Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Hamburg
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will enhance the information security management system, conduct risk analyses, support internal and external audits, and ensure compliance with regulatory requirements.
Your role in the team
- Further development and continuous improvement of the Information Security Management System (ISMS) considering regulatory requirements and best practices.
- Participation in the implementation and further development of regulatory requirements and standards, in particular DORA, MaRisk, ISO 27001, as well as other relevant supervisory regulations.
- Planning, coordination, and follow-up of internal and external audits as well as managing the processing of findings and corrective actions.
- Conducting risk analyses, protection requirement assessments, as well as security and control evaluations.
- Assessment of ICT projects, cloud solutions, outsourcing, and new technologies from an information security perspective.
- Development and maintenance of policies, standards, processes, and security requirements.
- Support in the further development of governance, risk, and control structures in the information security environment.
- Analysis, processing, and tracking of information security incidents as well as support in deriving sustainable improvement measures.
- Close collaboration with, among others, IT, Risk Management, Compliance, Internal Audit, as well as external auditors and service providers.
This text has been machine translated. Show original
Our expectations of you
Education
- Successfully completed (dual) studies in the field of (business) informatics, business law, IT security, or a comparable qualification.
Qualifications
- Good knowledge of regulatory requirements and standards such as DORA, MaRisk, ISO 27001, NIS2, or comparable frameworks.
- Excellent spoken and written proficiency in German and English.
- Ability to communicate regulatory and security-related requirements pragmatically and appropriately for the target audience.
- Analytical and structured thinking as well as a meticulous work approach.
- Proactiveness, willingness to learn, and enjoyment in familiarizing oneself with new topics.
- High level of initiative and willingness to take responsibility.
Experience
- 2 to 3 years of relevant professional experience in the fields of Information Security, IT Risk, GRC, or IT Audit.
- Experience in supporting or conducting information security audits, assessments, or reviews, as well as in handling findings, controls, and measures.
This text has been machine translated. Show original
What we offer
- Hybrid work model with flexible use of mobile working - you decide where you work from.
- 20 days of workation abroad in Europe.
- You enjoy 30 days of vacation per year and have the entire days off on December 24th and December 31st.
- Wherever you are right now - enjoy unlimited sports across Germany with our partner EGYM Wellpass.
- Whether with an e-bike, cargo bike, or traditional bicycle - with your leased company bike, you are traveling in an environmentally friendly way.
- And during Hamburg's miserable weather, you use your nationwide job ticket, which we subsidize.
- In addition, we also take out supplementary insurance for preventive examinations and dental treatments for you.
- Longing for your colleagues? Then we offer you attractive offices in an excellent location with great views of the Elbe, including a gym and gaming room, height-adjustable desks, laptop bars, and much more.
- A corporate culture that promotes personal development and combines the energy and innovativeness of a FinTech with the business orientation of a bank.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
Varengold Bank AG
The Varengold Bank is a German credit institution with its headquarters in Hamburg and offices in London and Sofia. Our aim is to give people access to capital and banking services. That's why we focus on marketplace banking and position ourselves as a partner of FinTechs. Varengold supports modern, user-friendly online marketplaces that deal with the financing of companies and consumers (peer-to-peer platforms).
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance