Manager ICT Third Party Risk

Job type:Permanent
Town/City:Frankfurt
Region:Hessen
Sector:Cyber Security
Client Company Type:In-House
Job ref:10537
Post Date:August 24, 2026

About the Role

Manager ICT & Information Security Third Party Risk – 2nd Line of Defence 

The Opportunity

If your current role only lets you flag risk after the decision's already been made, this one is different.

Here, you sit in the second line of defence with a genuine mandate to challenge. You'll assess how external providers handle security and technology risk, then push back when what you see doesn't meet the bar, regardless of how senior the stakeholder is on the other side of the table.

You'll work across Information Security, IT, Procurement and Operational Risk, with direct visibility into risk committees and senior management reporting.

The Role

You'll independently review and challenge the first line's risk assessments for third-party providers, from critical suppliers to cloud vendors and outsourcing partners.

  • Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners
  • Challenge the first line on identified risks, controls, remediation plans and risk acceptances
  • Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience
  • Support and help shape the TPRM and Information Security Risk frameworks
  • Monitor third-party incidents, vulnerabilities and control weaknesses through to remediation
  • Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk
  • Prepare risk reporting for senior management and risk committees
  • Support internal audits and regulatory assessments

Your findings feed directly into how the organisation manages its third-party exposure, giving you visibility that's hard to get in a first-line role.

The Company

Our client is a well-established, regulated financial services organisation with a mature second-line risk function. Its size and regulatory footprint mean third-party risk is treated as a genuine priority, not a box-ticking exercise, and the frameworks you'll work within are built to hold up under real regulatory scrutiny.

What You'll Need

  • Several years' experience in Information Security, ICT, Third Party or Cyber Risk
  • Solid knowledge of TPRM processes and third-party security assessments
  • Familiarity with ISO 27001, DORA, NIS2 and EBA requirements
  • Knowledge of cloud security, IAM, vulnerability management, incident response and cyber resilience
  • Confidence to independently challenge the first line and communicate risk to senior stakeholders
  • Fluent German and English

How to Apply

Interested? Your CV doesn't need to be up to date. Send what you have, or just give us a call, and we'll talk you through the details.

More Jobs from this Recruiter

Frankfurt, Hessen

Manager ICT Third Party Risk

Manager ICT & Information Security Third Party Risk – 2nd Line of Defence  The Opportunity If your current role only lets you flag risk after the decision's already been made, this one is different. Here, you sit in the second line of defence with a genuine mandate to challenge. You'll assess how external providers handle security and technology risk, then push back when what you see doesn't meet the bar, regardless of how senior the stakeholder is on the other side of the table. You'll work across Information Security, IT, Procurement and Operational Risk, with direct visibility into risk committees and senior management reporting. The Role You'll independently review and challenge the first line's risk assessments for third-party providers, from critical suppliers to cloud vendors and outsourcing partners. Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners Challenge the first line on identified risks, controls, remediation plans and risk acceptances Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience Support and help shape the TPRM and Information Security Risk frameworks Monitor third-party incidents, vulnerabilities and control weaknesses through to remediation Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk Prepare risk reporting for senior management and risk committees Support internal audits and regulatory assessments Your findings feed directly into how the organisation manages its third-party exposure, giving you visibility that's hard to get in a first-line role. The Company Our client is a well-established, regulated financial services organisation with a mature second-line risk function. Its size and regulatory footprint mean third-party risk is treated as a genuine priority, not a box-ticking exercise, and the frameworks you'll work within are built to hold up under real regulatory scrutiny. What You'll Need Several years' experience in Information Security, ICT, Third Party or Cyber Risk Solid knowledge of TPRM processes and third-party security assessments Familiarity with ISO 27001, DORA, NIS2 and EBA requirements Knowledge of cloud security, IAM, vulnerability management, incident response and cyber resilience Confidence to independently challenge the first line and communicate risk to senior stakeholders Fluent German and English How to Apply Interested? Your CV doesn't need to be up to date. Send what you have, or just give us a call, and we'll talk you through the details.
Learn More
Germanwide, Nordrhein-Westfalen

