All positions
ICT GRC - Senior IT Governance Associate
Department:Risk
Location:Berlin
About the opportunity
We are seeking an ICT GRC - Senior IT Governance Associate to join our team. In this role, you’ll ensure that our IT systems and information security practices are robust, compliant, and aligned with evolving regulations. You’ll be the bridge between compliance, security, and technology, helping the organisation meet regulatory obligations while embracing innovation.
With AI and automation transforming compliance processes, you’ll have the opportunity to explore and implement AI-driven solutions to enhance compliance monitoring, risk assessments, and regulatory reporting. This is your chance to not just follow regulations, but to help redefine how they are met in a tech-forward environment.
In this role, you will:
- Create, maintain, and communicate the updates to the Governance Documentation related to Information Security and DOR for the CISO Office. This will include policy, procedure, work instructions, process flows within the CISO office and connected to the 1st line teams that are dependent on these for direction.
- Maintain and update the TMC (Target Measure Catalogue)
- Collaborate with first line teams to ensure the TMC (Target Measure Catalogue), and any changes thereof, are applied to the 1st line procedures and operations.
- Ensure the mapping of Target measures to the various IT regulations and standards.
- Perform the annual ISMS Maturity assessment and other self assessments in collaboration with the IT Compliance roles in the ICT GRC team.
- Ensure the delivery of all the IT Audits for the CISO Office.
- Support the members of the Risk and Compliance domains of the ICT GRC team with reporting requirements and risk assessments, including and not limited to NPP, NFR Top-Down assessment.
- Explore AI-driven approaches to streamline compliance monitoring, automate assessments, and improve regulatory alignment.
What you need to be successful:
Background:
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field would be preferable but not mandatory.
- Professional certifications such as CISA / CISM / CRISC, or equivalent are highly desirable.
- Minimum of 3 to 4 years of experience in IT risk management, information security, and compliance, preferably within the banking or financial services industry.
- In-depth knowledge of relevant regulatory requirements, such as MaRisk, BAIT, DORA and industry standards such as ISO 27001/27002, NIST, etc.
- Strong understanding of IT infrastructure, network security, application security, and cloud security.
- Be able to leverage AI tools and automation techniques to enhance internal processes.
- Excellent analytical and problem-solving skills, with the ability to identify and assess complex IT and information security risks.
- Strong project management skills with the ability to manage multiple tasks and projects simultaneously.
- Proficient in using compliance and risk assessment tools, with a curiosity for how AI can improve compliance processes
- Proficient in using JIRA, Confluence and Figjam is a plus.
- Effective communication and interpersonal skills, with the ability to explain technical concepts to non-technical stakeholders.
- Strong report-writing and presentation skills.
- Fluency in English required; German (fluent or basic) preferred, with willingness to learn.
- Adaptable and open to learning, with a keen interest in staying up-to-date with the latest trends and developments in IT and information security.
- Passion for risk management, internal controls, and complex problem-solving.
- Detail-oriented and meticulous in ensuring accuracy and thoroughness in all tasks.
- Proactive and self-motivated, with the ability to work independently and as part of a team.
- Collaborative, able to work well with teams and stakeholders.
- Strong topic ownership and a bias for action.
- Critical thinking and a drive to improve the status quo.
- Both attention to detail and strong conceptual thinking.
- Flexibility in a fast-changing and agile environment.
- Actively help oneself and the team to be successful.
- Willingness to continuously learn and act upon direct feedback.
- High ethical standards and integrity, with a strong commitment to confidentiality and data protection.
What’s in it for you:
- Accelerate your career growth by joining one of Europe’s most talked about disruptors 🚀.
- Employee benefits that range from a competitive personal development budget, work from home budget, discounts to fitness & wellness memberships, language apps and public transportation.
- As an N26 employee you will have access to a Premium subscription on your personal N26 bank account. As well as subscriptions for friends and family members.
- Additional day of annual leave for each year of service.
- A high degree of autonomy and access to cutting edge technologies - all while working with a friendly team of peers of diverse nationalities, experiences, and backgrounds.
- We work in a hybrid setup, combining in-office collaboration with the flexibility to work from home.
- A relocation package with visa support for those who need it.