About this role
About the opportunity
We are seeking an ICT Risk Assessment Manager to join our Information Risk Management (IRM) Segment and work at the heart of ICT Compliance at N26. We’re setting the standard for innovation and excellence in FinTech compliance, embedding it into N26’s culture to ensure that every control, policy, and risk assessment strengthens our position as a leader in the industry. As part of our team, you’ll be at the forefront of building a compliance culture that’s innovative, scalable, and seamlessly integrated into our operations, making compliance a key driver of N26’s competitive advantage.
In this role, you will:
• Lead the lifecycle of ICT risk assessments, from initial risk identification and execution to final remediation monitoring.
• Execute and coordinate ICT Risk Assessments and ICT Audits for third-party tools and services, collaborating closely with Third-Party service providers, Product Owners, Security Engineers, and Data Privacy.
• Provide technical and quality oversight regarding ICT risks, controls, and technologies—including ongoing risk decisions, control implementation, and propose improvement opportunities.
• Act as a subject matter expert, translating complex technical risks into clear, actionable insights, for business and technical teams.
• Conduct security impact assessments on ICT assets and business processes.
• Develop KPIs and KRIs that support the monitoring of ICT third-party risks and reporting to the 2nd line of defense.
• Identify gaps in current frameworks and lead improvement efforts that streamline the team's efficiency and automation.
• Coach and mentor new hires and junior colleagues, through knowledge-sharing, hands-on guidance, and structured feedback.
• Build strong stakeholder relationships through proactive engagement, clear communication, and alignment with organizational priorities.
What you need to be successful:
• 4-5 years experience in information security ICT Risk Management, ICT audits, or related fields.
• Previous experience in the banking/FinTech sector is highly preferred, specifically with an understanding of MaRisk and DORA requirements.
• Proven experience working in a fast-paced, technology-driven business (e.g., a scaled startup), collaborating with security engineers, software developers, product managers, and IT auditors.
• A strong sense of ownership with the ability to inherit a workflow, identify weaknesses, and independently implement optimizations.
• Hands-on experience or advanced knowledge of leveraging AI tools to optimize workflows and overall team productivity.
• Ability to communicate complex technical concepts clearly to both technical peers and non-technical stakeholders of all levels.
• Relevant certifications (CISA, CISM, CRISC) are a plus.
Skills:
• A detail-oriented approach to analyzing technical evidence and documenting findings rigorously.
• A hands-on mentality, eager to suggest, test, and implement process improveme