INFORMATION SECURITY MANAGER (f/m/d)

Permanent employee, Full-time · Frankfurt am Main

Your Role
As Information Security Manager and part of the Security & Privacy Governance team, you will steer our ISO 27001:2022 certified information‑security‑management system (ISMS), drive compliance with the EU Digital Operational Resilience Act (DORA), and align our controls to international regulations such as the CFTC System Safeguards Requirements and Singapore’s MAS Technology Risk Management (TRM) Guidelines. 
Your Responsibilities
Governance & ICT Risk

  • ISMS Ownership: Maintain and enhance our ISO 27001:2022 ISMS and policy framework.
  • DORA Alignment:  Implement the act’s requirements on ICT-risk governance, incident reporting and third-party oversight ahead of the 17 Jan 2025 go-live.  
  • Global Regulatory Mapping — ensure our control set also meets CFTC System Safeguards for automated trading systems and MAS TRM principles on governance, access control and cloud security.  
  • ICT-Risk Assessments: Run risk analyses in line with regulations, best practices, Three-Lines-of-Defence model, reporting residual risk to senior management.
Engineering & Operations (First-Line Enablement)

  • Security-by-Design Reviews: Advise product teams on secure architecture, zero-trust networking and segregation of duties.
  • Control Lifecycle: Define, monitor and improve technical controls (vulnerability management, hardening baselines, privileged access) together with Development, Infrastructure, and SRE teams.
  • Tooling Strategy: Manage, use, and optimise our threat intelligence, security events, intrusion detection, deception, and similar platforms. Ensure coverage, effectiveness, efficiency and automation.
Detection & Response

  • Incident Response: Manage the NIST-aligned lifecycle (prepare, detect, contain, eradicate, recover, lessons learned) and meet the multi-jurisdiction requirements and timelines set by our regulators and expected by our clients.
  • Assess & Improve: Use threat intelligence, vulnerability reports, and similar news sources to assess changes in landscape, threats, and best practices, and provide thoughtful, innovative, and practical guidance to improve our processes and systems.
  • Table-Top & Purple-Team Drills: Coordinate regular exercises to validate controls and drive continuous improvement.
People & Culture

  • Awareness & Training: Deliver engaging security-awareness sessions and micro-learnings for developers, sales and operations staff.
  • Client & Audit Liaison: Help answer RFPs, coordinate ISO/DORA and other audits, and support due-diligence requests from counterparties worldwide.
Your Profile
  • University degree in computer science or a comparable education
  • 5+ years of experience in the IT security domain. Certifications are a plus (CISSP, CRISC, CISM, ISO27001 Lead Implementer or Auditor)
  • Working knowledge in implementing and maintaining security certifications (ISAE3402, SOC1, SOC2, ISO2700x) and maintaining compliance to national and international security, data protection, and privacy standards, laws and regulations
  • Experience in the development of practical security processes, policies and standards. Ability to work with multiple, sometime conflicting goals and priorities
  • Experience in the management of information security issues and incidents
  • Excellent analytical and conceptual thinking, able to understand, structure and prepare/explain complex topics on the appropriate level, depending on context and recipient
  • Track record of taking responsibility, working independently and without much supervision
  • Highly motivated to learn about new topics, technologies, and business cases
  • Highly proficient in spoken and written English (CEF C1 or above) is mandatory. Very good command of German language (CEF B2 or above) is desirable
Our Offer
  • Clear career concept
  • Performance appraisals on a regular base
  • Possibility to switch between Software Development teams according to interests, projects, and skills.
  • 360T Academy
  • Frankfurt office located directly in the city center
  • Social gatherings
We offer an outstanding opportunity for a highly motivated individual to participate in the growth of a successful technology company in the financial sector. The position is based in Frankfurt am Main and is available immediately.
How to Apply
If your background and qualifications meet these specifications, please forward your application including your salary expectation and the earliest starting date by clicking the “Apply” button.
Contact
Irune Del Buey
People & Culture Manager

Send email
Grüneburgweg 16-18
60322 Frankfurt am Main
About us
360T is a regulated, global marketplace for Foreign Exchange (FX). As Deutsche Börse Group’s powerhouse for FX, 360T provides a broad range of trading solutions and related services to both buy-side and sell-side firms. 

Since its inception in 2000, the company has developed and maintained a state-of-the-art multi-bank portal for foreign exchange, cash and money market products. It has recently expanded its instrument offering to include crypto NDFs and commodities (base metals and energy).

With over 2,900 buy-side customers and more than 200 liquidity providers across 75 different countries, 360T is uniquely positioned to connect the global FX industry.
Headquartered in Frankfurt am Main, Germany, 360T maintains subsidiaries in New York (360 Trading Networks Inc), London (360 Trading Networks UK Ltd), Singapore (360T Asia Pacific Pte. Ltd.), Mumbai (ThreeSixty Trading Networks (India) Pvt Ltd), Kuala Lumpur (360 Trading Networks Sdn Bhd) and Dubai (360 Trading Networks (DIFC) Limited).
We are looking forward to hearing from you!
Thank you for your interest in 360T. Please fill out the following short form. Should you have difficulties with the upload of your data, please send an email to careers@360t.com.
Uploading document. Please wait.
Please add all mandatory information with a * to send your application.