Senior Security Risk Manager (all genders)

Location
Berlin
Contract
Full time
Job Category
Cybersecurity

THE ROLE & THE TEAM
 

As a Senior Security Risk Manager in the Information Security - Security Risk & Governance Team, you will be at the forefront of safeguarding trust for our customers, stakeholders, and employees. By expertly identifying, assessing, and managing security risks, you will directly influence the security posture of our internal applications and third-party relationships, becoming the go-to expert and a key architect of our evolving Security Risk Management process.

INCLUSIVE BY DESIGN
 

At Zalando, our vision is to be the leading pan-European ecosystem for fashion and lifestyle e-commerce - one that is inclusive by design. We only assess candidates based on qualifications, merit, and business needs. We welcome applications from people of all gender identities, sexual orientations, personal expressions, racial identities, ethnicities, religious beliefs, and disability statuses. We only want to know why you’re great for this role, so please avoid including your picture, age, and marital status in your CV as well.

We want to provide you with a great candidate experience. Please feel free to inform us of any accommodations you may need, so we can best support and assist you throughout the hiring process.

do.BETTER - our diversity & inclusion strategy: https://jobs.zalando.com/en/our-culture/diversity-and-inclusion


 

WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)
 

  • Manage Security Compliance: Implement, maintain, and continuously improve the information security compliance framework.

  • Ensure Regulatory Adherence: Monitor, enforce, and advise on compliance with DORA, GDPR, PCI-DSS, SOC2, NIST CSF, and other relevant regulations.

  • Develop Security Governance: Contribute to the creation, review, and upkeep of information security policies, procedures, and controls.

  • Drive Risk Management: Design, implement, and maintain the information security risk management framework for projects, systems, and processes.

  • Measure Risk Management Effectiveness: Develop KPIs to track the effectiveness of risk management efforts.

  • Report to Leadership: Prepare and present regular reports on security risks, compliance, and improvements.



WE'D LOVE TO MEET YOU IF
 

  • You have 6+ years of experience working in Security Governance, Risk and Compliance functions.

  • You demonstrate strong communication skills and good interpersonal skills.You can communicate security risk-related concepts to technical and nontechnical audiences.

  • You have experience in interpreting and implementing security and privacy regulations and frameworks (e.g., NIST CSF, GDPR, ISO 2700x, SOC 2, PCI DSS, NIS2, CRA) into actionable security operational requirements.

  • You have a familiarity with the Secure Control Framework (SCF).

  • You have exceptional attention to detail, strong program/project management skills, analytical proficiency, and experience in operationalizing and developing scalable security processes in complex environments.

  • You have security certifications (e.g. CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer) as a plus.



OUR OFFER
 

Zalando provides a range of benefits, here’s an overview of what you can expect. Ask your Talent Acquisition Partner to learn more about what we offer.

  • Employee shares program

  • 40% off fashion and beauty products sold and shipped by Zalando, 30% off Lounge by Zalando, discounts from external partners

  • 2 paid volunteering days a year

  • Hybrid working model with up to 60% remote per week, actual practice is up to each team to best support their collaboration

  • Work from abroad for up to 30 working days a year

  • 27 days of vacation a year to start for full-time employees

  • Relocation assistance available (subject to prior agreement)

  • Family services, including counseling and support

  • Health and wellbeing options (including Wellhub)

  • Mental health support and coaching available

  • Drive your development through our training platform and biannual peer-to-peer review

Recruiter

Ana Ermilova

ana.ermilova@zalando.de

Bitte beachten, dass alle Bewerbungen auf dieser Seite über das Online-Formular erfolgen müssen – wir akzeptieren keine Bewerbungen per E-Mail. Nach der Prüfung werden unsere Recruiter*innen über eine offizielle Zalando E-Mail-Adresse (@zalando.de) Kontakt aufnehmen.

In einigen Fällen arbeiten wir auch mit einer Auswahl von Headhunter*innen und Agenturen zusammen, um bestimmte Positionen zu besetzen. Bitte beachte, dass weder Zalando noch unsere Rekrutierungspartner*innen irgendeine Art von Bezahlung verlangen, um sich für eine Stelle zu bewerben oder an einem Vorstellungsgespräch teilzunehmen. 

Wenn du Fragen zu unserem Rekrutierungsprozess hast, wirf bitte einen Blick auf unsere FAQ-Seite.

Über Zalando

Es ist die perfekte Zeit, sich Zalando auf unserer Reise anzuschließen, das führende E-Commerce-Ökosystem für den europäischen Mode- und Lifestyle-Markt aufzubauen. Hilf uns, rund 50 Millionen aktiven Kund*innen in 25 Märkten ein inspirierendes und qualitätsorientiertes Einkaufserlebnis für Mode- und Lifestyle-Produkte zahlreicher Marken aus einer Hand zu bieten. Oder sei Teil unserer Zalando Logistik-, Software- und Service-Infrastruktur, um Marken und Einzelhändler bei ihren E-Commerce-Transaktionen in ganz Europa zu unterstützen – sowohl auf als auch außerhalb der Zalando Plattform. Komm zu uns, um mit diesem Ökosystem einen positiven Wandel in der Mode- und Lifestylebranche zu bewirken.

Erfahre mehr über unsere Kultur