Associate Partner Cyber Security Sales

Associate Partner Cyber Security Sales The Opportunity If you're already winning Cyber Security business for someone else, when do you start building something that's genuinely yours? This role gives you ownership of a strategic sales pipeline within an established consulting business, with real autonomy to grow it your way. You'll be measured on revenue and account growth, and there's a genuine path to Partner level for the person who delivers. The Role You'll identify and win enterprise Cyber Security clients across Germany, running full sales cycles from first contact through to proposal, negotiation and close. You'll build direct relationships with CISOs, CIOs and CTOs, working as a trusted advisor rather than a vendor. You'll also take ownership of a set of existing strategic accounts, finding ways to expand the Cyber Security services they already buy. This isn't a delivery role. You won't be running projects yourself. Your job is to open doors, grow revenue, and help shape where the Cyber Security practice goes next, including feeding into go-to-market strategy and tracking regulatory and market developments that create new commercial opportunities. You'll work closely with colleagues across the wider consulting business, drawing on their relationships and expertise to open doors you couldn't reach alone. The Company You'll be joining an established consulting organisation whose Cyber Security practice is still being shaped, not one that's already fixed in place. That means real influence over how the practice grows, who it targets, and how it's positioned in the German market. It's a business with the scale and credibility to open enterprise doors, but with enough flexibility that a strong commercial lead can still make their mark and be recognised for it. What You'll Need Significant experience in Cyber Security consulting, professional services or technology advisory A demonstrable track record of Cyber Security sales and revenue generation Proven success winning new enterprise clients in Germany Experience growing and expanding existing strategic accounts An established network of senior decision-makers in the German market Comfort engaging credibly with CISO, CIO, CTO and executive-level stakeholders Fluent German and strong English How to Apply Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role. Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More
Prague, Breclav

ICT Cyber Strategy & Risk Framework Manager

ICT Cyber Strategy & Risk Framework Manager The Opportunity We are partnering with a major international financial services organisation in Prague that is looking to strengthen its Cyber Security and ICT Risk function with an experienced ICT Cyber Strategy & Risk Framework Manager. This is a highly visible position focused on shaping and developing the organisation's ICT and Cyber Risk strategy, governance and risk management framework across a complex financial environment. You will work closely with senior stakeholders across Cyber Security, Technology, Risk, Compliance and the wider business, helping ensure that ICT and cyber risks are identified, assessed and managed effectively. The Role Own and continuously develop the ICT & Cyber Risk Management Framework, ensuring alignment with the organisation's wider risk strategy. Define and drive the ICT and Cyber Risk strategy, policies, standards and governance structures. Establish appropriate risk methodologies, controls, risk appetite and reporting mechanisms. Ensure alignment with relevant financial services regulations and frameworks, including DORA, NIS2, EBA requirements, ISO 27001 and NIST. Identify, assess and challenge ICT and cyber risks across technology and business functions. Support the development of KRIs, risk reporting, dashboards and management information for senior leadership. Provide strategic guidance on technology risk, cyber resilience, third-party risk and emerging security threats. Work closely with senior stakeholders across IT, Cyber Security, Operational Risk, Compliance and Internal Audit. Present ICT and cyber risk topics to senior management and relevant governance committees. Drive continuous improvement of the organisation's overall ICT and cyber risk maturity. What You'll Need Strong professional experience within ICT Risk, Cyber Risk, Technology Risk, Information Security Governance or Cyber Security Strategy. Proven experience developing or managing ICT/Cyber Risk frameworks within a complex organisation. Strong understanding of financial services regulation, particularly DORA and broader ICT risk requirements. Knowledge of frameworks such as ISO 27001, NIST, COBIT or similar. Experience working with senior stakeholders and communicating complex technology risks at management level. Ability to combine strategic thinking with strong risk and governance expertise. Previous experience within banking, insurance or wider financial services is highly desirable. Strong communication, stakeholder management and influencing skills. Fluent Czech is mandatory, alongside strong professional English. Willingness to work onsite in Prague. How to Apply Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role.
Learn More
German wide, Baden-Württemberg

Director Cyber Security

Director, Cyber Security Consulting The Opportunity Ready to step into a role where your name is on the door, not buried in an org chart? This is a Director-level position with genuine weight behind it - the kind of opportunity to shape a cyber security practice, own client relationships, and make decisions that matter. If you're a senior consultant who's been doing the work but not getting the platform, this is worth reading. The Role You'll lead complex cyber security consulting engagements across Germany, working with clients across sectors on strategy, risk, architecture, and programme delivery. At Director level, that means driving business development as much as delivery - building relationships, identifying opportunities, and bringing in the mandates as well as executing them. You'll be a visible figure in the market, representing the practice externally and mentoring the consultants around you internally. Expect variety: no two clients are the same, and the work spans the full spectrum of cyber security advisory. The Company Our client is a specialist consulting business with a strong footprint in the German market. They're known for the quality of their advisory work and the calibre of the people they hire. This is not a firm where Directors spend their time managing PowerPoint. The environment is fast-moving, collegial, and built around people who are genuinely expert in what they do. What You'll Need Significant experience in cyber security consulting, with a track record at senior level Proven ability to develop and convert business development opportunities Deep fluency in the German market and the cyber security landscape within it Native or near-native German, with strong English alongside Credibility with C-suite stakeholders and the confidence to lead from the front How to Apply Send your CV to the MAM Gruppe team. It doesn't need to be up to date - send what you have, or just get in touch for a conversation.
Learn More

Latest Blogs

View all blogs