CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)

CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)

Frankfurt am Main Vollzeit 63000 - 77000 € / Jahr (geschätzt) Kein Homeoffice möglich
3

Auf einen Blick

  • Aufgaben: Unterstütze die Entwicklung und Überwachung der Cyber- und Informationssicherheitsstrategie.
  • Unternehmen: 360T, eine führende Handelsplattform für Devisen mit multinationaler Kultur.
  • Vorteile: Wettbewerbsfähiges Gehalt, regelmäßige Leistungsbeurteilungen und Weiterbildungsmöglichkeiten.
  • Weitere Informationen: Multikulturelles Team mit sozialen Aktivitäten und zentralem Büro in Frankfurt.
  • Warum dieser Job: Gestalte die Zukunft der Cyber-Sicherheit in einem dynamischen Umfeld.
  • Qualifikationen: Erfahrung in Cyber Security und ICT-Risiko, idealerweise im Finanzsektor.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

Your Role

As Deputy Cyber & Information Security and ICT Risk, you support the oversight and further development of 360T’s Cyber & Information Security and ICT Risk framework.

In this Second Line of Defense role, you provide independent oversight, challenge and advice while supporting operational and regulatory excellence across the 360T Group.

You act as a deputy to the responsible function lead and provide support and coverage across key governance, risk and oversight activities.

Our approach is based on full compliance in both word and spirit, continuous assessment of regulatory, legal and technological developments, constructive engagement with regulators and market participants, and the conviction that operational and regulatory excellence is a key competitive advantage.

  • Your Responsibilities
  • Strategy & Governance
  • Support the development and continuous enhancement of the Group’s Cyber & Information Security and ICT Risk strategy, policies and oversight framework in alignment with 360T’s business strategy.
  • Help ensure alignment with applicable legal and regulatory requirements, established standards and relevant industry best practices.
  • Support the translation of regulatory requirements, business objectives and risk considerations into appropriate governance and oversight measures.
  • Contribute to regular reporting to Management and relevant governance bodies on the risk profile, First Line roadmaps, control environment, testing activities and significant incidents.
  • Deputize for the responsible function lead in relevant committees, meetings and governance activities as required.
  • Identify and assess emerging ICT and cyber risks and recommend appropriate mitigation, challenge or escalation.
  • Organization & Risk Oversight
  • Support the oversight of the Information Security Management System (ISMS), related policies and governance processes through which the First Line implements the security and ICT risk strategy.
  • Support the governance and ongoing operation of the Global ICT Risk and Security Committee.
  • Perform independent Second Line monitoring and reviews of relevant processes, systems and controls to assess their adequacy and effectiveness, while operational ownership remains with the First Line.
  • Act as an interface to the Group Risk Management framework and contribute to the consistent identification, assessment, monitoring and reporting of ICT and cyber risks.
  • Support awareness of Cyber & Information Security and ICT Risk topics across the Group and provide subject-matter expertise for relevant training and awareness initiatives.
  • Engage with industry peers, interest groups and external experts to monitor developments and relevant market practices.
  • Oversee and challenge incident management, disaster recovery and business continuity readiness from a Second Line perspective, including monitoring post-incident remediation and compliance with regulatory notification requirements.
  • Advisory & Challenge
  • Provide independent advice to Management and stakeholders on Cyber & Information Security and ICT Risk matters.
  • Support the Management Board in defining and evolving relevant policies and risk requirements.
  • Help assess and resolve potential conflicts between business objectives, operational requirements and information security considerations.
  • Define and maintain appropriate risk and control criteria and provide Second Line requirements, including for physical security where relevant.
  • Act as an internal subject-matter expert while maintaining independence from operational First Line responsibilities.
  • Recommend appropriate controls and risk mitigation measures and independently monitor their implementation.
  • Advise and challenge stakeholders on ICT and security requirements relating to new systems, software, outsourcing arrangements and material changes.
  • Support oversight of the ICT third-party risk framework, including due diligence standards, criticality assessments, concentration risks and exit considerations, and independently challenge First Line assessments and outcomes.
  • Review and challenge disaster recovery and business continuity arrangements for adequacy and alignment with 360T’s risk appetite and applicable regulatory requirements.
  • Testing & Assurance
  • Support oversight of Cyber & Information Security and ICT Risk testing activities, including compliance testing, control assessments, evaluations and certifications.
  • Conduct independent Second Line reviews of relevant technical, organizational and physical security measures.
  • Assess identified weaknesses and remediation activities and escalate material risks or deficiencies where appropriate.
  • Contribute to the continuous improvement of the Cyber & Information Security and ICT Risk control and assurance framework.

