RefolkCandidates
Open now

ICT GRC - ICT Governance Senior Manager

N26 · Berlin

Location
Berlin
Level
Manager
Posted
Today

About this role

About the opportunity

As ICT Senior Governance Manager, you will own the strategic direction, execution, and continuous evolution of ICT Governance within the CISO Office (2nd Line of Defense), including oversight of Firewall Governance as part of your team's remit. You'll operate with full autonomy and accountability, both for the frameworks the function owns and for the people who run them day to day.

You will act as a trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities while enabling the organisation to innovate responsibly. As the primary escalation point for audit findings and regulatory reviews, you'll represent ICT Governance in high-stakes conversations and make sure your team has the context and support to do the same in their own areas.

Just as important as the governance mandate is the team behind it: you will lead and develop ICT Governance and Firewall Governance professionals, building a team others want to be part of. As regulatory and technological demands keep evolving, you'll help modernise how governance gets done - exploring AI-enabled approaches to compliance monitoring and control assurance. If you want the scope of a strategic governance mandate and the accountability of leading a team, this is your opportunity.

In this role, you will:

  • Own, define, and continuously evolve the ICT/Information Security governance documentation framework within the CISO Office - policies, standards, procedures, work instructions, and process flows - and establish clear accountability models across 1st and 2nd line functions.
  • Own and strategically develop the Target Measure Catalogue (TMC), ensuring its completeness, regulatory alignment, and accurate mapping to relevant regulations and standards.
  • Drive enterprise-wide integration of TMC requirements into 1st-line procedures, and oversee change management as the TMC and regulatory landscape evolve.
  • Ensure governance controls remain comprehensively and traceably mapped to relevant regulations (MaRisk, DORA, AI Act, CRA, PSD3) and standards (ISO 27001/27002, NIST), proactively translating regulatory developments into governance enhancements.
  • Drive DORA-related activities to strengthen operational resilience across the ICT landscape.
  • Act as subject matter expert for ICT Governance during regulatory reviews, supervisory interactions, and audits.
  • Own end-to-end delivery of IT audit-related requests for the CISO Office, acting as primary escalation and decision authority for findings, and ensuring timely, sustainable remediation with clear reporting to senior stakeholders.
  • Provide governance oversight of firewall and network security controls delivered by the team - rule reviews, segmentation assurance, control testing - ensuring they meet internal policy and regulatory expectations.
  • Lead, manage, and grow the ICT Governance team, spanning ICT Governance and Firewall Governance - own hiring, onboarding, task delegation, and day-to-day performance.
  • Own team planning and resourcing - staffing needs, workload distribution, and development priorities - in partnership with the department lead.
  • Coach team members toward independent judgement rather than directing every decision, and contribute to hiring decisions across the wider governance function.
  • Act as trusted advisor to senior stakeholders, aligning regulatory expectations with business priorities, and represent the function's work to bodies such as the Non-Financial Risk Committee.
  • Translate regulatory and security requirements into terms 1st-line technical teams can act on, and run enablement sessions to build shared governance literacy.
  • Define and implement AI-enabled approaches to automate compliance monitoring and control testing.

What you need to be successful:

Background:

  • Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field.
  • Professional certifications such as CISA, CISM, CRISC, or equivalent strongly preferred.
  • 8+ years of experience in ICT/information security governance, risk management, or compliance, ideally within banking or financial services - including experience leading, mentoring, or developing others.
  • Strong knowledge of regulatory requirements (MaRisk, DORA, AI Act, CRA, PSD3) and international standards (ISO 27001/27002, NIST, COBIT).
  • Working understanding of network and perimeter security governance (firewall management, segmentation, second-line assurance) sufficient to lead and quality-assure a specialised team; hands-on firewall certifications are a plus, not required.
  • Demonstrated experience leveraging automation or AI tools to strengthen governance and compliance frameworks.

