Über diese ICT GRC – ICT Compliance Senior Manager Stelle bei N26
About the opportunity
As an ICT Compliance Senior Manager, you will spearhead the strategy and continuous evolution of N26's IT compliance framework within the 2nd Line of Defense. Serving as a central authority in the CISO Office, you will ensure our digital infrastructure seamlessly aligns with stringent EU and German regulations while linking your team's vision directly to company OKRs. Beyond fostering a high-performing culture of mentorship and empowerment, you will pioneer the use of AI and automation to transform compliance monitoring, control testing, and regulatory reporting into highly scalable, modern processes.
In this role, you will:
- Drive the function-wide IT compliance objective and strategy within the 2nd Line of Defense, establishing an aligned vision across multiple teams and reporting to senior leadership.
- Define, maintain, and continuously elevate the target measure catalogue and ICT compliance roadmap, aligning internal security standards with cutting-edge industry practices and regulatory expectations.
- Lead and direct comprehensive, independent second-line compliance assessments of N26's Information Security Management System (ISMS) and ICT control ecosystem.
- Ensure full, end-to-end adherence to key EU and German regulatory frameworks (e.g., DORA, MaRisk, BAIT, CSA, PSD3) and international standards (ISO 27001/27002, NIST).
- Lead strategic regulatory gap analyses, defining clear multi-quarter remediation roadmaps and contributing to key business operational decisions across the organization.
- Own regulatory reporting for ICT compliance, delivering executive-level presentations on compliance posture, risk exposure, and strategic mitigation plans to top management and regulatory authorities.
- Serve as a primary authority and principal contact point for internal audits, external audits, and regulatory examinations for the CISO Office.
- Champion AI-enabled compliance monitoring, automation initiatives, and second-line control testing to maximize efficiency, accuracy, and operational impact.
- Communicating context to team members, surfacing appropriate issues to upper management, and constructively managing conflict and change.
- Independently audit and challenge 1st line ICT processes and information domain controls—specifically regarding DORA compliance—evaluating control design and operating effectiveness to guarantee sustainable remediation.
- Orchestrate DORA and broader ICT compliance initiatives across 2nd line functions, delegating work effectively, setting team KPIs, and collaborating across business units.
- Assist with annual planning, staffing, and expense prioritization while actively participating in hiring, mentoring team members, delegating work effectively, and driving a strong culture of feedback.
What you need to be successful:
Background:
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Information Security, or a related field.
- Professional certifications strongly preferred (e.g., CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer, CISSP).
- 8+ years of progressive experience in IT risk management, ICT compliance, or information security, with significant leadership exposure in banking, fintech, or regulated financial services.
- Proven track record of defining strategy, driving cross-team roadmaps, and owning regulatory compliance programs at a senior level.
- Deep mastery of European and German financial regulatory frameworks (DORA, MaRisk, BAIT, PSD3/PSD2, CSA) and security frameworks (ISO 27000 series, NIST CSF).
- Comprehensive technical grasp of cloud security, modern software architecture, application security, microservices, and IT infrastructure resilient controls.
Skills:
- Strategic and conceptual leadership: Ability to build an aligned vision across teams, drive function objectives, and contribute to business operational decision-making.
- Team Leadership & Talent Development: Experience in leading a team, delegating effectively, managing team productivity, mentoring colleagues, and fostering a robust feedback culture.
- Executive Communication & Stakeholder Alignment: Ability to build and maintain strong relationships with Leadership, Regulators, and other senior members of the organization by communicating context clearly, proactively surfacing key risks early and the ability to have difficult conversations constructively.
- Advanced Risk & Control Architecture: Strong ability to evaluate control design, challenge 1st line execution, and map complex regulatory directives into scalable security requirements for the organization.
- Change & Conflict Management: Comfort with direct, constructive conflict resolution, guiding teams through organizational change, and addressing performance or behavioral challenges positively.
- Planning & Execution: Proven ability to manage roadmaps, KPIs, project delivery, and assist with annual planning and budget allocation.
- Tooling Expertise: Proficiency with enterprise GRC tools, risk management software, and modern collaboration tools (JIRA, Confluence, FigJam).
- Professional working proficiency in English and German is required.
Traits:
- Strong sense of functional ownership, accountability, and strategic bias for action.
- Empathetic listener who remains objective, empowers others to make decisions, and drives collective team impact.
- Comfortable confronting negative behavior constructively and challenging stakeholders across all levels of the bank.
- Resilient, adaptable, and highly analytical leader capable of navigating complex, fast-changing regulatory dynamics.
- Highest ethical standards with an uncompromised commitment to confidentiality, integrity, and data protection.
What’s in it for you:
- Accelerate your career growth by joining one of Europe’s most talked about disruptors 🚀.
- Employee benefits that range from a competitive personal development budget, work from home budget, discounts to fitness & wellness memberships, language apps and public transportation.
- As an N26 employee you will have access to a Premium subscription on your personal N26 bank account. As well as subscriptions for friends and family members.
- Additional day of annual leave for each year of service.
- A high degree of autonomy and access to cutting edge technologies - all while working with a friendly team of peers of diverse nationalities, experiences, and backgrounds.
- A relocation package with visa support for those who need it.
Who we are
N26 has reimagined banking for today’s digital world. Technology and design empower everything we do and it’s how we are building the global banking platform the world loves to use.
We've eliminated physical branches, paperwork, and hidden fees for an elegant digital experience and supreme savings. Giving people the power to live and bank their way is what gets us out of bed in the morning and inspires the work that we do.
We are headquartered in Berlin with offices in multiple cities across Europe, including Vienna and Barcelona, and a 1,500-strong team of more than 80 nationalities.
Do you see yourself thriving in this role? We’d love to see your application even if you don’t meet 100% of the criteria. You may just be the right fit for this or other roles!
Equal opportunities for all
At N26, we believe our strength lies in our people and the varied perspectives they bring. We strive to build diverse teams that drive innovation and business success. We actively seek talent from all backgrounds and welcome applications from all genders, cultures, sexual orientations, abilities, neurodiversities, and ages.
We are committed to providing an excellent and accessible candidate experience. If you require any accommodations to make this process work for you, please let us know. We’re here to support you!
Discover more about Diversity & Inclusion at N26: https://n26.com/en-eu/diversity-and-inclusion