BlackFin Capital Partners | Germany | 40xxx Düsseldorf | Permanent position | Full time / Home office | Published since: 23.04.2026 on stepstone.de
Information Security Officer IAM (ITSO-IAM) (m/f/d)
BlackFin Capital Partners is looking for an IT security officer IAM (ITSO-IAM) to strengthen the team of a new portfolio company in Germany. The company is one of the leading asset management companies in Germany and offers institutional investors solutions for structuring diversified investment portfolios. The company currently manages a total of over 400 billion euros. To strengthen our team, we are looking for colleagues who are building and developing the company together with us. BlackFin Capital Partners is a European specialized investor focused on investment in financial services companies with growth potential. BlackFin founded a branch in Frankfurt in 2018 and has been actively investing in the DACH region since 2013. The company currently manages a fund volume of over EUR 4 billion and invests capital from its last two funds: the BlackFin Financial Services Fund IV with a volume of EUR 1.8 billion and the BlackFin Tech 2 with a volume of EUR 390 million. About the company's IT: As with all financial companies, IT is crucial to our company. The company's products and services are supported by around 60 specialized IT application systems. These are mainly standard software, such as Simcorp Dimension as a central fund accounting system, complemented by a number of self-developed systems and systems for corporate functions such as financial accounting, human resources, compliance and non-financial risk management. While core business systems are predominantly operated on site in two data centers of a European IT infrastructure service provider, cloud-based SaaS solutions are increasingly being used for corporate functions. Of course, all employees are equipped with the corresponding IT workstation functions, the procurement and operation of which is to be carried out via an IT service provider. The company's IT is subject to strict financial supervision; since 2025, the European DORA Regulation is in force. This lays down comprehensive requirements for the relevant IT processes, in particular for IT operation and IT infrastructure. .
* After clicking the Read more button, the original advert will open on our partner's website, where you can see the details of this vacancy and contact information. If you need a translation of this text, after returning to our website it will be prepared and you can read it by clicking the Show full translation button.
Your tasks • Your profile • What we offer
Enforce security policies in local and Microsoft 365 environments Ensuring compliance with third-party internal security standards Checking and monitoring of safety protocols both of local infrastructure and of working area Coordination of response to incidents between internal teams and third parties Monitoring the vulnerability management and ensuring the timely elimination of identified risks Review of the third-party patch management processes Promoting security awareness and ensuring appropriate security practices among users Support in the implementation, maintenance and continuous improvement of identity and access management processes (IAM) and appropriate controls in accordance with regulatory requirements (e.g. DORA, BaFin, ISO 27001) Ensuring the proper implementation of JML processes (Joiner, Mover and Leaver), including the provision, modification and cancellation of user access Monitoring of identity and access management (IAM), including MFA, RBAC and audits of privileged access Support for internal and external audits through the preparation of evidence for access control and follow-up of remedies
We are looking for a structured, security-conscious and detailed expertise with interest in identity and access management in regulated environments. You are familiar with audit requirements and ensure traceability and effectiveness of control measures. 2–5 years of professional experience in IT security, IAM or cyber security, ideally in a regulated environment Completion in Information Technology, Computer Science, Cybersecurity or a related field Good understanding of IAM principles, including JML processes, access checks, task separation and management of privileged accounts Experience in the support of audits, access control checks and follow-up of remedies Good understanding of IT security frameworks and regulatory requirements (DORA, BaFin, ISO 27001, GDPR) Confidence with authentication and authorization mechanisms Ability to check configurations and question technical setups Tools & abilities: Confidence with directory services and IAM tools (e.g. Active Directory, Microsoft Entra ID, IAM/IGA (Identity and Governance Administration)) Experience with ticket and documentation tools (e.g. Jira, Confluence) Ability to query and investigate protocols (Microsoft Sentinel or other SIEMs), identify anomalies and track incidents Understanding firewalls, VPNs, segmentation and traffic streams (even if managed by the provider, you need to validate and question them) Experience with scanners (e.g. Nessus, Qualys) and the ability to interpret results and prioritize remedial measures Basic understanding of authentication methods (MFA, SSO, Conditional Access) Experience in the documentation of processes, controls and test evidence Ability to question third-party configurations (make the right technical questions, check configurations, not only reports) Structured and reliable operation Team-oriented thinking with pronounced communication skills Liquid English and German in Word and Writing (level C1/C2 required)
Participation in building an independent KVG Flat organizational structures, fast decision-making and an agile working environment Individual training budgets and professional development perspectives Attractive compensation package Hybrid work (2-3 days / week on site in Düsseldorf) Flexible working hours A modern office in a convenient location in Düsseldorf College, highly motivated environment
Location
![]() | BlackFin Capital Partners | |
| 40549 Düsseldorf | ||
| Germany |
The text of this ad was translated from German into English using an automatic translation system and may contain semantic and lexical errors. Therefore, it should be used for introductory purposes only. For more detailed information, see the original text of the ad at the link below.
For more information read the original ad