ICT GRC – ICT Compliance Senior Manager
Verfasst am 2026-09-22
-
IT/Informationstechnik
Cyber-Sicherheit, IT Projekt Manager, IT Consulting, IT Business Analyst
About The Opportunity
As an ICT Compliance Senior Manager, you will spearhead the strategy and continuous evolution of N26's IT compliance framework within the 2nd Line of Defense. Serving as a central authority in the CISO Office, you will ensure our digital infrastructure seamlessly aligns with stringent EU and German regulations while linking your team's vision directly to company OKRs. Beyond fostering a high-performing culture of mentorship and empowerment, you will pioneer the use of AI and automation to transform compliance monitoring, control testing, and regulatory reporting into highly scalable, modern processes.
AboutThe Opportunity
As an ICT Compliance Senior Manager, you will spearhead the strategy and continuous evolution of N26's IT compliance framework within the 2nd Line of Defense. Serving as a central authority in the CISO Office, you will ensure our digital infrastructure seamlessly aligns with stringent EU and German regulations while linking your team's vision directly to company OKRs. Beyond fostering a high-performing culture of mentorship and empowerment, you will pioneer the use of AI and automation to transform compliance monitoring, control testing, and regulatory reporting into highly scalable, modern processes.
InThis Role, You Will
- Drive the function-wide IT compliance objective and strategy within the 2nd Line of Defense, establishing an aligned vision across multiple teams and reporting to senior leadership.
- Define, maintain, and continuously elevate the target measure catalogue and ICT compliance roadmap, aligning internal security standards with cutting-edge industry practices and regulatory expectations.
- Lead and direct comprehensive, independent second-line compliance assessments of N26's Information Security Management System (ISMS) and ICT control ecosystem.
- Ensure full, end-to-end adherence to key EU and German regulatory frameworks (e.g., DORA, MaRisk, BAIT, CSA, PSD3) and international standards (ISO 27001/27002, NIST).
- Lead strategic regulatory gap analyses, defining clear multi-quarter remediation roadmaps and contributing to key business operational decisions across the organization.
- Own regulatory reporting for ICT compliance, delivering executive-level presentations on compliance posture, risk exposure, and strategic mitigation plans to top management and regulatory authorities.
- Serve as a primary authority and principal contact point for internal audits, external audits, and regulatory examinations for the CISO Office.
- Champion AI-enabled compliance monitoring, automation initiatives, and second-line control testing to maximize efficiency, accuracy, and operational impact.
- Communicating context to team members, surfacing appropriate issues to upper management, and constructively managing conflict and change.
- Independently audit and challenge 1st line ICT processes and information domain controls - specifically regarding DORA compliance - evaluating control design and operating effectiveness to guarantee sustainable remediation.
- Orchestrate DORA and broader ICT compliance initiatives across 2nd line functions, delegating work effectively, setting team KPIs, and collaborating across business units.
- Assist with annual planning, staffing, and expense prioritization while actively participating in hiring, mentoring team members, delegating work effectively, and driving a strong culture of feedback.
- Bachelor's or Master's degree in Computer Science, Information Technology, Information Security, or a related field.
- Professional certifications strongly preferred (e.g., CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer, CISSP).
- 8+ years of progressive experience in IT risk management, ICT compliance, or information security,…
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).