Your Profile

  • Professional experience in Cyber Security, Information Security, ICT Risk, Technology Risk, IT Governance or a comparable risk and control function, ideally within a regulated financial-services environment.
  • Good understanding of information security and ICT risk management frameworks, governance models and internal control systems.
  • Familiarity with relevant regulatory requirements and industry standards affecting financial institutions and technology-driven financial-market infrastructures.
  • Experience with risk assessments, control reviews, incident oversight, third-party risk, business continuity and/or disaster recovery is an advantage.
  • Ability to independently assess and challenge risks and controls while working constructively with First Line stakeholders.
  • Strong analytical and communication skills with the ability to translate complex technical and regulatory topics into clear risk-based recommendations.
  • Confidence in communicating with senior management and stakeholders across technical, business, risk and compliance functions.
  • A structured, pragmatic and solution-oriented approach combined with a high degree of integrity and sound professional judgment.
  • Very good command of English; German language skills are an advantage.
  • Our Offer
  • Established and certified security organization and culture, stable and growing multinational company
  • Regular performance appraisals, close interaction with all business functions and management
  • Growth, development, and learning opportunities, including our internal „360T Academy“
  • Offices located directly in the city center
  • Multinational and multicultural environment, social gatherings and activities

The position is based in Frankfurt am Main and vacant immediately.

How to Apply

If your background and qualifications meet these specifications, please forward your application including your salary expectation, earliest starting date by clicking the “Apply” button.

  • Contact
  • Irune Del Buey
    People & Culture Manager
  • Send email
  • Grüneburgweg 16-18
    60322 Frankfurt am Main

About us

360T is one of the globally leading trading platforms for Foreign Exchange (FX).

As Deutsche Börse Group’s powerhouse for FX, 360T provides a web-based trading technology for over-the-counter (OTC) instruments, integration solutions and related services.

Since its inception in 2000, the company has developed and maintained a state-of-the-art multi-bank portal for foreign exchange, crypto assets, cash and money market products.

With over 3,000 Buy-Side customers and more than 200 liquidity providers across 80 different countries, 360T is uniquely positioned to connect the global FX and Crypto industry.

Headquartered in Frankfurt am Main, Germany, 360T maintains subsidiaries in London (360 Trading Networks UK Limited), New York (360 Trading Networks Inc), Singapore (360T Asia Pacific Pte.

Ltd.), Mumbai (Three Sixty Trading Networks (India) Pvt Ltd), Kuala Lumpur (360 Trading Networks Sdn Bhd) and Dubai (360 Trading Networks (DIFC) Limited).

CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d) Arbeitgeber: 360 Treasury Systems AG

Als Arbeitgeber bietet 360T eine herausragende Gelegenheit für engagierte Studierende, die in einem dynamischen FX-Vertriebsteam innerhalb einer schnelllebigen und internationalen Branche praktische Erfahrungen sammeln möchten. Mit flexiblen Arbeitszeiten, der Möglichkeit zur Erstellung von Bachelor- oder Masterarbeiten und regelmäßigen Leistungsbeurteilungen fördert das Unternehmen eine positive Arbeitskultur und unterstützt die persönliche sowie berufliche Weiterentwicklung seiner Mitarbeiter. Zudem besteht die Chance auf eine Festanstellung nach erfolgreichem Abschluss, was 360T zu einem attraktiven Arbeitgeber in Frankfurt am Main macht.

3

Kontaktdaten:

360 Treasury Systems AG Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie 360 Treasury Systems AG kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von 360 Treasury Systems AG zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei 360 Treasury Systems AG.

Wir glauben, dass du diese Fähigkeiten brauchst, um CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d) mit Bravour zu bestehen

Cyber Security
Information Security
ICT Risk Management
IT Governance
Regulatory Compliance
Risk Assessment
Incident Management

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei 360 Treasury Systems AG vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei 360 Treasury Systems AG könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. 360 Treasury Systems AG sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird 360 Treasury Systems AG auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!