Technology Risk & Security Manager (m/f/d)
Simon-Kucher & Partners · Berlin, Germany
You apply off-site, with the employer or the job board. I never handle applications.
Technology Risk & Security Manager (m/f/d)
In Germany- Berlin | Bonn | Cologne | Frankfurt/Main | Hamburg | Munich This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating within the company’s Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance.
This individual will focus on reviewing technical concepts, stand-alone products, services, and AI-enabled solutions that the company plans to implement or integrate into its complex global enterprise technology landscape, including SaaS, PaaS, SAP, and AI-enabled platforms.
You will be responsible for assessing and governing new technology demands, services, platforms, and AI-enabled solutions through the organization’s technology intake process. The role ensures that security, compliance, architecture, operational, and business risks are identified, clearly documented, and addressed through effective and practical mitigation measures
What makes us special:
- Advance your career with exciting professional opportunities in our thriving company with a startup feel.
- Voice your unique ideas in a corporate culture defined by openness and integrity.
- Enjoy the opportunity to work from abroad (workation).
- Feel at home working with our helpful, enthusiastic colleagues who have great team spirit.
- Broaden your perspective with our extensive training curriculum and learning programs (e.g. LinkedIn Learning).
- Speak your mind in our holistic feedback and development processes (e.g. 360-degree feedback).
- Satisfy your need for adventure with our opportunities to live and work abroad in one of our many international offices
- Enjoy our benefits, such as hybrid working, daycare allowance, corporate discounts, and wellbeing support (e.g. Headspace).
- Unwind in our break areas where you can help yourself to the healthy snacks and beverages provided.
- See another side of your coworkers at our frequent employee events and highly anticipated World Meeting and Holiday Party.
How you will create an impact:
- Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
- Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
- Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
- Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
- Ensure new technologies comply with security policies, controls, and integration requirements.
- Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
- Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
- Translate business requirements into security and compliance recommendations that enable timely technology decisions.
- Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
- Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
- Support vendor assessments, RFPs, technical evaluations, and solution reviews.
- Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
- Work effectively in agile, global project environments with multiple priorities and tight timelines.
About you:
- Experience in a complex global environment, comparable consulting or service industries is preferred.
- Bachelor’s Degree required – preferred in the area of Technology, MIS, Cybersecurity, etc.
- 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
- Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies.
- Experience assessing SaaS, cloud, third-party, and AI-enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements.
- Experience improving governance processes, workflows, standards, and risk management practices.
- Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar.
- Experience with security controls, risk assessments, compliance, audit support, and governance approval processes.
- Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security.
- Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation.
- Strong stakeholder management skills with experience working across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams.
- Experience preparing executive-level presentations, risk reports, and decision-ready documentation, and presenting recommendations to senior leadership.
- Experience evaluating third-party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments.
- Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross-functional technology initiatives.
- Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle.
- CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands-on experience).
Have we sparked your interest? Simply click the 'Apply now' button to submit your application. Please note that, for data protection reasons, we cannot accept applications via email.
Would you like to learn more about us and our company culture? Click here to watch our recruitment video.
About Simon-Kucher
Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. As a trusted commercial advisor focused on unlocking better growth, we combine deep consulting expertise, growth specialization, and technology to scale lasting impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value. With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist. simon-kucher.com
We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.
Your personal contact:
Christina Jaup-Schwilk
recruitment.germany(at)simon-kucher.com
Please submit your application exclusively via the “Apply now” button!
Better growth starts here. With you.