Skills:

  • Strong strategic thinking, translating regulatory complexity into practical governance frameworks in a fast paced environment.
  • Proven leadership and stakeholder management across 1st and 2nd line functions.
  • Team Leadership & Talent Development: Experience in leading a team, delegating effectively, managing team productivity, developing team members toward independent judgement and fostering a robust feedback culture.
  • Executive Communication & Stakeholder Alignment: Ability to build and maintain strong relationships with Leadership, Regulators, and other senior members of the organization by communicating context clearly, proactively surfacing key risks early and the ability to have difficult conversations constructively.
  • Excellent analytical and problem-solving capabilities in complex regulatory environments.
  • Advanced project and program management, able to run parallel initiatives independently.
  • Fluency in English and German (spoken and written) required.

Traits:

  • Strong sense of ownership and accountability - operates independently without supervision.
  • Strategic mindset balanced with attention to detail.
  • Comfortable challenging the status quo and driving organisational change.
  • Genuinely invested in developing people, not just delivering projects.
  • High ethical standards and integrity, with a strong commitment to confidentiality and data protection.
  • Resilient and adaptable in a fast-changing, regulated environment.

What’s in it for you:

  • Accelerate your career growth by joining one of Europe’s most talked about disruptors 🚀.
  • Employee benefits that range from a competitive personal development budget, work from home budget, discounts to fitness & wellness memberships, language apps and public transportation.
  • As an N26 employee you will have access to a Premium subscription on your personal N26 bank account. As well as subscriptions for friends and family members.
  • Additional day of annual leave for each year of service.
  • A high degree of autonomy and access to cutting edge technologies - all while working with a friendly team of peers of diverse nationalities, experiences, and backgrounds.
  • A relocation package with visa support for those who need it.

Who we are

N26 has reimagined banking for today’s digital world. Technology and design empower everything we do and it’s how we are building the global banking platform the world loves to use.

We've eliminated physical branches, paperwork, and hidden fees for an elegant digital experience and supreme savings. Giving people the power to live and bank their way is what gets us out of bed in the morning and inspires the work that we do.

We are headquartered in Berlin with offices in multiple cities across Europe, including Vienna and Barcelona, and a 1,500-strong team of more than 80 nationalities.

Do you see yourself thriving in this role? We’d love to see your application even if you don’t meet 100% of the criteria. You may just be the right fit for this or other roles!

Equal opportunities for all

At N26, we believe our strength lies in our people and the varied perspectives they bring. We strive to build diverse teams that drive innovation and business success. We actively seek talent from all backgrounds and welcome applications from all genders, cultures, sexual orientations, abilities, neurodiversities, and ages.

We are committed to providing an excellent and accessible candidate experience. If you require any accommodations to make this process work for you, please let us know. We’re here to support you!

Discover more about Diversity & Inclusion at N26: https://n26.com/en-eu/diversity-and-inclusion

As published by N26. Applications are handled on their site.

About N26

N26 SE is Europe’s leading digital bank with a full German banking licence. Built on the latest technology, N26’s mobile banking experience makes managing money easier, more secure and customer friendly. N26 is headquartered in Berlin with offices in multiple cities across Europe, including Vienna and Barcelona, and a 1,500-strong team of more than 90 nationalities. Founded by Valentin Stalf and Maximilian Tayenthal in 2013, N26 has raised close to US$ 1.8 billion from some of the world’s most renowned investors. Need support? Please send us a direct message over on our N26 Support LinkedIn page: http://www.linkedin.com/company/n26support. Our team is here to help. Social media imprint and privacy policy: https://n26.com/en-de/social-media-imprint-and-privacy-policy

All 81 openings at N26

One click, then it is written

Apply to N26 with a resume written for this role.

Queue ICT GRC - ICT Governance Senior Manager and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in N26’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at N26

See all

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board N26 publishes. Refolk is not the employer and does not handle their hiring. Applications go to N26 directly.