AI & SDLC Risk Manager (f/m/d)

Date: 6 Oct 2026

Location: Frankfurt am Main, DE

Company: Deutsche Börse Group

Your area of work:

Group ICT Risk acts as the second line of defence for one of the world’s leading financial market infrastructures, overseeing ICT risks across Deutsche Börse Group. As an AI & SDLC Risk Manager, you will assess and challenge the security of AI systems and software development pipelines, translating your engineering background into risk-relevant insights that protect critical market infrastructure. You will be part of a newly built unit operating at the intersection of technology, regulation, and capital markets, working closely with the Group CISO and first-line engineering teams.

 

Your responsibilities:

  • You drive the resilience strategy operationally,  Shift Left (security embedded in development), Shift Down (platform security, OSCAL, infrastructure-as-code, Terraform), Shield Right (vulnerability management, patching, 1D1D), in close collaboration with the Head of ICT Risk
  • You assess AI and Cloud systems, deployed in trading, clearing, and risk environments for AI-specific risks such as adversarial ML, prompt injection, data poisoning, and uncontrolled agent behaviour, and prepare content for management and supervisory bodies
  • You evaluate the maturity of the Secure Software Development Lifecycle (SSDLC) e.g. against IEC 62443-4-1 and the Cyber Resilience Act, and challenge security controls in CI/CD pipelines (SAST, DAST, SCA, container scanning) from an independent second-line perspective
  • You support the SQUARE initiative (Post-Quantum Cryptography) with technical assessments: crypto inventory, evaluation of NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA), and migration readiness of systems and pipelines
  • From time to time, you conduct DORA-compliant application risk assessments and manage observation tracking and remediation follow-up with first-line teams
  • You support internal and regulatory audits (DORA, BaFin, internal audit) and contribute to EU AI Act implementation as a second-line function towards product teams and 1LoD

 

Your profile:

  • You have a background in software engineering or computer science: you have developed and shipped software, can read code, and understand what a CI/CD pipeline does; the programming language is secondary, but the hands-on experience is not
  • You have at least 2 years of professional experience in product delivery, DevOps, or a related engineering field, with a genuine interest in application security, cloud security, or secure development practices
  • You have picked up security concepts through your engineering work, whether via OWASP, CTF participation, open source security contributions, or hands-on use of security tooling (SAST/DAST, container security, SBOM)
  • You can assess what is critical and what is not, even without a formal framework, and you communicate findings clearly to both technical and non-technical audiences
  • You have worked in an agile environment like SCRUM, Kanban or with OKRs
  • Knowledge of cloud security (preferably GCP or Azure), regulatory frameworks (DORA, EU AI Act, CRA), or security certifications (AWS/GCP Security, OSCP, or equivalent) rounds off your profile
  • Proficiency in written and spoken English; German language skills are an asset