Logo for Qwist

Information Security Manager (m/f/d) - Ownership in Open Finance

Role overview

Qualifications

  • Degree in information security, computer science, law/compliance or comparable qualification
  • Relevant professional experience in information security and ICT risk management
  • Solid hands-on experience operating an ISO 27001 ISMS
  • Knowledge of DORA and exposure to MaRisk or comparable frameworks

Responsibilities

  • Hold the ICT Risk Management Function under DORA, maintain the ICT risk framework
  • Develop ISMS in line with ISO 27001, define baseline controls, and run continuous maturity assessments
  • Own audit evidence for DORA and ISO 27001, run internal self-audits, and coordinate with external audit partners
  • Work closely with Software Engineering and DevOps to embed security and compliance requirements into development processes

About the company

Qwist logo

Qwist

Financial Services

Qwist is the leading, independent Open Banking platform provider in Europe. It enables companies across a multitude of industries to provide the next generation of financial services by understanding how customers transact and interact. With its “full-stack” platform of solutions, Qwist makes it possible for its clients to compliantly access the financial transactions data of customers, enrich said data with analytics tools, provide digital banking services and deliver high-quality, digital financial services products and services to customers. Qwist is a regulated payment institution under the Payment Services Supervision Act (Zahlungsdiensteaufsichtsgesetz - ZAG). The company employs around 80 people from more than 35 countries in its offices in Berlin, Hamburg, and Madrid.

Company details

Company typeScaleup
IndustryFinancial Services
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Your Role

​​​​​You don't just want to manage information security and ICT risk but you want to drive it? As Information Security Manager (m/f/d) you own our ISMS under ISO 27001 and hold the ICT Risk Management Function under DORA from risk assessment to ICT incident classification and third-party risk oversight. You work closely with Engineering and Platform to embed security directly into our development processes, and you're the central point of contact for internal and external audits. You report directly to the Management Board and work closely with our Chief Legal Officer. We're not looking for administrators, but people who take ownership and want to grow with us.

What You'll Do

  • ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments – including preparing and steering certification and surveillance audits.
  • Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Security Operations: Initiate penetration tests, run security incident response from triage through post-incident review, and strengthen security awareness across the company through training and workshops.


What You Bring

  • A degree in information security, computer science, law/compliance or a comparable qualification, plus relevant professional experience in information security and ICT risk management
  • Solid hands-on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities
  • Experience working directly with software engineering, product or DevOps teams in a technology-led environment
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is explicitly welcome – we'll support you in becoming an expert here
  • A strong hands-on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment
  • Confident communication in German and English, with both technical and non-technical audiences


What we offer

  • Impact & Ownership: Direct reporting lines to C-level and an environment where your ownership is valued and strengthened.
  • Flexibility: A modern, hybrid working model across our Berlin and Munich locations. We work in a hybrid setup, with a strong focus on teamwork and efficient collaboration.
  • Personal growth: We support your development with a personal budget, semi-annual feedback, and clear growth paths.
  • Pioneering spirit: Become part of a team with genuine passion for the future of open banking.

Diversity is welcome!
Don't tick every single box? At Qwist we value diverse perspectives and experiences. If you're excited about this role but your background doesn't perfectly match every point, we encourage you to apply anyway. You might be exactly who we're looking for!

Qwist is proud to be an equal-opportunity employer that values diversity. We do not discriminate on the basis of race, religion, ethnic or national origin, gender identity, sexual orientation, age, marital status, or disability status.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

IT Security Manager Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.