As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.
Security Risk Manager
Location
Hungary
Posted
4 days ago
Salary
0
Seniority
Lead
Job Description
Security Risk Manager
Deutsche Telekom IT Solutions
Role Description As a Security Risk Manager, you will be part of a centralized information security governance team providing security risk management services across multiple Deutsche Telekom legal entities. The role focuses on operating and continuously improving the security risk management framework, while supporting and enabling local risk managers through consultation, training, and professional use of GRC tools. You will contribute to transparent risk reporting, effective risk mitigation, and harmonized governance practices in a complex, multinational environment. - Operate and continuously improve the security risk management process, methodologies, and related policies - Ensure alignment with group-level security standards and governance requirements - Support the integration of risk management into business and IT processes - Act as a trusted advisor for supported legal entities on information security risk topics - Train and upskill local risk managers on risk processes, methods, and policies - Provide hands-on guidance during risk identification, assessment, and treatment - Support professional usage of the GRC platform by local risk managers - Assist in risk creation, maintenance, and lifecycle management within the tool - Collect user feedback and represent business needs toward process and tool improvements - Identify, create, and manage security risks in cooperation with stakeholders - Monitor and support risk mitigation actions, including follow-up on progress and effectiveness - Ensure risks are properly documented and audit-ready - Prepare and maintain Top 10 risk reports, quarterly risk summaries, and ad-hoc reports - Define, monitor, and analyze risk KPIs and metrics - Provide management with insights on risk trends and improvement areas Qualifications - Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering, Business Informatics, or a related field - High-level English language knowledge (spoken and written) - At least mid-level German language proficiency - 3–7+ years of experience in Information Security / Cybersecurity / Risk Management / GRC roles - Experience in large enterprise or multinational environments - Strong understanding of information security risk management frameworks (e.g. ISO 27005, NIST RMF) - Knowledge of information security standards (e.g. ISO 27001, NIST, CIS) - Ability to apply security governance principles in practical, business-aligned ways - Strong communication and stakeholder management skills - Ability to explain security and risk topics in business-friendly language - Structured, proactive, and solution-oriented mindset Requirements - Experience in training, coaching, or enablement activities - Experience working in a shared service or internal consulting model is an advantage - CRISC, CISM, CISSP, COBIT, ITIL or similar governance-related certifications - Hands-on experience with GRC tools (e.g. ServiceNow, Archer, OneTrust, or similar) Benefits - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Consultant
Logicalis SpainSomos Arquitectos Del Cambio, ayudamos a las organizaciones a tener éxito en un mundo cada vez más digitalizado.
• Definición estratégica de revisiones de seguridad basada en riesgos, criticidad y prioridades del negocio. • Planificación, coordinación y seguimiento de múltiples iniciativas ofensivas simultáneas, incluyendo pentest y ejercicios de red team. • Gestión integral del ciclo de vida de las revisiones y auditorías de seguridad, desde la preparación hasta el cierre de acciones derivadas. • Supervisión de resultados e interpretación de informes técnicos de carácter ofensivo. • Coordinación de la respuesta a los informes derivados de las revisiones de seguridad. • Seguimiento de planes de remediación, asegurando su correcta ejecución en tiempo y forma. • Interlocución con clientes, equipos técnicos y responsables de negocio para garantizar una comunicación clara y alineada.
