Bern
Senior IT Risk & Security Governance Manager (80–100%)
- 18 September 2026
- 40%
- Temporary
About the job
For a demanding and business-critical IT environment at a leading Swiss company, we are looking for an experienced professional in the field of IT Risk Management, Security Governance and Compliance.
Senior IT Risk & Security Governance Manager (80–100%)
Job description:
- Consolidation, management and further development of the existing IT risk portfolio
- Conducting and moderating risk analyses and risk reviews
- Assessment of technical and organisational risks as well as coordination of corresponding risk mitigation measures
- Management and coordination of security, compliance and governance topics
- Ensuring structured follow-up of identified risks and measures
- Preparation of management reports, decision-making bases and status overviews
- Stakeholder management across various IT, security, operations and delivery teams
- Support of the product owner in governance, risk and security issues
- Continuous development of existing risk and governance processes
About the customer:
In this senior role, you take on a central role in managing risks within a complex application portfolio. You work closely with product owners, IT operations, DevOps, security and delivery teams to ensure that risks are transparently assessed, appropriate measures defined and consistently followed up.
The position is planned with a workload of 80–100% and offers the possibility of up to two home office days per week.
This is a fixed-term position with a duration of 12 months, with the option of extension.
Requirements:
- Several years of professional experience in the field of IT operations, IT service management, DevOps or comparable enterprise IT structures
- Solid experience in IT risk management as well as in the analysis and assessment of technical and organisational risks
- Very good knowledge of information security, security governance and compliance
- Experience in conducting risk reviews as well as in tracking and managing risk mitigation measures
- Extensive experience in stakeholder management across multiple teams and organisational units
- Ability to prepare complex technical and organisational matters in a clear and management-appropriate manner
- Experience with management reporting and preparation of decision-making bases
- Practical experience with Jira and Confluence
- Very good German skills as well as good English skills
Advantageous:
- Knowledge of ISO 27001, NIST, COBIT or comparable security and governance frameworks
- Experience with audit, compliance or regulatory requirements
- Experience in operating business-critical applications in cloud environments
- Understanding of modern operating models such as DevOps or Site Reliability Engineering (SRE)
- Experience in governance of application or IT portfolios
- Certifications such as CISSP, CISM, CRISC or ITIL
- Experience in large enterprise organisations with complex stakeholder structures