ICT Risk Governance Specialist (f/m/d)

Date: 24 Aug 2026

Location: Luxembourg, LU Eschborn, DE

Company: Deutsche Börse Group

Your area of work:

The ICT Risk Governance team is responsible for establishing and steering second-line ICT risk governance across Clearstream's post-trade entities. The function drives the evolution of the ICT Risk Framework and ensures alignment with business objectives, risk appetite, regulatory requirements, and operational resilience expectations.

 

You will contribute to the development and maintenance of ICT risk governance processes, support board-level reporting and regulatory engagements, coordinate risk assessments and audits, and help drive harmonized ICT risk management practices across legal entities. You will work closely with ICT, business, compliance, audit, and risk stakeholders to strengthen digital operational resilience and governance effectiveness.

 

Your responsibilities:

  • Support the development, maintenance, and continuous improvement of the ICT Risk Framework, ensuring alignment with regulatory requirements, risk appetite, and business objectives.
  • Coordinate ICT risk governance activities across post-trade entities, promoting consistent governance standards, reporting methodologies, and decision-making principles.
  • Prepare and maintain ICT risk reports, management information, and governance committee materials for senior management and legal entity governance bodies.
  • Support regulatory inspections, internal audits, external assessments, and remediation tracking by maintaining accurate documentation, evidence, and action plans.
  • Provide ICT risk guidance and advisory services for material changes, outsourcing arrangements, information classification, ICT incidents, and strategic initiatives.
  • Contribute to ICT risk awareness initiatives, resilience exercises, automation opportunities, and continuous enhancement of governance processes and reporting capabilities

Your profile:

  • University degree in Information Security, Information Technology, Computer Science, Risk Management, Business Administration, or a related discipline.
  • 3–4 years of professional experience in ICT Risk Management, Information Security, Operational Risk, IT Governance, Internal Audit, or related control functions.
  • Strong understanding of ICT risk frameworks, digital operational resilience, outsourcing risk management, governance processes, and regulatory environments (e.g., DORA, EBA Guidelines, NIS2, ISO 27001).
  • Experience in preparing management reports, governance presentations, audit documentation, and regulatory deliverables for senior stakeholders.
  • Excellent analytical, organizational, and stakeholder management skills with the ability to coordinate activities across multiple functions and legal entities.
  • Professional proficiency in English; German language skills are considered an advantage.