Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 16,000 colleagues around the globe, we actively shape the future of financial markets. Join our One Global Team!
AI & SDLC Risk Manager (f/m/d)
Deutsche Börse AG • Frankfurt am Main
Who we are
Deutsche Börse Group is one of the world’s leading exchange organisations and an innovative market infrastructure provider. With our products and services, we ensure that capital markets are fair, transparent, reliable, and stable. Together, we develop state-of-the-art IT solutions and offer our IT systems all over the world. Play a key role in our mission: to create trust in the markets of today and tomorrow.
Frankfurt am Main
Your career at Deutsche Börse Group
Your area of work:
Group ICT Risk acts as the second line of defence for one of the world’s leading financial market infrastructures, overseeing ICT risks across Deutsche Börse Group. As an AI & SDLC Risk Manager, you will assess and challenge the security of AI systems and software development pipelines, translating your engineering background into risk-relevant insights that protect critical market infrastructure. You will be part of a newly built unit operating at the intersection of technology, regulation, and capital markets, working closely with the Group CISO and first-line engineering teams.
Your responsibilities:
- You drive the resilience strategy operationally, Shift Left (security embedded in development), Shift Down (platform security, OSCAL, infrastructure-as-code, Terraform), Shield Right (vulnerability management, patching, 1D1D), in close collaboration with the Head of ICT Risk
- You assess AI and Cloud systems, deployed in trading, clearing, and risk environments for AI-specific risks such as adversarial ML, prompt injection, data poisoning, and uncontrolled agent behaviour, and prepare content for management and supervisory bodies
- You evaluate the maturity of the Secure Software Development Lifecycle (SSDLC) e.g. against IEC 62443-4-1 and the Cyber Resilience Act, and challenge security controls in CI/CD pipelines (SAST, DAST, SCA, container scanning) from an independent second-line perspective
- You support the SQUARE initiative (Post-Quantum Cryptography) with technical assessments: crypto inventory, evaluation of NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA), and migration readiness of systems and pipelines
- From time to time, you conduct DORA-compliant application risk assessments and manage observation tracking and remediation follow-up with first-line teams
- You support internal and regulatory audits (DORA, BaFin, internal audit) and contribute to EU AI Act implementation as a second-line function towards product teams and 1LoD
Your profile:
- You have a background in software engineering or computer science: you have developed and shipped software, can read code, and understand what a CI/CD pipeline does; the programming language is secondary, but the hands-on experience is not
- You have at least 2 years of professional experience in product delivery, DevOps, or a related engineering field, with a genuine interest in application security, cloud security, or secure development practices
- You have picked up security concepts through your engineering work, whether via OWASP, CTF participation, open source security contributions, or hands-on use of security tooling (SAST/DAST, container security, SBOM)
- You can assess what is critical and what is not, even without a formal framework, and you communicate findings clearly to both technical and non-technical audiences
- You have worked in an agile environment like SCRUM, Kanban or with OKRs
- Knowledge of cloud security (preferably GCP or Azure), regulatory frameworks (DORA, EU AI Act, CRA), or security certifications (AWS/GCP Security, OSCP, or equivalent) rounds off your profile
- Proficiency in written and spoken English; German language skills are an asset
Why Deutsche Börse Group?
We are committed to providing a work environment where everyone feels welcome and can reach their full potential. Our standards go far beyond simply matching candidates with the right position.
Mobility
We enable you to move freely with our job tickets, job (e-)bikes and free parking opportunities.
Work environment
Collaboration, communication, or deep focus – in our modern office buildings you will find the perfect work environment. Free drinks and food and meal allowances included.
Health and wellbeing
We care for your health and wellbeing and besides various health promotion measures we offer you a group accident insurance and additional insurance offers at discounted rates.
Financial stability
We provide financial stability by offering attractive salaries, company pension schemes, participation in our Group Share Plan, as well as bonuses, subsidies and discounts.
Hybrid work
Collaborate and exchange on-site or work remotely several days a week in line with business needs and local regulations. Our hybrid working model combines the best of both worlds.
Flexible working hours
We want your job to fit your life situation and offer flexible working time models, childcare allowance, or the possibility to study alongside your job.
Internationality
Our market infrastructures are globally connected. Working with us means collaborating with like-minded colleagues across over 60 locations from more than 100 nations.
Development
We promote individual development by offering internal development programmes, mentoring, further education and training budgets.
Recruiting Team
Send e-mail E-Mail copied! Copy E-Mail?
Our Recruiting Team is looking forward to your call or e-mail.