Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 15,000 colleagues around the globe, we actively shape the future of financial markets. Join our One Global Team!
Information Security Specialist (f/m/d)
Deutsche Börse AG • Frankfurt am Main
Who we are
Deutsche Börse Group is one of the world’s leading exchange organisations and an innovative market infrastructure provider. With our products and services, we ensure that capital markets are fair, transparent, reliable, and stable. Together, we develop state-of-the-art IT solutions and offer our IT systems all over the world. Play a key role in our mission: to create trust in the markets of today and tomorrow.
Frankfurt am Main
Your career at Deutsche Börse Group
The successful candidate will join the Information Security, Risk & Regulations unit of the CTO. The Information Security, Risk & Regulatory unit supports the CTO product lines to comply with the ICT Risk Framework, by continuously improving existing controls, analyzing security gaps identified by control functions and designing and implementing suitable solutions in collaboration with the products. The unit works closely with stakeholders across the Group to close or mitigate these gaps and ensure sustainable remediation. Through these activities, the unit directly contributes to improving the Information Security KPIs vulnerability SLA adherence, findings, coverage of the CTO IT assets and represents the CTO area in the group wide Security Committee thus strengthening the overall security posture of the organization.
Your responsibilities:- Lead Vulnerability Quality & Drive Resolution Across Teams
- Ensure that vulnerabilities generated by scanners are high quality, actionable, and correctly classified.
- Design and enhance processes that make vulnerability intake, triage, and escalation predictable, transparent, and efficient.
- Take ownership of escalated blockers, partnering with engineering, cloud, and platform teams to remove obstacles and drive real remediation progress.
- Identify cross product patterns and help improve our scanning approach to increase accuracy and reduce operational friction.
- Partner closely with our CTO Hyderabad Vulnerability Operations team to ensure smooth and efficient daily handling without any overdue.
- Align with Group Information Security to evolve scanning capabilities in line with organizational needs.
- Support integration of security controls into CI/CD pipelines and cloud environments.
- Shape Secure Architecture & Influence Technical Direction
- As part of projects or regular releases, contribute to solution designs for alignment with our security standards and architectural principles.
- Challenge designs with a constructive, solution-oriented mindset, helping teams build secure, scalable, and resilient systems.
- Build Relationships & Drive Security Culture Forward
- Build trusted partnerships with Group Information Security, DevSecOps, Cloud Infrastructure, application owners, and operations teams.
- Communicate security topics clearly and constructively, tailoring your message to technical and non‑technical audiences.
- Act as a facilitator who aligns teams, resolves blockers, and helps everyone move forward in the same direction.
Your profile:
- Minimum 5 years of experience as Information Security professional.
- Solid experience in Vulnerability Management or Security Operations, including working with enterprise scanning tools.
- Strong understanding of cloud environments and the integration of security controls into CI/CD workflows.
- Experience reviewing solution architectures, identifying gaps, and providing actionable security recommendations.
- Ability to collaborate with globally distributed teams and proactively resolve blockers across engineering, cloud, and platform domains.
- Strong communication skills, including the ability to translate complex security topics for both technical and nontechnical audiences.
- Proven capability to drive processes, improve operational workflows, and ensure high-quality outputs (e.g. ticket intake, triage, classification).
- Constructive, solution-oriented mindset with strong analytical and problem-solving skills.
- Ability to work independently, prioritize effectively, and drive initiatives end-to-end.
- Strong relationship building capability and a collaborative approach.
- Comfortable navigating ambiguity and influencing decisions without formal authority.
- Proficiency in written and spoken English required.
- A relevant degree, or equivalent practical experience, in Information Technology, Computer Science, Cybersecurity, Engineering, or a related technical field.
- Hands-on experience with cloud platforms (Azure, GCP) and containerized environments (Kubernetes, Docker).
- Familiarity with secure coding practices, CI/CD orchestration tools, and infrastructure-as-code concepts.
- Experience working with or alongside enterprise InfoSec teams and central governance bodies.
- Security-related certifications (e.g., CISSP, CISM, CCSP, CEH, GIAC) are a strong plus.
- Previous engaging experience with stakeholders across architecture, engineering, and operational teams—acting as a facilitator and bridge-builder.
Why Deutsche Börse Group?
We are committed to providing a work environment where everyone feels welcome and can reach their full potential. Our standards go far beyond simply matching candidates with the right position.
Mobility
We enable you to move freely with our job tickets, job (e-)bikes and free parking opportunities.
Work environment
Collaboration, communication, or deep focus – in our modern office buildings you will find the perfect work environment. Free drinks and food and meal allowances included.
Health and wellbeing
We care for your health and wellbeing and besides various health promotion measures we offer you a group accident insurance and additional insurance offers at discounted rates.
Financial stability
We provide financial stability by offering attractive salaries, company pension schemes, participation in our Group Share Plan, as well as bonuses, subsidies and discounts.
Hybrid work
Collaborate and exchange on-site or work remotely several days a week in line with business needs and local regulations. Our hybrid working model combines the best of both worlds.
Flexible working hours
We want your job to fit your life situation and offer flexible working time models, childcare allowance, or the possibility to study alongside your job.
Internationality
Our market infrastructures are globally connected. Working with us means collaborating with like-minded colleagues across over 60 locations from more than 100 nations.
Development
We promote individual development by offering internal development programmes, mentoring, further education and training budgets.
Recruiting Team
Send e-mail E-Mail copied! Copy E-Mail?
Our Recruiting Team is looking forward to your call or e-mail.