Information Security Controls Manager
Job description
About the role
We are seeking an Information Security Controls Manager to join the Information Risk Management (IRM) Segment within the Information Security (IS) Controls team at N26. You will own the operation, maintenance, and continuous improvement of the Information Security Controls Framework with a specialized focus on strengthening our Cloud Security posture and AI Governance frameworks. In this capacity, you will ensure that control processes run seamlessly across N26 and its subsidiaries, navigating a complex and rapidly evolving technological landscape across multiple regulatory environments and international boundaries. You will act as a key driver in monitoring, testing, and validating the effectiveness of security controls while fostering a culture of security awareness and responsible AI usage. Your work will directly support the CISO office and DPO office by providing clear, timely updates on the status of controls and compliance.
Key facts
What you'll do
Frequently communicate with various stakeholders of all levels to ensure alignment on security objectives and control outcomes.
Execution and review of the Information Security (IS) Controls Framework monitoring process, ensuring comprehensive coverage of cloud infrastructure and AI/ML deployments.
Communicate, Collate and review the evidence received via monthly control review request tickets (TOE) to validate control performance.
Perform QA reviews, query and or seek clarification from stakeholders to achieve the objectives of controls effectiveness and completeness.
Highlight the gaps/risks observed during reviews, raise non-conformities, particularly concerning cloud misconfigurations and AI model risks, and suggest improvements to the teams or stakeholders.
Liaise with the CISO office and the DPO office to provide updates on a monthly basis over the status of controls, including compliance updates regarding cloud security and AI systems.
Improve awareness of controls, security practices, and responsible AI utilization among stakeholders through targeted communication and training initiatives.
Contribute to the team in developing KRIs tailored to traditional IT, Cloud environments, and AI use cases to enable proactive risk management.
Working independently and managing the IS Controls daily tasks with a high degree of ownership and accountability.
Review and update the design of the controls pages from a technical perspective and maintain the control calendar to ensure accuracy and relevance.
Actively work on the change requests from stakeholders, assessing impact and facilitating timely implementation.
Preparation and follow-up of Change Request tickets to ensure proper documentation, approval, and traceability.
Drafting and publishing of the monthly control reports & other documentation (MoMs) to provide transparent reporting to internal stakeholders and auditors.
Support the team and stakeholders during audits and coordinating the action items and evidence collection in a structured manner.
Maintain controls team's key documentation to ensure audit readiness and quick retrieval of evidence.
Equally participate in designing controls, developing working instructions and procedures that are required based on security standards and regulations such as ISO 27001, EU GDPR, DORA, SWIFT, NIS2, and the EU AI Act.
Evaluate and map internal control frameworks to cloud security benchmarks (e.g., Cloud Security Alliance (CSA), BSI C5) and AI governance frameworks to ensure alignment with industry best practices.
Facilitate and make sure that all key processes have been documented in an easy and efficient process flow to support scalability and consistency.
Design and update working instructions to implement the requirements coming from the policies and regulatory obligations.
Identify and surface process or tooling-related inefficiencies and support AI enabled process optimizations to increase effectiveness and reduce manual effort.
Mapping of Internal control framework to the various regulations/Standards to ensure comprehensive coverage and traceability.
Requirements
Bachelor's or Master's degree, relevant to information security or computer science.
You have approximately 4-6 years of experience in an information security compliance, risk, or audit role.
You have demonstrated experience or strong knowledge of Cloud Security controls (AWS/Google Cloud preferred) and AI/ML governance risk frameworks.
You possess previous hands-on experience or knowledge on security standards such as ISO 27001, ISO42001, NIST, BSI C5, and other regulatory requirements like DORA, EU AI Act, EU CRA & EU GDPR.
You have a good understanding of Information & Communication Technologies (ICT) and Security controls.
Previous experience related to audit/compliance frameworks and methodologies is a plus.
You can communicate clearly with peers, as well as stakeholders of all levels, including non-technical audiences.
You are proficient in using Jira, Confluence and Google Workspace apps, with a good understanding of Google Sheets features and formulas.