Now hiring

AI & SDLC Risk Manager (f/m/d) (Frankfurt am Main, DE) @ Deutsche Börse AG

Frankfurt am Main, DEOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Your area of work: Group ICT Risk acts as the second line of defence for one of the world’s leading financial market infrastructures, overseeing ICT risks across Deutsche Börse Group. As an AI & SDLC Risk Manager, you will assess and challenge the security of AI systems and software development pipelines, translating your engineering background into risk-relevant insights that protect critical market infrastructure. You will be part of a newly built unit operating at the intersection of technology, regulation, and capital markets, working closely with the Group CISO and first-line engineering teams. Your responsibilities: You drive the resilience strategy operationally, Shift Left (security embedded in development), Shift Down (platform security, OSCAL, infrastructure-as-code, Terraform), Shield Right (vulnerability management, patching, 1D1D), in close collaboration with the Head of ICT Risk You assess AI and Cloud systems, deployed in trading, clearing, and risk environments for AI-specific risks such as adversarial ML, prompt injection, data poisoning, and uncontrolled agent behaviour, and prepare content for management and supervisory bodies You evaluate the maturity of the Secure Software Development Lifecycle (SSDLC) e.g. against IEC 62443-4-1 and the Cyber Resilience Act, and challenge security controls in CI/CD pipelines (SAST, DAST, SCA, container scanning) from an independent second-line perspective You support the SQUARE initiative (Post-Quantum Cryptography) with technical assessments: crypto inventory, evaluation of NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA), and migration readiness of systems and pipelines From time to time, you conduct DORA-compliant application risk assessments and manage observation tracking and remediation follow-up with first-line teams You support internal and regulatory audits (DORA, BaFin, internal audit) and contribute to EU AI Act implementation as a second-line function towards product teams and 1LoD Your profile: You have a background in software engineering or computer science: you have developed and shipped software, can read code, and understand what a CI/CD pipeline does; the programming language is secondary, but the hands-on experience is not You have at least 2 years of professional experience in product delivery, DevOps, or a related engineering field, with a genuine interest in application security, cloud security, or secure development practices You have picked up security concepts through your engineering work, whether via OWASP, CTF participation, open source security contributions, or hands-on use of security tooling (SAST/DAST, container security, SBOM) You can assess what is critical and what is not, even without a formal framework, and you communicate findings clearly to both technical and non-technical audiences You have worked in an agile environment like SCRUM, Kanban or with OKRs Knowledge of cloud security (preferably GCP or Azure), regulatory frameworks (DORA, EU AI Act, CRA), or security certifications (AWS/GCP Security, OSCP, or equivalent) rounds off your profile Proficiency in written and spoken English; German language skills are an asset

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores