General Information
Type of contract Fixed-term contract which may be converted into a permanent contract after three years subject to individual performance and organisational needs
Who can apply? EU nationals
Salary E/F (bracket 1 - step 1) full time monthly net salary: €4,869 plus benefits, for further information see what we offer.
Working time Full time
Place of work Frankfurt am Main, Germany
Closing date 11.11.2025
Your team
- IT risk inspections: the ECB has been conducting IT risk and cybersecurity inspections since 2014 for banks designated as significant institutions. DG/OMI has an existing team of 17 IT Risk On-site Inspectors within its Non-Financial Risk Inspections Division.
- Threat Led Penetration Testing (TLPT): the Digital Operational Resilience Act (DORA) requires the ECB to ensure that identified banks under direct ECB supervision conduct an advanced cybersecurity test using the TLPT model. DG/OMI is building a team of TLPT experts within its Non-Financial Risk Inspections Division to manage these tests alongside teams from national supervisory authorities and national central banks.
Your role
- contribute to IT risk on-site inspections (OSI), primarily at the premises of the significant institutions;
- add to the technical knowledge within the team, building upon your current expertise and staying up to date with a wide range of new developments, in close contact with national supervisory authorities, joint supervisory teams and ECB horizontal functions;
- provide deliverables, implement standards and contribute to the assessment of the risks faced by significant institutions and their adherence to regulatory requirements;
- carry out activities to optimise, manage and integrate processes and tools to support the efficiency and effectiveness of OSIs in the SSM.
- take an active part in overseeing the TLPT as Test Manager, working closely with the banks undergoing testing, the threat intelligence provider, the red team and all other stakeholders;
- contribute to the internal TLPT processes of the SSM, such as identifying banks to be tested, planning the tests, liaising with the TLPT Cyber Teams, assisting in attestations and providing guidance to the joint supervisory teams for specific tests;
- play an active role in the SSM TLPT community and the overall community implementing the European framework for threat intelligence-based ethical red-teaming (TIBER-EU).
Qualifications, experience and skills
- a bachelor’s degree or equivalent in computer science, information systems, or another relevant field (see How you can join us for details on degree equivalences);
- in addition to the above, a minimum of two years of relevant professional experience (including traineeships and internships) in the field of IT operations, IT audit, IT risk management or cybersecurity;
- a high level of commitment and flexibility as well as the ability to work efficiently and effectively under pressure;
- good drafting and presentation skills and the ability to prepare briefings in a clear and concise way for diverse audiences;
- the ability to familiarise yourself quickly with new topics and willingness to continue learning;
- very good IT skills and experience of using MS Office;
- an advanced (C1) command of English and an intermediate (B1) command of at least one other official language of the EU, according to the Common European Framework of Reference for Languages.
- a master’s degree, preferably in computer science, information systems, or another relevant field;
- professional experience with IT system operations, management, IT audit and inspections;relevant professional qualifications such as Certified Information Systems Auditor;
- a strong ability to use other EU languages for business purposes.
- a master’s degree, preferably in computer science, information systems, or another relevant field;
- professional experience with IT security testing and/or red teaming and/or threat intelligence ;
- relevant professional qualifications, such as Certified Information Systems Security Professional, Certified Information Security Manager or Certified in Risk and Information Systems Control;
- a strong ability to use other EU languages for business purposes.
Working modalities
Further information
Application and selection process
By registering on our pool, our recruiters will be able to view your profile, contact you for current & future vacancies and engage you on opportunities that match your skills and interest.
We encourage you to always keep your profile updated with your most recent qualifications, experience, skills and languages (local & international) to increase the possibility of being contacted.
Register