IT Technician, Specialist in System Integration – Cyber Security
HK EDV Beratung GmbHIhr Servicepartner für individuelle, optimierte IT-Lösungen
• Manage the Cyber Security area • Provide 2nd & 3rd Level Support with a focus on Cyber Security • Accept and resolve support cases directly • Lead and implement Cyber Security projects • Support our support and data center teams
Role Description Foresite is looking for a highly technical, results-oriented Cloud Security Engineer to serve as the technical lead for onboarding customers to GCP Security Command Center (SCC) and Wiz. In this role, you will be the driving force behind ensuring cloud security findings are seamlessly integrated into Google SecOps, providing our clients with a unified and actionable security posture. What You'll Do: - Operate at the heart of Foresite’s technical onboarding framework. - Lead the hands-on configuration of cloud security tools, partnering closely with customer analysts to translate complex findings into automated, high-fidelity security operations. - Drive successful technical handoffs and build custom detection and remediation logic. Technical Onboarding & Implementation - Lead the Integration: Lead the hands-on configuration of GCP SCC and Wiz for new customers, ensuring all high-fidelity security findings are correctly ingested into Google SecOps. - Data Integrity: Ensure technical accuracy in parser creation and UDM mapping to maintain the highest quality of security data. Detection & Automation - Custom Logic: Write custom YARA-L detection rules to correlate cloud posture findings with network traffic. - Streamline Response: Develop end-to-end SOAR Playbooks and utilize Python to write logic for custom actions, streamlining the customer's remediation workflows. Customer Enablement & Support - Technical Walkthroughs: Lead sessions for customer analysts, teaching them how to navigate SCC/Wiz findings and investigate alerts within the Google SecOps interface. - Troubleshooting: Act as the technical point of contact for resolving integration errors and optimizing automation scripts. Qualifications - At least 2 years of strong hands-on experience with Google SecOps (Chronicle), specifically in parser creation, UDM mapping, and YARA-L rule writing. - Proven experience configuring GCP SCC and Wiz, with foundational knowledge equivalent to a Google Cloud Associate Cloud Engineer. - Proficient in Python and enjoy using it to solve complex security automation challenges. - Demonstrated ability to manage a customer onboarding from technical kickoff to final handoff without constant senior oversight. - Ability to translate deep technical configurations into actionable insights for customer security teams. Nice to Have - Current Google Cloud Associate Cloud Engineer or professional security certifications. - Experience building complex API integrations between cloud security platforms. - Experience advising customers on cloud security best practices and long-term posture management. Benefits - Robust medical insurance options to keep you and your family healthy. - Employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD). - 3 weeks of paid vacation, plus additional sick leave and paid company holidays. - Access to world-class training to support your career trajectory. - Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.
Security Engineer
GoDaddyGoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a
Role Description Join our dynamic Hosting Security Detection Engineering team as a Security Engineer, where you'll play a pivotal role in safeguarding millions of customers across our diverse hosting ecosystem! - This includes fully managed WordPress sites, cPanel servers, Plesk hosting, virtual private servers, domain name services, and hosted email solutions. - This role offers an exceptional chance to create a direct impact on customer security at scale, working with groundbreaking detection technologies and threat intelligence while working with a dedicated team of security engineers. - You'll gain deep expertise in large-scale security operations, advance your cybersecurity skills in a fast-paced environment, and contribute to innovative security solutions that protect one of the internet's largest hosting platforms from sophisticated cyber threats. What you'll get to do: - Participate in continuous improvement efforts for SOC capabilities across people, process, and technology. - Collaborate with teams to optimize detections and playbooks. - Analyze and triage security incidents. - Serve as an escalation point from our global SOC. - Contribute to detection and response automation and infrastructure. Qualifications - 4+ years of experience in a SOC or Fusion Center environment. - Proficiency in SIEM platforms (Splunk, Elastic Security, Chronicle, Sentinel) including advanced query languages (SPL, KQL, Lucene) and custom dashboard creation. - Capable of performing remediation actions on endpoints/servers. - Experience with threat intelligence platforms and the ability to translate IOCs, TTPs, and threat research into actionable detection rules and hunting queries. - Knowledge of networking protocols, system administration, and security frameworks (MITRE ATT&CK, NIST) with experience in log analysis and forensic investigation. Requirements - Security certifications such as GCIH, GCFA, CISSP, or cloud security specializations (AWS Security Specialty, Azure Security Engineer). - Experience with containerized environments (Docker, Kubernetes) and modern DevSecOps practices including CI/CD pipeline security integration. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Other family-friendly benefits including parental leave. GoDaddy’s benefits vary based on individual role and location and can be reviewed in more detail during the interview process. We also embrace our diverse culture and offer a range of Employee Resource Groups. Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way. We encourage you to apply even if your experience or skillset doesn’t align perfectly with every requirement. We value a wide range of backgrounds and transferable skills, and we are excited to support learning and growth.



