Skip to main content

Information Security Manager (m/f/d) - Ownership in Open Finance

Qwist GmbH - Germany (Berlin), Qwist GmbH - Germany (Munich), Qwist GmbH - Germany (Remote)
Full-time
Permanent employee

Your Role

​​​​​You don't just want to manage information security and ICT risk but you want to drive it? As Information Security Manager (m/f/d) you own our ISMS under ISO 27001 and hold the ICT Risk Management Function under DORA from risk assessment to ICT incident classification and third-party risk oversight. You work closely with Engineering and Platform to embed security directly into our development processes, and you're the central point of contact for internal and external audits. You report directly to the Management Board and work closely with our Chief Legal Officer. We're not looking for administrators, but people who take ownership and want to grow with us.

What You'll Do
  • ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
  • ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments – including preparing and steering certification and surveillance audits.
  • Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
  • Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
  • Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
  • Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
  • Security Operations: Initiate penetration tests, run security incident response from triage through post-incident review, and strengthen security awareness across the company through training and workshops.

What You Bring

  • A degree in information security, computer science, law/compliance or a comparable qualification, plus relevant professional experience in information security and ICT risk management
  • Solid hands-on experience operating an ISO 27001 ISMS, including ownership of documentation, controls and compliance activities
  • Experience working directly with software engineering, product or DevOps teams in a technology-led environment
  • Knowledge of DORA, and first practical exposure to MaRisk or comparable frameworks (NIS2, BAIT/KAIT) is explicitly welcome – we'll support you in becoming an expert here
  • A strong hands-on mentality, analytical thinking, and the ability to manage multiple topics and stakeholders in a dynamic environment
  • Confident communication in German and English, with both technical and non-technical audiences

What we offer

  • Impact & Ownership: Direct reporting lines to C-level and an environment where your ownership is valued and strengthened.
  • Flexibility: A modern, hybrid working model across our Berlin and Munich locations. We work in a hybrid setup, with a strong focus on teamwork and efficient collaboration.
  • Personal growth: We support your development with a personal budget, semi-annual feedback, and clear growth paths.
  • Pioneering spirit: Become part of a team with genuine passion for the future of open banking.

Diversity is welcome!
Don't tick every single box? At Qwist we value diverse perspectives and experiences. If you're excited about this role but your background doesn't perfectly match every point, we encourage you to apply anyway. You might be exactly who we're looking for!

Qwist is proud to be an equal-opportunity employer that values diversity. We do not discriminate on the basis of race, religion, ethnic or national origin, gender identity, sexual orientation, age, marital status, or disability status.

About us


Qwist is a leader in Open Finance, helping organizations unlock, analyze, and leverage financial data. With 100 employees across Europe and more than 100 clients – including leading banks, insurers, and automotive platforms – we provide regulated, secure access to 99% of all bank accounts in the DACH region and beyond.