Overview
In this role you bridge business demand with security, governance and architecture across a global technology landscape. You assess new technologies, AI-enabled solutions and SaaS offerings, ensuring security, compliance and risk are addressed through practical mitigations. You collaborate with IT, Security, Procurement, Legal and Audit to enable timely technology decisions while maintaining governance and risk documentation. You work in a dynamic, multinational environment with opportunities to grow through training and cross-functional projects.
Leistungen / Benefits
- hybrid working
- daycare allowance
- corporate discounts
- wellbeing support (Headspace)
Verantwortungsbereiche
- Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions
- Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions
- Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees
- Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions
- Ensure new technologies comply with security policies, controls, and integration requirements
- Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes
- Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks
- Translate business requirements into security and compliance recommendations that enable timely technology decisions
- Communicate complex technical concepts through presentations, decision papers, and executive-facing materials
- Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders
- Support vendor assessments, RFPs, technical evaluations, and solution reviews
- Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements
- Work effectively in agile, global project environments with multiple priorities and tight timelines
Zentrale Anforderungen
- 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting
- Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies
- Experience assessing SaaS, cloud, third-party, and AI-enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements
- Experience improving governance processes, workflows, standards, and risk management practices
- Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar
- Experience with security controls, risk assessments, compliance, audit support, and governance approval processes
- Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security
- Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation
- Strong stakeholder management skills with experience across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams
- Experience preparing executive-level presentations, risk reports, and decision-ready documentation, and presenting recommendations to senior leadership
- Experience evaluating third-party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments
- Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross-functional technology initiatives
- CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands-on experience)
- stakeholder management
- clear communication
- cross-functional collaboration
- SaaS/cloud/AI-enabled solution assessment
- security controls and risk assessments
- ISO 27001, SOC 2, ITIL frameworks
Technology Risk & Security Manager (m/f/d) in Köln Arbeitgeber: Simon Kucher & Partners
Simon-Kucher ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern in Deutschland die Möglichkeit bietet, in einem dynamischen und unterstützenden Umfeld zu arbeiten. Mit einer offenen Unternehmenskultur, umfangreichen Weiterbildungsmöglichkeiten und der Flexibilität, von verschiedenen Standorten aus zu arbeiten, fördert das Unternehmen nicht nur die berufliche Entwicklung, sondern auch das persönliche Wohlbefinden seiner Mitarbeiter. Die zahlreichen Benefits, wie hybride Arbeitsmodelle und regelmäßige Teamevents, machen Simon-Kucher zu einem attraktiven Arbeitsplatz für alle, die eine sinnvolle und erfüllende Karriere anstreben.