Toyota Kreditbank GmbH | Germany | 50xxx Köln | Permanent position | Full time | Published since: 07.05.2025 on stepstone.de
Manager (m/w/d) IT Compliance
At Toyota we know nothing is impossible. This applies not only to Toyota as a mobility brand, but also to us: the Toyota Kreditbank GmbH (TKG). As a bank of one of the largest automotive manufacturers worldwide, we have been working successfully on the German market for over 35 years - and continue to grow. The Toyota Future Mission "Mobility for All" should allow as many people as possible access to mobility. The Group therefore expands the existing business model with relevant solutions that provide added value to society. This attitude is also reflected in our innovative financial products and customer-oriented services, which regularly bring us the award as the best car bank. For only together can we initiate progress and redefine the limits of the possible - and lose sight of this without our roots. JOBV1_EN
* After clicking the Read more button, the original advert will open on our partner's website, where you can see the details of this vacancy and contact information. If you need a translation of this text, after returning to our website it will be prepared and you can read it by clicking the Show full translation button.
Your tasks • Your profile • What we offer
At Toyota we know nothing is impossible. This applies not only to Toyota as a mobility brand, but also to us: the Toyota Kreditbank GmbH (TKG). As a bank of one of the largest automotive manufacturers worldwide, we have been working successfully on the German market for over 35 years - and continue to grow. The Toyota Future Mission 'Mobility for All'' is intended to allow as many people as possible access to mobility. The Group therefore expands the existing business model with relevant solutions that provide added value to society. This attitude is also reflected in our innovative financial products and customer-oriented services, which regularly bring us the award as the best car bank. For only together can we initiate progress and redefine the limits of the possible - and lose sight of this without our roots.
Conduct regular risk and threat analyses to verify the ICT risk management framework, assess the effectiveness of risk controls and ensure compliance with regulatory requirements and compliance with intra-group requirements Continuous monitoring of information security measures and reporting to the management to assess the risk situation and derive from the support of management in determining the risk readiness Independent development and implementation of risk mitigation measures (e.g. development of clear security policies that regulate the handling of sensitive data and IT resources. Regular information on current threats and security measures etc.) Ensuring proper treatment, classification and internal (relevant bodies within the TKG) and external (regulatory) reporting of ICT-related incidents. Ensuring compliance with the requirements of the third-party DOR Regulation, in particular monitoring and assessment of third-party security measures Promoting a security awareness within the company, in particular linked to the initiation and coordination of training and awareness-raising measures for employee information security Coordination of the implementation of the information security requirements of TFSC (GISG = Global Information Security Group) for TKG and TKG Group. This includes the support of the annual safety assessments by the GISG Ensure coordination and cooperation with the data protection officer and risk management for third parties Perception of the function of the Information Security Officer (ISO) in accordance with the legal requirements for TKG, TKG-Institut and TKG-Group Coordination of tasks between the first (1LOD) and the second (2LoD) line of defence, in particular before the implementation of strategic measures Monitoring and coordination of external audits related to information security (legal audits, supervisory audits by the central bank, audit of deposit guarantee funds, etc.) Leading, designing and developing a team in the sense of Toyota Way and the company's leadership principles
Successfully completed university studies focusing on IT, cybersecurity, risk management or comparable discipline At least four years of professional experience in the field of information security, ideally in the financial sector or in a vehicle manufacturer's bank Practical experience in implementing regulatory requirements, in particular DORA Found knowledge of ISO 27001, ideally connected to corresponding certifications, e.g. CISA, CISM, COBIT, CISSP Experience with Governance-Risk Compliance (GRC) and Incident Management Tools Outstanding analytical skills and problem-solving competence Communication strength associated with negotiation competence Cooperation in an international and multicultural environment English language skills
We offer a future-oriented workplace with challenging, versatile tasks in a dynamic environment and a pleasant working environment. Flexible working hours and targeted training offers are of course for us. In addition to attractive remuneration, you will also receive an occupational pension scheme. We also offer a vehicle registration program where you and up to two members can participate. Two canteens are available for your lunch to choose from. JOBV1_EN
Company location
Location
![]() | Toyota Kreditbank GmbH | |
Köln | ||
Germany |
The text of this ad was translated from German into English using an automatic translation system and may contain semantic and lexical errors. Therefore, it should be used for introductory purposes only. For more detailed information, see the original text of the ad at the link below.
For more information read the original ad