Senior Analyst - Information Security Risk Analyst
Deutsche Börse Group
Job Description
About Deutsche Börse Group:
Headquartered in Frankfurt, Germany, Deutsche Börse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and companies by facilitating access to global capital markets.
Their India centre is located in Hyderabad, serves as a key strategic hub and comprises Indias top-tier tech talent. They focus on crafting advanced IT solutions that elevate market infrastructure and services.
Deutsche Börse Group in India is composed of a team of capital market engineers forming the backbone of financial markets worldwide.
Division:
- Deutsche Börse AG, Chief Information Officer/Chief Operating Officer (CIO/COO), Chief Technology Officer (CTO), Plan & Control
- Field of activity
- The Deutsche Börse CTO develops and runs the groupwide Information Technology (IT) infrastructure, develops and operates innovative IT products and offers services to the rest of the Group upon which they can build. The CTO area plays a significant role in the achieving the Groups strategic goals by leading transformation and supporting a stable operating environment.
- The Transformation Office unit supplies reliable project management capabilities and information security management to the CTO and enables the other delivery units within the area to rollout IS compliance requirements and Group IS strategy.
- The successful candidate will join the Information Security, Risk & Regulatory unit and support in carrying out these responsibilities.
Tasks/responsibilities:
Risk Assessment & Analysis:
- Support CTO teams in conducting regular risk assessments by guiding them through the process.
- Supervise risk tickets and coordinate with application/asset owners to raise extension or closure requests to avoid overdue items.
- Assist application/asset owners in creating ad-hoc risk entries, handling risks and closing them.
Reporting andMonitoring:
- Prepare and present risk status reports to various stakeholders.
- Track and report metrics related to risk exposure and remediation progress.
- Support the creation and operation of the Unit Information Security Committee.
- Maintain and update the knowledge database in Confluence.
Qualifications/required skills:
- Bachelors degree in Computer Science, Cybersecurity, Information Systems, or related field.
- 13 years of experience in information security, or risk management
- Strong understanding of risk assessment concepts (risk mitigation, acceptance, avoidance, threat modelling, CIA triad).
- Structured with strong problem-solving abilities and analytical mindset.
- Effective communication and stakeholder management skills.
- Preferrable knowledge of Information Security frameworks (ISO 27001, NIST).
- Certifications such as CISM, CRISC, CISA, CompTIA Security+ are a plus.