Welcome to the team:
Specialist in Standards and Frameworks (m/f/diverse)

  • Function
    Function:
    Risk / Credit / Financing
  • Location
    Location:
    Praha

Group ICT-Risk and Resilience Management is responsible for the group-wide management of cyber and information security risks. It ensures an adequate level of (cyber) security in Commerzbank through clearly defined roles and responsibilities within the security organization. GRM-ICT RRM serves as the second line of defense (2LoD) for managing cyber and information security risks across Commerzbank. GRM-ICT RRM establishes the ICT Policy & Control Framework, sets standards, monitors compliance, and assesses ICT risks to ensure adherence to regulatory requirements, such as the Digital Operational Resilience Act (DORA).

We are seeking a Specialist Information Security to join our 2LoD team in Prague, contributing to robust ICT governance, risk, and compliance (GRC) processes through effective risk assessment, reporting, and policy development. As a Specialist in Standards and Frameworks, you will play an important role in enhancing Commerzbank’s security framework. Your expertise in information security will ensure a resilient ICT environment aligned with regulatory and internal standards.

n. Is there a possibility of career advancement, a strong corporate culture, or above-standard benefits? This is the right place to state that.

Your tasks

  • Update ICT security policies and guidelines, as well as processes and procedures, particularly during significant changes in the cyber threat landscape.
  • Measure/ monitor the implementation of security policies and guidelines.
  • Maintain Commerzbank's ISPF/ISCF as part of the written regulations. Further development in compliance with the requirements of a major bank and international standards for ICT-related cyber and information security. The guiding standards chosen by Commerzbank AG ISO 2700x and NIST CSF are given special consideration.
  • Implement communication channels between organizational units.

Your Profile

  • Completed degree in computer science or business informatics, or vocational training in IT, commercial, business, or technical fields, ideally supplemented with certifications like CISA, CISM, CISSP, or equivalent training.
  • Good knowledge of the Digital Operational Resilience Act (DORA) regulation and standards for information security and risk management (e.g., NIST, ISMS according to ISO 27001), as well as essential legal and regulatory requirements for information security.
  • Interest and/or experience in data analysis, agile working methods, project management, and digitalization processes
  • Strong analytical, conceptual, and strategic thinking skills, along with confident appearance and assertiveness.
  • Initiative, persuasive power, readiness to perform, and teamwork skills, along with an enthusiasm for dealing with complex issues.
  • Excellent communication skills in English written and spoken.

Our Benefits

  • 30 days of vacation
  • Employer-funded pension
  • Flexible work
  • Employee conditions
  • Digital learning
  • Diversity
  • Family & job friendly
  • Friendly work environment
  • Inspiring company culture
  • Work-life balance

30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance

The company

Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create a positive impact in the banking world.  

Contact

In case of interest please apply via this job portal.