Upvest

Lead IT Risk Manager

Stellenbeschreibung:

  • As the Lead IT Risk Manager, you will play a pivotal role in owning and evolving our IT Risk Framework within the second-line risk function. Operating in a highly growth-oriented and regulated financial services environment, this role demands an exceptional blend of technical governance expertise, independent challenge capabilities, and strategic stakeholder management
  • You will serve as the primary second-line authority for IT risk matters, providing oversight to the first-line IT GRC team, leading comprehensive risk assessments, and ensuring strict alignment with Upvest’s overarching Risk Appetite Framework
  • Risk Framework Ownership & Oversight
  • Own and evolve the IT Risk and Business Continuity Management Framework within the second line, keeping it scalable as the business grows
  • Provide independent second-line oversight and challenge to the first-line IT GRC team on the design and effectiveness of IT controls
  • Lead IT risk identification, assessment, and mitigation across cyber, technology resilience, third-party, and data security, linking back to the Risk Appetite Framework
  • IT Governance & Compliance Management
  • Mature the ISMS by guiding policies, standards, and procedures with the relevant process owners
  • Define baseline controls and run continuous ISMS maturity assessments against ISO/IEC 27001:2022 and related standards
  • Oversee third-party IT risk, internal technology exposures, and business continuity assessments
  • IT Audit & 2nd Line Assurance
  • Drive second-line assurance reviews and deep-dives across critical IT risk domains, reporting findings and tracking remediation to closure
  • Support internal and external audits, including IT General Controls (ITGC) and Application Controls
  • Run preliminary internal IT audits to prepare engineering, product, and business teams for official engagements
  • Regulatory Alignment & Stakeholder Management
  • Lead Upvest’s DORA obligations, including ICT risk management, incident classification, and third-party ICT risk oversight
  • Track the regulatory landscape (BaFin, EBA, ESMA, ECB) and translate requirements into actionable risk guidance
  • Act as the primary second-line contact for IT risk, reporting posture and material risk events to senior stakeholders, the C-suite, and the Risk Committee

Benefits

  • Flexibility - We work in a hybrid set-up, with the team spread around Germany and other parts of Europe. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose.
  • Development - In keeping with one of our values, ‘Learn and grow’, every Upvenger has access to a development budget. And in line with one of our other values, ‘Own the outcome’, how you make the most of it is up to you.
  • Wellbeing - Everyone here has access to our in-house coach. You can have regular sessions to support you personally and professionally. We also believe it’s important to have time out to rest and recover, which is why we offer 30 days’ holiday.
  • Greenfield projects - We’re building something quite complex. A first in Europe. This means you get to work with cutting-edge technologies, with no legacy code.

Technical Depth: Deep operational understanding of IT governance standards (e.g., ISO 27001), regulatory risk requirements (BaFin BAIT/MaRisk), and modern resilience standards like DORA.

Experience: Minimum of 5+ years of progressive professional experience in IT Governance, Risk, Compliance, and Security (IT GRC / IT Security) within a regulated financial institution, bank, fintech, or fast-scaling B2B platform environment.

Mindset: A strong product engineering and security-focused mindset, combined with commercial pragmatism and the ability to operate confidently under ambiguity.

Education: University degree in Computer Science, Information Technology, Information Security, or an equivalent academic/professional background.

Communication Skills: Exceptional verbal and written articulation skills in English, with a proven ability to engage credibly with a multilingual international stakeholder base, technical engineering leads, and C-level executives.

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    23 Aug 2026
  • Standort:

    Berlin

    Einsatzort:

    Berlin, Germany
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!