Senior Specialist: IT Audit & Cyber Risk (2nd Line) (f/m/d)

Stellenbeschreibung:

Overview

In this role, you will join the ICT Risk Assurance team to oversee continuous monitoring of ICT controls and ensure they are well-designed, implemented, and effective. You will drive risk-based assurance plans and lead audits across applications, infrastructure, cloud, and networks to protect the organization. You will translate complex technical and regulatory issues into actionable guidance for senior stakeholders and help embed sustainable remediation. This position offers impact at the intersection of IT risk governance and operational assurance, with opportunities to shape control frameworks and respond to evolving cyber threats.

Verantwortungsbereiche
  • Design and implement risk-based assurance plans aligned with internal and regulatory requirements
  • Lead and execute IT & IS assurance assessments across applications, infrastructure, cloud platforms, and network/security processes
  • Test ITGC and cybersecurity controls (Access Management, SDLC & Change Management, Encryption, Third‑Party Risk, Patch & Vulnerability Management, SIEM, Penetration Testing, IT Operations) to identify gaps
  • Prepare high-quality assurance reports with observations, risk, and recommendations for management; communicate complex issues to technical and non-technical stakeholders
  • Track remediation actions, validate closure, and ensure sustainability of corrective measures
  • Collaborate with IT, Security teams, and other stakeholders to provide risk insights for new and existing systems
  • Contribute to continuous improvement of assurance methodologies, frameworks, and processes
  • Stay updated with evolving threats, technologies, cloud risks, and regulatory changes
Zentrale Anforderungen
  • 6+ years in IT/cyber audit, second-line assurance, cybersecurity implementation, or GRC with proven complex audit/assurance leadership
  • Bachelor’s or Master’s degree in IT, Information Security, Risk Management, or related field
  • Experience in security domains: Cloud Security, Network Security, Vulnerability Management, Penetration Testing, SIEM/SOC/CERT, Encryption, IAM/PAM, Software Development & Change Management, AI Risk/Governance
  • Strong knowledge of IT governance and control frameworks: COBIT, CSA-CCM, ISO/IEC 27000, ITIL, EU regulations
  • Certifications preferred: CISA, ISO 27001 LA/LI, CISM, CISSP, CRISC
  • Experience with audit/assurance techniques, risk-based testing, sampling, mentoring junior staff
  • Ability to translate technical/regulatory issues into business implications
  • Strong communication/negotiation/influencing skills with senior stakeholders
  • Understanding of the Three Lines of Defense model
  • Excellent English communication
  • Strong communication
  • Negotiation and influencing
  • Mentoring junior team members
  • Cloud Security
  • Network Security
  • Vulnerability Management
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    14 Sep 2026
  • Standort:

    Frankfurt am Main
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!