CRIT Information Security Officer (f/m/d)
Date: 13 Aug 2026
Location: Frankfurt am Main, DE
Company: Deutsche Börse Group
Your area of work:
- The CRIT Information Security Officer is a key member of the CRIT Information Security Office, responsible for strengthening Eurex Clearing's security posture through effective vulnerability management, network security controls, and automation — including the strategic use of AI technologies.
- This role operates within a multidisciplinary team that manages IT audit readiness, remediation and finding management, IT Outsourcing, IT Compliance, IT resilience, and broader IT governance and risk reporting processes.
- You will contribute to the organization's overall security strategy and support consolidated IT and Information Security status reporting for executive leadership and the board of Eurex Clearing AG (ECAG).
Your responsibilities:
- Understand and apply requirements of applicable regulations impacting Information Security and IT, with a particular focus on DORA, NIS2, and BSI-related standards.
- Plan, execute, improve, and document vulnerability management and network security controls.
- Maintain and structure technical Information Security documentation for IT applications and infrastructure, including IT suppliers within Clearing and Risk IT.
- Maintain an overview of IT and non-IT assets relevant for IT asset management, including stakeholder interfaces to Group IT, Information Security, BCM, Outsourcing, and supplier monitoring processes.
- Review and maintain IT Risk Management and IT Continuity Management processes and procedures for ECAG, including outsourced services.
- Align with stakeholders to prevent gaps, issues, or regulatory findings related to the surveillance of IT suppliers.
- Analyze automation potential and implement AI-based tools to enhance the team's effectiveness.
- Contribute to drafting IT and Information Security status reports for the executive board of Eurex Clearing AG.
Your profile:
- University or Master's degree in Information Security, Computer Science, or a comparable qualification.
- At least 2 years of relevant professional experience in IT or Information Security.
- Strong understanding of security frameworks (ISO 27001, NIST, CIS Controls) and risk management methodologies.
- Experience in scripting and automation (e.g. Python, PowerShell) and familiarity with AI-based security technologies.
- Knowledge of audit processes and IT compliance requirements; experience with DORA and EMIT is an asset.
- Experience preparing executive or board-level reporting.
- Strong analytical skills combined with a hands-on, result-oriented working style.
- Good communication, planning, and prioritization skills with intercultural competence.
- Proficiency in written and spoken English; German language skills are an asset.
Nice to have:
- Expertise in IT process standards such as ITIL or COBIT.
- Hands-on experience with AI tools in a professional or security context.
- Familiarity with ISO 2700x, DORA, NIS2, or BSI frameworks beyond foundational knowledge.