LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Welcome to the team: Specialist Cyber Hygiene Governance (m/f/diverse)

ExperiencedNo visa sponsorship
Commerzbank logo

at Commerzbank

Investment Banking

Posted 4 days ago

No clicks

**Specialist Cyber Hygiene Governance (m/f/diverse):** Translate 2nd Line of Defense requirements into operational cyber hygiene standards. Collaborate with asset owners to anchor cyber hygiene as a repeatable process. Continuously improve processes, with a focus on vulnerability, patch, and secret management, baseline configurations, and KPI definition. Ensure consistent, transparent reporting and reduce preventable cyber risk. Key requirements include deep cyber hygiene governance knowledge, experience with risk-based vulnerability management, familiarity with IT risk compliance frameworks (e.g., NIST), and proficiency in vulnerability scanning tools like Qualys or TenableOne. Effective communication, agile teamwork, and IT risk & compliance expertise are essential.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
Bulgaria

Full Job Description

Your tasks

  • Translating 2nd Line of Defense requirements, regulatory obligations and internal standards into concrete, operationally executable cyber hygiene standards, SLAs, policies and reporting rules
  • Collaborating closely with the Cyber Hygiene Factory as well as responsible asset and service owners to anchor cyber hygiene as a repeatable, managed baseline process;
  • Continuously improving cyber hygiene processes with particular focus on:
    • Managing vulnerabilities;
    • Managing patches;
    • Managing secrets;
    • Defining and maintaining baseline configurations / known-good state;
    • Defining KPIs / scorecards and establishing reporting;
  • Ensuring cyber hygiene controls (NIST: Govern / Identify / Protect) are consistently defined, monitored and transparently reported to management and stakeholders;
  • Reducing preventable cyber risk and strengthening the banks cyber resilience through effective cyber hygiene governance.

Your profile

  • High Knowledge within Cyber Hygiene Governance, including roles & responsibilities, policies, SLAs, RACI, exception and risk acceptance processes, and oversight mechanisms
  • Experience with designing and steering a risk-based vulnerability management program across infrastructure and applications, including CVSS, risk context, asset criticality; integration with exposure management and coordination of remediation;
  • Knowledge of IT Risk and Compliance Frameworks (e.g. PCI-DSS, DORA, SOC2, NIST-aligned).
  • Expertise in definition and oversight of standards, processes and KPIs for patch management, asset management and baseline configuration to ensure a known-good state;
  • Experience with vulnerability scanning and exposure management tools (e.g. Qualys, TenableOne, Wiz, GitGuardian) in a governance context: policies, scoping, quality / completeness control, and interpretation of results;
  • Effective communication of complex security and risk topics to technical and non-technical stakeholders, including senior management; facilitation of discussions, conflict resolution and prioritization;
  • Working in agile teams/cells, self-organizing planning, iterative improvement of processes and standards, and close collaboration with product owners, engineers and analysts.

In return, we offer:

  • Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
  • Luxury package of additional health and dental insurance;
  • Food vouchers in the amount of EUR 80 monthly;
  • 6 additional annual days off for exceptional circumstances
  • Employee assistance program for psychological, financial and legal consultations;
  • Multisport card;
  • Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
  • Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
  • Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
  • Friendly and supportive multicultural environment, open to new opinions and ideas.

Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.

Our Benefits

Learning Platforms; Children Summer Camp Contribution; Employee assistance program; Food vouchers; 6 Exceptional Days Off; 25 up to 31 annual paid leave; Multisport Card; Health& Dental Insurance; Work-life balance; Work internationally

Bookmark job ad
Print job ad
Share job ad

The company

Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.

As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Specialist Cyber Hygiene Governance in our Cyber Defense and Base Services team.

Cluster Cyber Defense & Base services provides 1. LoD activities within the Commerzbank Cyber Security Organization. In addition, to these operational topics the cluster also develops and operates a variety of security tools which are used by the operational units SOC and Threat Intelligence.

In the Cluster Organization, business analysts, engineers and product owners work together as a team. The agile methods support the team members in performing their functions by facilitating a rapid and flexible response to changing conditions and customer needs through an iterative approach and the continual development of new solutions resulting in better products, higher quality, and more efficient processes.

The team works together to ensure that valuable functionalities are provided to customers, and that existing products, processes and services are developed and improved in line with customer needs. To achieve this, the team members organize their own activities, working autonomously and with full accountability. Open communication and feedback are key to adopt a fail-fast approach recognize mistakes and move forward in the right direction.

Contact

Apply now with your up-to-date CV in English!

Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.

