Information Security Manager / ICT Risk Manager
For our client, we are looking for an experienced Information Security Manager / ICT Risk Manager (m/f/d) with a strong focus on information security, governance, and ICT risk management.
In this role, you will be responsible for the continuous development and operation of the Information Security Management System (ISMS) as well as the management and oversight of ICT risks in an international environment. You will act as the key interface between business units, management, external service providers, and audit partners, ensuring compliance with regulatory and security-related requirements.
The role is less focused on operational security administration and more focused on risk management, governance, documentation, compliance, and managing external partners.
Start: ASAP
Duration: 3-6 months
Workload: Full-time
Location: Remote i. EU
Language: English
Responsibilities
- Develop, maintain, and operate the Information Security Management System (ISMS) in accordance with ISO 27001
- Identify, assess, and monitor ICT risks
- Create and maintain policies, processes, and security-related documentation
- Support the implementation of regulatory requirements in the field of information security
- Prepare, conduct, and support internal and external audits
- Coordinate and manage compliance and audit-related activities
- Perform risk assessments and derive appropriate mitigation measures
- Manage and assess suppliers, third-party risks, and vendor risks
- Collaborate closely with business units, management, and external stakeholders
- Support business continuity and operational resilience initiatives
- Promote security awareness and information security practices throughout the organization
- Requirements
Must-Have
- Several years of hands-on experience in Information Security, ISMS, ICT Risk Management, or Governance
- Strong knowledge of ISO 27001 and practical experience applying the framework
- Experience in establishing, operating, or further developing ISMS structures
- Proven experience in risk management and conducting risk assessments
- Knowledge of audit, compliance, and governance processes
- Experience in creating and maintaining regulatory documentation
- Excellent communication and stakeholder management skills
- Structured, independent, and accountable way of working
- Business fluent English skills
Nice-to-Have
- Knowledge of regulatory frameworks and requirements such as DORA, NIS2, MaRisk, BAIT, or similar standards
- Experience within Financial Services, Banking, or FinTech environments
- Experience in Third-Party Risk Management and Vendor Risk Management
- Knowledge of Business Continuity Management (BCM)
- Relevant certifications such as:
ISO 27001 Lead Implementer
ISO 27001 Lead Auditor
CISM
CISSP
CRISC
CISA
Personal Attributes
- Hands-on mentality
- Strong sense of ownership and responsibility
- High level of initiative
- Analytical mindset
- Pragmatic and solution-oriented approach
- Confident communication with management and business stakeholders
- Enjoys working in international and dynamic environments