Information Security Manager - Risk Management (m/w/d)
Core
Lead quantitative security risk management and third-party risk assessments for a global SaaS/cloud organization, reporting to C-Level.
Role type
Senior IC information security manager (risk management)
Builds
Quantitative risk scenarios, risk portfolios, and C-Level risk reports
Domain
Information security, risk management, cloud/SaaS architecture
Required skills
Quantitative risk analysis (FAIR), scenario-based estimation, third-party risk assessment, cloud architecture understanding, audit support, risk culture development
Preferred skills
CRISC, CISM, CISSP, ISO 27005, Open FAIR, Jira, Confluence, GRC tools (via careerplan.io/jobs/2833845-information-security-manager-risk-management-mwd-at-docuware-gmbh)
Technologies
Microsoft Azure, Jira, Confluence, GRC tools
Responsibilities
Evaluate incoming security incidents and moderate risk scenario formulation with risk owners; estimate frequencies and damages to calculate expected annual loss; assess third-party suppliers throughout their lifecycle; support internal control frameworks and audits (ISO 27001, SOC 2); develop risk methodology and train risk owners
Seniority
Senior, hands-on IC