Welcome to the team: Specialist Cyber Hygiene Governance (m/f/diverse)

Compensation

Not specified

City: Not specified

Country: Bulgaria

Commerzbank logo
Investment Banking

4 days ago

No clicks

at Commerzbank

ExperiencedNo visa sponsorship

**Specialist Cyber Hygiene Governance (m/f/diverse):** Translate 2nd Line of Defense requirements into operational cyber hygiene standards. Collaborate with asset owners to anchor cyber hygiene as a repeatable process. Continuously improve processes, with a focus on vulnerability, patch, and secret management, baseline configurations, and KPI definition. Ensure consistent, transparent reporting and reduce preventable cyber risk. Key requirements include deep cyber hygiene governance knowledge, experience with risk-based vulnerability management, familiarity with IT risk compliance frameworks (e.g., NIST), and proficiency in vulnerability scanning tools like Qualys or TenableOne. Effective communication, agile teamwork, and IT risk & compliance expertise are essential.

Full Job Description

Your tasks

  • Translating 2nd Line of Defense requirements, regulatory obligations and internal standards into concrete, operationally executable cyber hygiene standards, SLAs, policies and reporting rules
  • Collaborating closely with the Cyber Hygiene Factory as well as responsible asset and service owners to anchor cyber hygiene as a repeatable, managed baseline process;
  • Continuously improving cyber hygiene processes with particular focus on:
    • Managing vulnerabilities;
    • Managing patches;
    • Managing secrets;
    • Defining and maintaining baseline configurations / known-good state;
    • Defining KPIs / scorecards and establishing reporting;
  • Ensuring cyber hygiene controls (NIST: Govern / Identify / Protect) are consistently defined, monitored and transparently reported to management and stakeholders;
  • Reducing preventable cyber risk and strengthening the banks cyber resilience through effective cyber hygiene governance.

Your profile

  • High Knowledge within Cyber Hygiene Governance, including roles & responsibilities, policies, SLAs, RACI, exception and risk acceptance processes, and oversight mechanisms
  • Experience with designing and steering a risk-based vulnerability management program across infrastructure and applications, including CVSS, risk context, asset criticality; integration with exposure management and coordination of remediation;
  • Knowledge of IT Risk and Compliance Frameworks (e.g. PCI-DSS, DORA, SOC2, NIST-aligned).
  • Expertise in definition and oversight of standards, processes and KPIs for patch management, asset management and baseline configuration to ensure a known-good state;
  • Experience with vulnerability scanning and exposure management tools (e.g. Qualys, TenableOne, Wiz, GitGuardian) in a governance context: policies, scoping, quality / completeness control, and interpretation of results;
  • Effective communication of complex security and risk topics to technical and non-technical stakeholders, including senior management; facilitation of discussions, conflict resolution and prioritization;
  • Working in agile teams/cells, self-organizing planning, iterative improvement of processes and standards, and close collaboration with product owners, engineers and analysts.

In return, we offer:

  • Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
  • Luxury package of additional health and dental insurance;
  • Food vouchers in the amount of EUR 80 monthly;
  • 6 additional annual days off for exceptional circumstances
  • Employee assistance program for psychological, financial and legal consultations;
  • Multisport card;
  • Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
  • Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
  • Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
  • Friendly and supportive multicultural environment, open to new opinions and ideas.

Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.

Our Benefits

Learning Platforms; Children Summer Camp Contribution; Employee assistance program; Food vouchers; 6 Exceptional Days Off; 25 up to 31 annual paid leave; Multisport Card; Health& Dental Insurance; Work-life balance; Work internationally

Bookmark job ad
Print job ad
Share job ad

The company

Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.

As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Specialist Cyber Hygiene Governance in our Cyber Defense and Base Services team.

Cluster Cyber Defense & Base services provides 1. LoD activities within the Commerzbank Cyber Security Organization. In addition, to these operational topics the cluster also develops and operates a variety of security tools which are used by the operational units SOC and Threat Intelligence.

In the Cluster Organization, business analysts, engineers and product owners work together as a team. The agile methods support the team members in performing their functions by facilitating a rapid and flexible response to changing conditions and customer needs through an iterative approach and the continual development of new solutions resulting in better products, higher quality, and more efficient processes.

The team works together to ensure that valuable functionalities are provided to customers, and that existing products, processes and services are developed and improved in line with customer needs. To achieve this, the team members organize their own activities, working autonomously and with full accountability. Open communication and feedback are key to adopt a fail-fast approach recognize mistakes and move forward in the right direction.

Contact

Apply now with your up-to-date CV in English!

Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.