Technology Risk & Security Manager (m/f/d)
In Germany- Berlin
| Bonn | Cologne | Frankfurt/Main | Hamburg | Munich
This role serves as the
bridge between business demand, IT architecture, cybersecurity, SOC, audit,
compliance, procurement, privacy, and implementation teams - operating within
the company’s Technology Demand Intake Process, which is closely connected to
implementation and lifecycle governance.
This individual will focus on reviewing technical concepts, stand-alone
products, services, and AI-enabled solutions that the company plans to
implement or integrate into its complex global enterprise technology landscape,
including SaaS, PaaS, SAP, and AI-enabled platforms.
You will be responsible for assessing and governing new technology demands,
services, platforms, and AI-enabled solutions through the organization’s
technology intake process. The role ensures that security, compliance, architecture, operational, and
business risks are identified, clearly documented, and addressed through
effective and practical mitigation measures
What makes us special: - Advance your career with exciting professional opportunities in our thriving company with a startup feel.
- Voice your unique ideas in a corporate culture defined by openness and integrity.
- Enjoy the opportunity to work from abroad (workation).
- Feel at home working with our helpful, enthusiastic colleagues who have great team spirit.
- Broaden your perspective with our extensive training curriculum and learning programs (e.g. LinkedIn Learning).
- Speak your mind in our holistic feedback and development processes (e.g. 360-degree feedback).
- Satisfy your need for adventure with our opportunities to live and work abroad in one of our many international offices
- Enjoy our benefits, such as hybrid working, daycare allowance, corporate discounts, and wellbeing support (e.g. Headspace).
- Unwind in our break areas where you can help yourself to the healthy snacks and beverages provided.
- See another side of your coworkers at our frequent employee events and highly anticipated World Meeting and Holiday Party.
How you will create an impact:
- Manage the
end-to-end Technology Demand Intake and Risk Assessment process for new
technologies, platforms, tools, and AI-enabled solutions.
- Assess security,
compliance, operational, vendor, and architecture risks; identify
mitigation strategies and recommend risk treatment decisions.
- Prepare
executive-ready reports and present findings to IT leadership, governance
boards, and risk committees.
- Partner with
Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and
business stakeholders to evaluate and approve technology solutions.
- Ensure new
technologies comply with security policies, controls, and integration
requirements.
- Maintain risk
documentation, exception records, control evidence, and governance
reporting while continuously improving intake processes.
- Stay current on
emerging technologies, AI, cybersecurity trends, regulatory requirements,
and industry control frameworks.
- Translate
business requirements into security and compliance recommendations that
enable timely technology decisions.
- Communicate
complex technical concepts through presentations, decision papers, and
executive-facing materials.
- Facilitate
collaboration across IT architecture, infrastructure, business teams,
vendors, and other stakeholders.
- Support vendor
assessments, RFPs, technical evaluations, and solution reviews.
- Contribute to
cross-functional IT projects by identifying dependencies, risks, and
process improvements.
- Work effectively
in agile, global project environments with multiple priorities and tight
timelines.
About you: - Experience in
a complex global environment, comparable consulting or service
industries is preferred.
- Bachelor’s
Degree required – preferred in the area of Technology, MIS, Cybersecurity,
etc.
- 5+ years of
experience in technology risk, cybersecurity, IT governance, GRC, IT
audit, security architecture, or technology consulting.
- Strong knowledge
of cybersecurity, technology risk management, compliance, enterprise IT
governance, and emerging AI-enabled technologies.
- Experience
assessing SaaS, cloud, third-party, and AI-enabled solutions, with the
ability to identify risks, mitigation strategies, and implementation
requirements.
- Experience
improving governance processes, workflows, standards, and risk management
practices.
- Knowledge of
security and governance frameworks such as ISO 27001, SOC 2, ITIL, or
similar.
- Experience with
security controls, risk assessments, compliance, audit support, and
governance approval processes.
- Ability to
evaluate platform architecture, integrations, identity and access
management, data flows, encryption, logging, monitoring, and operational
security.
- Understanding of
enterprise architecture, cloud security, vendor risk management, and
secure technology implementation.
- Strong
stakeholder management skills with experience working across IT, Security,
Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business
teams.
- Experience
preparing executive-level presentations, risk reports, and decision-ready
documentation, and presenting recommendations to senior leadership.
- Experience
evaluating third-party vendors, cloud platforms, SaaS solutions, and
managed services within global IT environments.
- Experience
supporting technology onboarding, vendor risk assessments, procurement,
RFPs, and cross-functional technology initiatives.
- Ability to
manage risks, remediation activities, project dependencies, and
implementation progress across the technology lifecycle.
- CISSP, CISM,
CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent
certification (or comparable hands-on experience).
Have we sparked your interest? Simply click the 'Apply now' button to submit your application. Please note that, for data protection reasons, we cannot accept applications via email.
Would you like to learn more about us and our company culture? Click here to watch our recruitment video.
About Simon-Kucher
Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. As a trusted commercial advisor focused on unlocking better growth, we combine deep consulting expertise, growth specialization, and technology to scale lasting impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value. With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist. simon-kucher.com
We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.
Your personal contact:
Christina Jaup-Schwilk
recruitment.germany(at)simon-kucher.com
Please submit your application exclusively via the “Apply now” button!
Better growth starts here. With you.