AI & SDLC Risk Manager (f/m/d)

Deutsche Börse AG • Frankfurt am Main

Build the future of financial markets. Build yours.​

Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 16,000 colleagues around the globe, we actively shape the future of financial markets. Join our One Global Team!

Want to learn more?
Who we are

Who we are

Deutsche Börse Group is one of the world’s leading exchange organisations and an innovative market infrastructure provider. With our products and services, we ensure that capital markets are fair, transparent, reliable, and stable. Together, we develop state-of-the-art IT solutions and offer our IT systems all over the world. Play a key role in our mission: to create trust in the markets of today and tomorrow.

Frankfurt am Main

Your career at Deutsche Börse Group

Your area of work:

Group ICT Risk acts as the second line of defence for one of the world’s leading financial market infrastructures, overseeing ICT risks across Deutsche Börse Group. As an AI & SDLC Risk Manager, you will assess and challenge the security of AI systems and software development pipelines, translating your engineering background into risk-relevant insights that protect critical market infrastructure. You will be part of a newly built unit operating at the intersection of technology, regulation, and capital markets, working closely with the Group CISO and first-line engineering teams.

 

Your responsibilities:

  • You drive the resilience strategy operationally,  Shift Left (security embedded in development), Shift Down (platform security, OSCAL, infrastructure-as-code, Terraform), Shield Right (vulnerability management, patching, 1D1D), in close collaboration with the Head of ICT Risk
  • You assess AI and Cloud systems, deployed in trading, clearing, and risk environments for AI-specific risks such as adversarial ML, prompt injection, data poisoning, and uncontrolled agent behaviour, and prepare content for management and supervisory bodies
  • You evaluate the maturity of the Secure Software Development Lifecycle (SSDLC) e.g. against IEC 62443-4-1 and the Cyber Resilience Act, and challenge security controls in CI/CD pipelines (SAST, DAST, SCA, container scanning) from an independent second-line perspective
  • You support the SQUARE initiative (Post-Quantum Cryptography) with technical assessments: crypto inventory, evaluation of NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA), and migration readiness of systems and pipelines
  • From time to time, you conduct DORA-compliant application risk assessments and manage observation tracking and remediation follow-up with first-line teams
  • You support internal and regulatory audits (DORA, BaFin, internal audit) and contribute to EU AI Act implementation as a second-line function towards product teams and 1LoD

 

Your profile:

  • You have a background in software engineering or computer science: you have developed and shipped software, can read code, and understand what a CI/CD pipeline does; the programming language is secondary, but the hands-on experience is not
  • You have at least 2 years of professional experience in product delivery, DevOps, or a related engineering field, with a genuine interest in application security, cloud security, or secure development practices
  • You have picked up security concepts through your engineering work, whether via OWASP, CTF participation, open source security contributions, or hands-on use of security tooling (SAST/DAST, container security, SBOM)
  • You can assess what is critical and what is not, even without a formal framework, and you communicate findings clearly to both technical and non-technical audiences
  • You have worked in an agile environment like SCRUM, Kanban or with OKRs
  • Knowledge of cloud security (preferably GCP or Azure), regulatory frameworks (DORA, EU AI Act, CRA), or security certifications (AWS/GCP Security, OSCP, or equivalent) rounds off your profile
  • Proficiency in written and spoken English; German language skills are an asset

Why Deutsche Börse Group?

We are committed to providing a work environment where everyone feels welcome and can reach their full potential. Our standards go far beyond simply matching candidates with the right position.

Mobility

We enable you to move freely with our job tickets, job (e-)bikes and free parking opportunities.

Work environment

Collaboration, communication, or deep focus – in our modern office buildings you will find the perfect work environment. Free drinks and food and meal allowances included.

Health and wellbeing

We care for your health and wellbeing and besides various health promotion measures we offer you a group accident insurance and additional insurance offers at discounted rates.

Financial stability

We provide financial stability by offering attractive salaries, company pension schemes, participation in our Group Share Plan, as well as bonuses, subsidies and discounts.

Hybrid work

Collaborate and exchange on-site or work remotely several days a week in line with business needs and local regulations. Our hybrid working model combines the best of both worlds.

Flexible working hours

We want your job to fit your life situation and offer flexible working time models, childcare allowance, or the possibility to study alongside your job.

Internationality

Our market infrastructures are globally connected. Working with us means collaborating with like-minded colleagues across over 60 locations from more than 100 nations.

Development

We promote individual development by offering internal development programmes, mentoring, further education and training budgets.

Contact
Recruiting Team

Recruiting Team

Take your career to the next level with us and embrace new challenges!
 

+496921111810

Our Recruiting Team is looking forward to your call or e-mail.

Ready to start your career with us?

Apply now!