning and resourcing - staffing needs, workload distribution, and development priorities - in partnership with the department lead.

• Coach team members toward independent judgement rather than directing every decision, and contribute to hiring decisions across the wider governance function.

• Act as trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities, and represent the function's work to bodies such as the Non-Financial Risk Committee.

• Translate regulatory and security requirements into terms 1st-line technical teams can act on, and run enablement sessions to build shared governance literacy.

• Define and implement AI-enabled approaches to automate compliance monitoring and control testing.

What you need to be successful:

Background:

• Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field.

• Professional certifications such as CISA, CISM, CRISC, or equivalent strongly preferred.

• 8+ years of experience in ICT/information security governance, risk management, or compliance, ideally within banking or financial services - including experience leading, mentoring, or developing others.

• Strong knowledge of regulatory requirements (MaRisk, DORA, AI Act, CRA, PSD3) and international standards (ISO 27001/27002, NIST, COBIT).

• Working understanding of network and perimeter security governance (firewall management, segmentation, second-line assurance) sufficient to lead and quality-assure a specialised team; hands-on firewall certifications are a plus, not required.

• Demonstrated experience leveraging automation or AI tools to strengthen governance and compliance frameworks.

Skills:

• Strong strategic thinking, translating regulatory complexity into practical governance frameworks in a fast paced environment.

• Proven leadership and stakeholder management across 1st and 2nd line functions.

• Team Leadership & Talent Development: Experience in leading a team, delegating effectively, managing team productivity, developing team members toward independent judgement and fostering a robust feedback culture.

• Executive Communication & Stakeholder Alignment: Ability to build and maintain strong relationships with Leadership, Regulators, and other senior members of the organization by communicating context clearly, proactively surfacing key risks early and the ability to have difficult conversations constructively.

• Excellent analytical and problem-solving capabilities in complex regulatory environments.

• Advanced project and program management, able to run parallel initiatives independently.

• Fluency in English and German (spoken and written) required.

Traits:

• Strong sense of ownership and accountability - operates independently without supervision.

• Strategic mindset balanced with attention to detail.

• Comfortable challenging the status quo and driving organisational change.

• Genuinely…

Ähnliche Stellen

Beim Arbeitgeber bewerben

Ihre nächste Stelle ist schon hier.

Durchsuchen Sie aktuelle Stellen von Tausenden Arbeitgebern, merken Sie sich die interessanten und lassen Sie JobBob den Rest im Blick behalten.