Information Security Controls Manager - Cloud & AI Governance
at N26
- Location
- Berlin
- Posted
- 5d ago
at N26
<h2><strong>About the opportunity</strong></h2> <p>We are seeking an <strong>Information Security Controls Manager</strong> to join the Information Risk Management (IRM) Segment within the Information Security (IS) Controls team at N26. As a member of this team, you will contribute to ensuring that Information Security Controls Framework processes are operated without any disruptions, <strong>with a specialized focus on strengthening our Cloud Security posture and AI Governance frameworks.</strong> N26 and its subsidiaries operate in a variety of regulatory environments and across international boundaries, while the IRM team helps N26 to navigate this complex, demanding, and rapidly evolving technological landscape.</p> <h2><strong>In this role, you will:</strong></h2> <ul> <li>Frequently communicate with various stakeholders of all levels.</li> <li>Execution and review of the Information Security (IS) Controls Framework monitoring process, ensuring comprehensive coverage of cloud infrastructure and AI/ML deployments.</li> <li>Communicate, Collate and review the evidence received via monthly control review request tickets (TOE).</li> <li>Perform QA reviews, query and or seek clarification from stakeholders to achieve the objectives of controls effectiveness.</li> <li>Highlight the gaps/risks observed during reviews, raise non-conformities, particularly concerning cloud misconfigurations and AI model risks, and suggest improvements to the teams or stakeholders.</li> <li>Liaise with the CISO office and the DPO office to provide updates on a monthly basis over the status of controls, including compliance updates regarding cloud security and AI systems.</li> <li>Improve awareness of controls, security practices, and responsible AI utilization among stakeholders.</li> <li>Contribute to the team in developing KRIs<strong> </strong>tailored to traditional IT, Cloud environments, and AI use cases.</li> <li>Working independently and managing the IS Controls daily tasks.</li> <li>Review and update the design of the controls pages from a technical perspective and maintain the control calendar.</li> <li>Actively work on the change requests from stakeholders.</li> <li>Preparation and follow-up of Change Request tickets.</li> <li>Drafting and publishing of the monthly control reports & other documentation (MoMs).</li> <li>Support the team and stakeholders during audits and coordinating the action items and evidence.</li> <li>Maintain controls team’s key documentation to ensure audit readiness.</li> <li>Equally participate in designing controls, developing working instructions and procedures that are required based on security standards and regulations such as ISO 27001, EU GDPR, DORA, SWIFT, NIS2,<strong> </strong>and the EU AI Act.</li> <li>Evaluate and map internal control frameworks to cloud security benchmarks (e.g., Cloud Security Alliance (CSA), BSI C5) and AI governance frameworks.</li> <li>Facilitate and make sure that all key processes have been documented in an easy and efficient process flow.</li> <li>Design and update working instructions to implement the requirements coming from the policies.</li> <li>Identify and surface process or tooling-related inefficiencies and support AI enabled process optimizations</li> <li>Mapping of Internal control framework to the various regulations/Standards.</li> </ul> <h2><strong>What you need to be successful:</strong></h2> <ul> <li>Bachelor’s or Master’s degree, relevant to information security or computer science.</li> <li>You have approximately 4-6 years of experience in an information security compliance, risk, or audit role.</li> <li>Demonstrated experience or strong knowledge of Cloud Security controls (AWS/Google Cloud preferred) and AI/ML governance risk frameworks.</li> <li>Previous hands-on experience or knowledge on security standards such as ISO 27001, ISO42001, NIST, <strong>BSI C5</strong>, and other regulatory requirements like DORA, <strong>EU AI Act</strong>, EU CRA & EU GDPR.</li> <li>Good understanding of Information & Communication Technologies (ICT) and Security controls. Previous experience related to audit/compliance frameworks and methodologies is a plus.</li> <li>Ability to communicate clearly with peers, as well as stakeholders of all levels.</li> <li>You are proficient in using Jira, Confluence and Google Workspace apps. (i.e. Docs, Sheets, Slides). Good understanding of Google Sheets features and formulas.</li> <li>Previous experience with Compliance tools is a plus (i.e. ServiceNow, OneTrust..).</li> <li>Ability to analyze and evaluate documentation, reports, data, flowcharts etc., for IT processes such as system development, cloud infrastructure management, and IT operations.</li> <li>Fluency in English is strictly required. German proficiency is a plus.</li> <li>You have insight into information security and are willing to become deeply acquainted with EU regulatory laws, standard banking requirements, as well as cloud-native banking IT-Systems.</li> <li>You have a hands-on mentality and are comfortable to share improvement ideas about existing processes.</li> </ul> <h2><strong>What’s in it for you:</strong></h2> <ul> <li>Accelerate your career growth by joining one of Europe’s most talked about disruptors 🚀.</li> <li>Employee benefits that range from a competitive personal development budget, work from home budget, discounts to fitness & wellness memberships, language apps and public transportation. </li> <li>As an N26 employee you will have access to a Premium subscription on your personal N26 bank account. As well as subscriptions for friends and family members. </li> <li>Additional day of annual leave for each year of service. </li> <li>A high degree of autonomy and access to cutting edge technologies - all while working with a friendly team of peers of diverse nationalities, experiences, and backgrounds. </li> <li>A relocation package with visa support