360T

CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)

360T  •  Frankfurt am Main, DE (Onsite)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Your Role

As Deputy Cyber & Information Security and ICT Risk, you support the oversight and further development of 360T’s Cyber & Information Security and ICT Risk framework.

In this Second Line of Defense role, you provide independent oversight, challenge and advice while supporting operational and regulatory excellence across the 360T Group. You act as a deputy to the responsible function lead and provide support and coverage across key governance, risk and oversight activities.

Our approach is based on full compliance in both word and spirit, continuous assessment of regulatory, legal and technological developments, constructive engagement with regulators and market participants, and the conviction that operational and regulatory excellence is a key competitive advantage.

Your Responsibilities

Strategy & Governance

  • Support the development and continuous enhancement of the Group’s Cyber & Information Security and ICT Risk strategy, policies and oversight framework in alignment with 360T’s business strategy.
  • Help ensure alignment with applicable legal and regulatory requirements, established standards and relevant industry best practices.
  • Support the translation of regulatory requirements, business objectives and risk considerations into appropriate governance and oversight measures.
  • Contribute to regular reporting to Management and relevant governance bodies on the risk profile, First Line roadmaps, control environment, testing activities and significant incidents.
  • Deputize for the responsible function lead in relevant committees, meetings and governance activities as required.
  • Identify and assess emerging ICT and cyber risks and recommend appropriate mitigation, challenge or escalation.

Organization & Risk Oversight

  • Support the oversight of the Information Security Management System (ISMS), related policies and governance processes through which the First Line implements the security and ICT risk strategy.
  • Support the governance and ongoing operation of the Global ICT Risk and Security Committee.
  • Perform independent Second Line monitoring and reviews of relevant processes, systems and controls to assess their adequacy and effectiveness, while operational ownership remains with the First Line.
  • Act as an interface to the Group Risk Management framework and contribute to the consistent identification, assessment, monitoring and reporting of ICT and cyber risks.
  • Support awareness of Cyber & Information Security and ICT Risk topics across the Group and provide subject-matter expertise for relevant training and awareness initiatives.
  • Engage with industry peers, interest groups and external experts to monitor developments and relevant market practices.
  • Oversee and challenge incident management, disaster recovery and business continuity readiness from a Second Line perspective, including monitoring post-incident remediation and compliance with regulatory notification requirements.
  • Advisory & Challenge
  • Provide independent advice to Management and stakeholders on Cyber & Information Security and ICT Risk matters.
  • Support the Management Board in defining and evolving relevant policies and risk requirements.
  • Help assess and resolve potential conflicts between business objectives, operational requirements and information security considerations.
  • Define and maintain appropriate risk and control criteria and provide Second Line requirements, including for physical security where relevant.
  • Act as an internal subject-matter expert while maintaining independence from operational First Line responsibilities.
  • Recommend appropriate controls and risk mitigation measures and independently monitor their implementation.
  • Advise and challenge stakeholders on ICT and security requirements relating to new systems, software, outsourcing arrangements and material changes.
  • Support oversight of the ICT third-party risk framework, including due diligence standards, criticality assessments, concentration risks and exit considerations, and independently challenge First Line assessments and outcomes.
  • Review and challenge disaster recovery and business continuity arrangements for adequacy and alignment with 360T’s risk appetite and applicable regulatory requirements.

Testing & Assurance

  • Support oversight of Cyber & Information Security and ICT Risk testing activities, including compliance testing, control assessments, evaluations and certifications.
  • Conduct independent Second Line reviews of relevant technical, organizational and physical security measures.
  • Assess identified weaknesses and remediation activities and escalate material risks or deficiencies where appropriate.
  • Contribute to the continuous improvement of the Cyber & Information Security and ICT Risk control and assurance framework.

Your Profile

  • Professional experience in Cyber Security, Information Security, ICT Risk, Technology Risk, IT Governance or a comparable risk and control function, ideally within a regulated financial-services environment.
  • Good understanding of information security and ICT risk management frameworks, governance models and internal control systems.
  • Familiarity with relevant regulatory requirements and industry standards affecting financial institutions and technology-driven financial-market infrastructures.
  • Experience with risk assessments, control reviews, incident oversight, third-party risk, business continuity and/or disaster recovery is an advantage.
  • Ability to independently assess and challenge risks and controls while working constructively with First Line stakeholders.
  • Strong analytical and communication skills with the ability to translate complex technical and regulatory topics into clear risk-based recommendations.
  • Confidence in communicating with senior management and stakeholders across technical, business, risk and compliance functions.
  • A structured, pragmatic and solution-oriented approach combined with a high degree of integrity and sound professional judgment.
  • Very good command of English; German language skills are an advantage.

Our Offer

  • Established and certified security organization and culture, stable and growing multinational company
  • Regular performance appraisals, close interaction with all business functions and management
  • Growth, development, and learning opportunities, including our internal „360T Academy“
  • Offices located directly in the city center
  • Multinational and multicultural environment, social gatherings and activities
The position is based in Frankfurt am Main and vacant immediately.

How to Apply

If your background and qualifications meet these specifications, please forward your application including your salary expectation, earliest starting date by clicking the “Apply” button.

Contact

Irune Del Buey
People & Culture Manager

Send email
Grüneburgweg 16-18
60322 Frankfurt am Main

360T

About 360T

360T is far more than an award-winning multi-bank, multi-asset trading platform for OTC and listed financial instruments. As Deutsche Börse Group’s global FX unit, the company offers services across the entire trading workflow of FX and short-term Money Market asset classes to satisfy the needs of Corporate Treasurers, Institutional Asset Managers and Hedge Funds as well as Banks. Beyond optimising execution, 360T allows clients to directly reduce their operational costs and risks in all parts of the trading life cycle while enhancing compliance and transparency at the same time.

The company also offers licensing of a hosted white labelled trading technology between a scalable group of price-takers and either proprietary price providers or a rich choice of back-to-back liquidity sources. 360T’s buy-side clients are national and multinational corporate treasuries, institutional clients (asset managers, hedge funds, commodity trading advisors), broker/dealers and banks. The company is authorized under German law and regulated by the German Federal Financial Supervisory Authority (BaFin).

Headquartered in Frankfurt am Main, Germany, 360T maintains subsidiaries in New York (360 Trading Networks Inc), Singapore (360T Asia Pacific Pte. Ltd.), India (ThreeSixty Trading Networks (India) Pvt Ltd) and Dubai (360 Trading Networks LLC).

Industry
Finance & Insurance
Company Size
201-500 employees
Headquarters
Frankfurt, DE
Year Founded
2000
Website
360t.com
Social Media