×
Hier anmelden um sich kostenlos auf Stellen zu bewerben oder Stellenanzeigen aufzugeben. X

ICT GRC – ICT Governance Senior Manager

in 10115, Berlin, Berlin, Deutschland
Unternehmen: DUDE CHEM
Vollzeit position
Verfasst am 2026-09-19
Berufliche Spezialisierung:
  • IT/Informationstechnik
    Cyber-Sicherheit, IT Projekt Manager, Informationssicherheit & Datenschutz, IT Business Analyst
Gehalts-/Lohnspanne oder Branchenbenchmark: 110000 - 140000 EUR pro Jahr EUR 110000.00 140000.00 YEAR
Stellenbeschreibung

About the opportunity

As ICT Senior Governance Manager, you will own the strategic direction, execution, and continuous evolution of ICT Governance within the CISO Office (2nd Line of Defense), including oversight of Firewall Governance as part of your team's remit. You'll operate with full autonomy and accountability, both for the frameworks the function owns and for the people who run them day to day.

You will act as a trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities while enabling the organisation to innovate responsibly. As the primary escalation point for audit findings and regulatory reviews, you'll represent ICT Governance in high-stakes conversations and make sure your team has the context and support to do the same in their own areas.

Just as important as the governance mandate is the team behind it: you will lead and develop ICT Governance and Firewall Governance professionals, building a team others want to be part of. As regulatory and technological demands keep evolving, you'll help modernise how governance gets done - exploring AI-enabled approaches to compliance monitoring and control assurance. If you want the scope of a strategic governance mandate and the accountability of leading a team, this is your opportunity.

In this role, you will:
  • Own, define, and continuously evolve the ICT/Information Security governance documentation framework within the CISO Office - policies, standards, procedures, work instructions, and process flows - and establish clear accountability models across 1st and 2nd line functions.
  • Own and strategically develop the Target Measure Catalogue (TMC), ensuring its completeness, regulatory alignment, and accurate mapping to relevant regulations and standards.
  • Drive enterprise-wide integration of TMC requirements into 1st-line procedures, and oversee change management as the TMC and regulatory landscape evolve.
  • Ensure governance controls remain comprehensively and traceably mapped to relevant regulations (MaRisk, DORA, AI Act, CRA, PSD3) and standards (ISO 27001/27002, NIST), proactively translating regulatory developments into governance enhancements.
  • Drive DORA-related activities to strengthen operational resilience across the ICT landscape.
  • Act as subject matter expert for ICT Governance during regulatory reviews, supervisory interactions, and audits.
  • Own end-to-end delivery of IT audit-related requests for the CISO Office, acting as primary escalation and decision authority for findings, and ensuring timely, sustainable remediation with clear reporting to senior stakeholders.
  • Provide governance oversight of firewall and network security controls delivered by the team - rule reviews, segmentation assurance, control testing - ensuring they meet internal policy and regulatory expectations.
  • Lead, manage, and grow the ICT Governance team, spanning ICT Governance and Firewall Governance - own hiring, onboarding, task delegation, and day-to-day performance.
  • Own team planning and resourcing - staffing needs, workload distribution, and development priorities - in partnership with the department lead.
  • Coach team members toward independent judgement rather than directing every decision, and contribute to hiring decisions across the wider governance function.
  • Act as trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities, and represent the function's work to bodies such as the Non-Financial Risk Committee.
  • Translate regulatory and security requirements into terms 1st-line technical teams can act on, and run enablement sessions to build shared governance literacy.
  • Define and implement AI-enabled approaches to automate compliance monitoring and control testing.
What you need to be successful:

Background:

  • Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field.
  • Professional certifications such as CISA, CISM, CRISC, or equivalent strongly preferred.
  • 8+ years of experience in ICT/information security governance, risk management, or compliance, ideally within banking or financial services - including experience leading, mentoring, or developing others.
  • Strong knowledge of regulatory requirements (MaRisk, DORA, AI Act, CRA, PSD3) and international standards (ISO 27001/27002, NIST, COBIT).
  • Working understanding of network and perimeter security governance (firewall management, segmentation, second-line assurance) sufficient to lead and quality-assure a specialised team; hands‑on…
Stellen-Anforderungen
10+ Jahre Berufserfahrung
Um Jobs auf dieser Seite anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie unten auf den Button, um eine Suche zu starten.
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).
 
 
 
Suchen Sie hier nach weiteren Stellen:
(nach Beruf, Fähigkeit)
Standort
Suchradius erweitern (Meilen)
0
200
Filter
Mindest-Bildungsgrad für die Stelle
Mindest-Berufserfahrung für die Stelle
Veröffentlicht in den letzten:
Gehalt