Welcome to the team: Product Owner – Cyber Hygiene Toolchain (m/f/diverse)

Your tasks
- Acting as Product Owner for the Cyber Hygiene / Vulnerability Management toolchain from a DevSecOps and ITIL perspective;
- Collecting, analysing and documenting requirements from stakeholders in Cyber Security, Infrastructure/Platform, DevOps, IT Operations and Compliance;
- Translating functional and non‑functional requirements into clear user stories, technical specifications and acceptance criteria for engineering and operations teams;
- Ensuring that solutions and workflows derived from these requirements adhere to DevSecOps best practices (automation, integration into CI/CD and SDLC, “security by design”);
- Aligning requirements and resulting implementations with ITIL processes (especially Incident, Problem, Change, Configuration Management and Continual Improvement);
- Maintaining and prioritising the product backlog for the Cyber Hygiene toolchain, balancing risk reduction, regulatory needs and operational feasibility;
- Supporting the design of process flows and integrations (e.g. ticket creation, notification flows, dashboards and reporting) in the existing Vulnerability Management tools;
- Collaborating with Service Management to ensure that requirements are reflected in service definitions, SLAs/OLAs, reporting and KPIs;
- Facilitating refinement, planning and review sessions with cross‑functional teams to ensure common understanding and high‑quality implementation of requirements;
- Gathering feedback from users and stakeholders and convert it into concrete improvement initiatives for our Cyber Hygiene services.
Your profile
- Experience with collecting, analysing and documenting requirements from multiple stakeholder groups.
- Ability to translate business, risk and compliance needs into precise technical user stories and specifications;
- Solid understanding of DevSecOps concepts (security in CI/CD pipelines and SDLC, automation, quality gates);
- Strong capability to design requirements and workflows that integrate security controls into development and operations processes;
- Practical knowledge of ITIL processes (Incident, Problem, Change, Configuration, Continual Improvement);
- Understanding of the vulnerability management lifecycle and typical Cyber Hygiene use cases - familiarity with the capabilities and data of enterprise Vulnerability Management platforms (e.g. Tenable One) to formulate realistic, implementable requirements;
- Experience maintaining and prioritising a product backlog in an agile setup (Scrum, Kanban);
- Experience designing end to end workflows and integration patterns (e.g. ticketing, notifications, dashboards);
- High level of stakeholder management and communication skills; able to moderate between technical and non technical audiences;
- Strong sense of ownership, structured and self driven way of working in an agile, international environment;
- Very good command of English (spoken and written); German is an advantage.
In return, we offer:
- Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
- Luxury package of additional health and dental insurance;
- Food vouchers in the amount of EUR 80 monthly;
- 6 additional annual days off for exceptional circumstances
- Employee assistance program for psychological, financial and legal consultations;
- Multisport card;
- Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
- Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
- Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
- Friendly and supportive multicultural environment, open to new opinions and ideas.
Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.
Our Benefits
Work-life balance; Health& Dental Insurance; Multisport Card; 25 up to 31 annual paid leave; 6 Exceptional Days Off; Food vouchers; Employee assistance program; Children Summer Camp Contribution; Learning Platforms
The company
Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.
As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Product Owner – Cyber Hygiene Toolchain in our Cyber Defense and Base Services team.
Contact
Apply now with your up-to-date CV in English!
Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.

