About this role
About the opportunity
We are seeking an ICT GRC - ICT Governance Manager to join our CISO Office at N26. In this role, you will drive and evolve our ICT governance framework, ensuring alignment with regulatory requirements, industry standards, and organisational strategy across a fast-paced digital banking environment.
You will work cross-functionally to strengthen governance, operational resilience, audit readiness, and compliance practices, while helping shape innovative and scalable approaches to ICT risk and control management.
In this role, you will:
• Own, define, and continuously evolve the Governance Documentation framework for Information Security within the CISO Office (2nd LoD), including policies, standards, procedures, work instructions, and process flows.
• Ensure governance artifacts remain aligned with regulatory requirements, industry best practices, and organisational strategy.
• Establish clear accountability models and governance operating models across 1st and 2nd line functions.
• Own and strategically develop the Target Measure Catalogue (TMC), ensuring its completeness, regulatory alignment, and operational effectiveness.
• Drive enterprise-wide integration of Target Measure Catalogue requirements into 1st line procedures and operational processes.
• Ensure accurate and traceable mapping of target measures to relevant regulations and standards.
• Oversee change management processes related to TMC updates and regulatory changes.
• Ensure comprehensive mapping of governance controls to regulations such as MaRisk, DORA, AI Act, CRA, PSD3 and standards including ISO 27001/27002, NIST, and other applicable frameworks.
• Drive DORA related activities to ensure operational resilience within the ICT landscape.
• Proactively monitor regulatory developments and translate them into actionable governance enhancements.
• Act as the subject matter expert for ICT Governance during regulatory reviews and supervisory interactions.
• Own the end-to-end delivery of all IT audits related requests for the CISO Office.
• Act as the primary escalation and decision authority for audit findings.
• Ensure timely remediation, sustainable control improvements, and executive-level reporting.
• Define and implement AI-enabled approaches to automate compliance monitoring and control testing.
What you need to be successful:
Background:
• Bachelor’s degree in Information Technology, Computer Science, Information Security, or related field (preferred).
• Professional certifications such as CISA, CISM, CRISC, or equivalent strongly preferred.
• 6+ years of experience in IT governance, risk management, and information security compliance, ideally within banking or financial services.
• Knowledge of regulatory requirements such as MaRisk, DORA, AI Act, CRA, PSD3 and international standards such as ISO 27001/27002, NIST, COBIT.
• Strong understanding of IT infrastructure, cloud security, application security, and enterpri