Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Frankfurt
- Working Model
- Onsite
Job Summary
In this role, you will develop the governance framework for data leakage prevention and focus on continuous improvement of DLP services by creating governance documents and ensuring compliance.
Your role in the team
- As part of the Cyber Protection - Detect & Prevent unit, you will act as the Group's senior specialist for Data Leakage Prevention (DLP) governance, with end-to-end accountability for the DLP governance framework and the effective delivery of the DLP service.
- The role focuses on policy and rule-setting, governance oversight, risk management, and assurance, while also ensuring that the DLP service is reliably operated, performance-managed, and continuously improved through close coordination with IT delivery teams and business stakeholders.
- Technical implementation is executed by dedicated operational teams; this role is responsible for direction, oversight, and service outcomes.
- Define, maintain, and evolve DLP governance requirements, internal security policies, and written rules in alignment with the ICT risk framework and regulatory expectations.
- Establish clear requirements for information handling, classification, data transfer, endpoint usage, and media protection, etc.
- Ensure governance documentation is clear, consistent, risk based, and fit for practical adoption across the organisation.
- Define and oversee the DLP control framework, including mandatory controls, criteria, and governance expectations.
- Ensure clear accountability across governance, operational, and delivery functions, with appropriate separation of duties.
- Monitor adherence to DLP requirements and support corrective actions where gaps are identified.
- Support responsible teams with data leakage risk assessments, deviations, and exception handling, advising stakeholders on risk implications and mitigation options.
- Assess the impact of regulatory, organisational, or technology changes on DLP governance and service obligations.
- Manage audit and assurance activities by providing governance evidence, expert input, and remediation oversight.
- Act as the governance owner of the enterprise DLP service, ensuring it is delivered in line with defined policies, risk expectations, and service objectives.
- Oversee service performance, operational stability, and lifecycle evolution, including monitoring and reporting on KPIs, SLAs, and recurring issues.
- Coordinate incidents, changes, and improvement initiatives with responsible delivery teams to ensure timely resolution and risk aligned outcomes.
- Drive continuous improvement of the DLP service to enhance effectiveness, efficiency, and user experience.
- Serve as the primary point of contact for DLP related governance and service matters for business units, IT, and risk stakeholders.
- Provide expert guidance on DLP requirements, service capabilities, and acceptable data handling practices.
- Support projects, new solutions, and organisational changes by advising on DLP governance and service implications.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelor's or Master's degree in Cybersecurity, Information Security, IT, Risk Management, or a related discipline.
- High degree of ownership, adaptability, and a proactive, quality driven mindset.
Qualifications
- Solid understanding of Data Leakage Prevention principles, including information handling, classification, secure data transfer, email and endpoint controls.
- Strong analytical, documentation, and stakeholder management skills.
- Ability to translate governance requirements into practical, business aligned rules and service expectations.
- Proficiency in English; German language skills are an advantage.
Experience
- Experience in information security governance, data protection, or risk management within a regulated or complex environment.
- Experience in information security governance, data protection, or risk management within a regulated environment, including practical application of requirements arising from GDPR, DORA, and related industry standard frameworks such as ISO/IEC 27001, NIST.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
More net
Food & Drink
Topics that you deal with on the job
Job Locations
This is your employer
Deutsche Börse AG
Deutsche Börse Group is one of the world's leading trading platforms. As a financial market organizer, the company offers a full range of services to cover the entire process: trading and clearing of securities and derivatives, netting and settlement of transactions, opening of accounts and provision of market information services.
Description
- Language
- English
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance