Senior Cyber Security Governance & Audit Expert | Frankfurt
Our client is seeking a Senior Cyber Security Governance & Audit Expert to own the cyber hygiene governance framework, with a strong focus on audit readiness, serving as the central point of contact for audits and supervisory reviews.
The role:
- Design and maintain the governance framework: policies, standards, SLAs, RACI, and exception/risk acceptance processes.
- Translate regulatory frameworks (e.g. DORA, NIS 2, ISO 27001) into concrete controls, assessing effectiveness and driving remediation.
- Act as central point of contact for Internal Audit, external auditors, and supervisory authorities.
- Plan and coordinate audits and reviews, including stakeholder preparation and evidence provision.
- Maintain audit-proof documentation of controls, processes, and risk acceptance cases, supporting findings through to closure.
- Define and maintain KPIs, KRIs, and reporting models; prepare executive-ready reports for CISO and steering committees.
- Advise stakeholders on governance and audit expectations, and coach junior governance specialists.
What you'll need:
- 5+ years' experience in cyber security governance, IT risk management, or audit in a regulated industry.
- Deep knowledge of security frameworks and regulatory requirements (e.g. ISO 27001/2, DORA, NIS 2).
- Strong understanding of cyber hygiene controls and how to evidence them to auditors and regulators.
- Experience in control design and assessment, and deriving remediation from audit findings.
- Excellent communication and stakeholder management skills, particularly with audit and senior leadership.
- Excellent English required; German is a strong advantage.
- Certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, or CISA are an advantage.
- Fluent English, fluent German preferred.
How to apply:
Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role.