Associate: IT Audit & Cyber Security Risk [T500-30032]
Deutsche Börse Group · Hyderabad, Telangana, India
Apply & track with Apply EdgeAbout Deutsche Börse Group:Headquartered in Frankfurt, Germany, Deutsche Börse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and companies by facilitating access to global capital markets.Their India centre is located in Hyderabad, serves as a key strategic hub and comprises India’s top-tier tech talent. They focus on crafting advanced IT solutions that elevate market infrastructure and services. Deutsche Börse Group in India is composed of a team of capital market engineers forming the backbone of financial markets worldwide."Associate: IT Audit & Cyber Security Risk (2nd Line)«full time», «Hyderabad», «Level 2A - Level 2B», «must have skills: Cyber Security Audit or SIEM or Security Information and Event Management or Cloud Security or Penetration Testing»«nice to have skills: Audit, Assurance, Vulnerability management, IT Audit, Information Technology Audit, Information Security Audit, Network Security, Encryption, SOC, CERT»Your area of work:The Chief ICT Risk Office (CISO) combines IT & IS Risk Management in the 2nd Line of Defense. The department’s mandate is to set the IT and IS (ICT) risk governance and framework, set the control objectives, control review methodology and risk assessment methodology, conduct independent risk assurance of 1st LoD ICT controls (IT and IS controls), and independently monitor and report on the level of ICT risks as well as to drive transformation and collaboration.In this role, you will be part of ICT Risk Assurance team, performing continuous monitoring and oversight to confirm that our ICT controls are well-designed, correctly implemented, and operating effectively to protect the organization.Your responsibilities:Design and implement risk-based assurance plans aligned with internal and regulatory requirementsLead and execute IT & IS assurance assessments to evaluate risks across applications, infrastructure, cloud platforms, and network/security processesEnsure IT systems and processes comply with relevant laws, regulations, and standards, including DORA, MaRisk, CSSF, NIST, ISO 27000, etc.Test the effectiveness of cybersecurity controls across Encryption, SIEM Logging and Monitoring, Vulnerability Management, SIEM, Penetration Testing, Cloud Security, and other security domains to identify gaps and improvement areasPrepare high quality assurance reports with clear observations, identified risk, and actionable recommendations for management; effectively communicate complex technical issues to both technical and non technical stakeholdersTrack and monitor remediation actions, validate closure, and ensure sustainability of corrective measuresCollaborate with IT, Security teams, and other cross-functional stakeholders to provide risk insights or guidance on risk and control expectations for new and existing systemsContribute to the continuous improvement of assurance methodologies, frameworks, and processesStay updated with emerging cyber threats, industry trends, evolving technologies, cloud risks, and changes in the regulatory landscapeYour profile:Experience: 3 - 7 years of dedicated experience in cyber security audit, second-line assurance, or cybersecurity implementation with a proven track record of leading complex audits/assurance reviews or implementation projects from planning to reportingEducation: Bachelor’s or master’s degree in IT, Information Security, Risk Management, or a related fieldExpert Industry Knowledge: Practical experience in various security domains, such asSIEM / SOC /CERTCloud SecurityEncryptionNetwork SecurityVulnerability ManagementPenetration TestingFrameworks and Standards: Strong knowledge of IT governance and control frameworks such as COBIT, CSA CCM, ISO/IEC 27000 series, ITIL, and relevant EU regulationsProfessional Certifications: Certifications such as CEH, CISA, ISO 27001 LA/LI, CISM, CISSP, CRISC are preferred.Advanced Core Skills:Assurance Skills: Experienced in audit/assurance techniques, developing risk-based testing strategies, sampling methodologies, and mentoring junior team membersAnalytical & Strategic Mindset: Ability to identify root causes, understand cross-domain risk impacts, and translate complex technical and regulatory issues into business implicationsStakeholder Influence: Strong communication, negotiation, and influencing skills; comfortable presenting findings and building credibility with senior stakeholdersThree Lines of Defense: Strong understanding of the Three Lines of Defense modelLanguages: Excellent command of English (written and spoken)