IT Risk Manager

Job type:Permanent
Town/City:Hamburg
Region:Hamburg
Sector:Cyber Security
Client Company Type:In-House
Job ref:10700
Post Date:September 17, 2026

About the Role

IT Risk Manager

The Opportunity

Tired of writing risk reports nobody actually reads? This role is built for someone who wants risk management to mean something, not just tick a box.

You'll join an established international business to bring order and follow-through to IT risk across a large, complex organisation. The frameworks exist. What's needed is someone who makes sure they're used, understood, and acted on.

The Role

  • Maintain a practical framework for identifying, tracking, and closing out IT-related risk
  • Keep risk categorisation and control standards consistent across teams
  • Turn scattered risk data into reporting leadership can actually use
  • Chase open issues until they have an owner and a resolution, not just a log entry
  • Partner with recovery planning colleagues so IT can bounce back fast when things break
  • Work alongside security, infrastructure, and delivery teams to catch risk early in projects
  • Act as the go-to contact for risk-related questions across the business
  • Support audits and regulatory reviews, keeping documentation audit-ready

The Company

Our client is an established international business with a large, complex IT organisation. Risk and continuity sit high on the agenda here, and this role has real visibility with senior stakeholders as a result. You'll be operating across borders and functions, working with people who take risk seriously rather than treating it as paperwork.

What You'll Need

  • 3+ years focused on IT risk, operational risk, or continuity, within a 5+ year IT career
  • Practical knowledge of recognised risk and control frameworks
  • Familiarity with continuity or disaster recovery standards
  • Exposure to ITIL-based ways of working
  • Experience operating in international, cross-functional settings
  • Fluent English

How to Apply

Your CV doesn't need to be up to date. Send what you have, or just give us a call.

More Jobs from this Recruiter

Hamburg, Hamburg

IT Risk Manager

IT Risk Manager The Opportunity Tired of writing risk reports nobody actually reads? This role is built for someone who wants risk management to mean something, not just tick a box. You'll join an established international business to bring order and follow-through to IT risk across a large, complex organisation. The frameworks exist. What's needed is someone who makes sure they're used, understood, and acted on. The Role Maintain a practical framework for identifying, tracking, and closing out IT-related risk Keep risk categorisation and control standards consistent across teams Turn scattered risk data into reporting leadership can actually use Chase open issues until they have an owner and a resolution, not just a log entry Partner with recovery planning colleagues so IT can bounce back fast when things break Work alongside security, infrastructure, and delivery teams to catch risk early in projects Act as the go-to contact for risk-related questions across the business Support audits and regulatory reviews, keeping documentation audit-ready The Company Our client is an established international business with a large, complex IT organisation. Risk and continuity sit high on the agenda here, and this role has real visibility with senior stakeholders as a result. You'll be operating across borders and functions, working with people who take risk seriously rather than treating it as paperwork. What You'll Need 3+ years focused on IT risk, operational risk, or continuity, within a 5+ year IT career Practical knowledge of recognised risk and control frameworks Familiarity with continuity or disaster recovery standards Exposure to ITIL-based ways of working Experience operating in international, cross-functional settings Fluent English How to Apply Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More
Mannheim, Baden-Württemberg

SOC Lead

SOC Lead Ready to Build Something That Doesn't Exist Yet? Most SOC roles ask you to maintain. This one asks you to create. A global industrial technology business, over 175 years old and still innovating, has made cyber security a boardroom priority. They're building their CDC from the ground up, and they need a Lead who can architect the entire function: strategy, processes, automation, tooling, and a team of analysts to back it up. This is a rare opportunity to put your name on something. No inherited processes. No legacy decisions to unpick. Just a clear mandate, executive backing, and the freedom to do it right. What You'll Be Doing You'll take end-to-end ownership of the CDC — defining how it operates, how it scales, and how it matures. Day to day, that means: Designing and owning all CDC processes, SOPs, runbooks, and playbooks — building from scratch, not from a template Leading an automation-first approach: implementing and continuously improving SOAR capabilities to cut manual workload and sharpen response times Developing the CDC roadmap with a clear eye on regulatory requirements including NIS2 and ISO 27001 Acting as incident manager for critical events — staying strategic, not getting pulled into the weeds Integrating OT security requirements into centralised monitoring alongside IT environments Selecting, optimising, and managing the security technology stack — SIEM, SOAR, XDR Leading, mentoring, and developing a team of 3–5 security analysts Reporting CDC performance to senior leadership through meaningful KPIs (MTTD, MTTR) The Company You'll be joining a global industrial technology business with a 175-year track record of innovation. The organisation operates across IT and OT environments at scale — which means the security challenges here are genuinely complex, and the investment behind this function is real. Cyber security has moved firmly onto the executive agenda. You'll have the organisational weight behind you to build this properly. What You'll Need Solid experience in a SOC, CDC, or Information Security leadership environment A process-first mindset — you think in workflows, not just incidents Hands-on experience with SOAR platforms and an instinct for automation Familiarity with SIEM and XDR tooling Working knowledge of relevant frameworks and standards — NIST, SANS, ISO/IEC 27001, NIS2 Experience leading and developing security analysts Business-level German and strong English — you'll need both Comfortable with on-call responsibilities and major incident availability How to Apply You can apply directly through this page, or reach out to the consultant listed in this advert if you'd prefer a conversation first. Your CV doesn't need to be polished or up to date — send what you have. If this sounds like the right move, we'd rather hear from you early than not at all.
Learn More
Frankfurt, Hessen

Product Owner Cyber Hygiene

Vice Director Cyber Hygiene  Location: Frankfurt Our client is seeking a Vice Director Cyber Hygiene to support the operational and strategic development of its cyber hygiene and vulnerability management function. This role focuses on vulnerability scanning, tooling integration and the coordination of security operations within a complex environment. Key Responsibilities: Oversee day-to-day cyber hygiene and vulnerability management activities. Support vulnerability scanning operations and exposure management initiatives. Coordinate the integration and optimisation of security tooling and platforms. Collaborate with internal stakeholders on operational and security-related topics. Support the implementation of strategic security initiatives across the function. Contribute to operational governance, reporting and continuous improvement activities. Assist with the development and scaling of security operations capabilities. Your Profile: Strong experience within vulnerability management or cyber hygiene environments. Hands-on knowledge of Tenable One or comparable vulnerability management platforms. Understanding of security operations, scanning technologies and exposure management. Experience working within large or regulated environments would be advantageous. Strong communication and stakeholder management skills. Independent and solution-oriented working style. Fluent German and English language skills. What’s on Offer? Senior position within an international security environment. Exposure to large-scale cyber security and transformation initiatives. Collaborative and modern working culture. Long-term development and progression opportunities.
Learn More
Frankfurt, Hessen

Threat Intelligence (Senior Business Expert)

Threat Intelligence Expert Frankfurt  We are seeking a Threat Intelligence Business Expert to join the Cyber Security Division of a leading financial service provider in Frankfurt. You will be responsible for delivering high-quality intelligence products, engaging with internal security teams, and contributing to the company’s intelligence-led security posture across a fast-moving and complex threat environment. Key Responsibilities  Produce tactical, operational, and strategic threat intelligence products for technical and non-technical audiences including SOC, Incident Response, Risk, and senior management. Analyse threat actor activity targeting the financial sector Manage and optimise threat intelligence feeds and platforms, supporting integration with SIEM and SOAR tooling. Engage with internal stakeholders across Vulnerability Management, Red Team, and Compliance to ensure intelligence drives operational outcomes. Support DORA-aligned ICT risk reporting and contribute to the continuous improvement of intelligence processes and workflows. Key Requirements  5–7 years of cyber security experience Strong knowledge of the threat landscape relevant to financial institutions, including e-crime, ransomware, fraud, and account takeover. Proficiency with the MITRE ATT&CK framework and structured analytic techniques. Awareness of DORA and BaFin regulatory expectations for cybersecurity within EU financial institutions. Relevant certifications desirable: CREST CTIA, GIAC GCTI (FOR578), or equivalent. Fluent in both German and English  
Learn More

Latest Blogs

View all blogs