Take formal responsibility as the Information Security Officer (ISO) and as the ICT Risk Control Function under DORA, overseeing the governance and effectiveness of HFS’s ICT and cyber risk management framework., Establish, operate, and continuously improve the Information Security Management System (ISMS) in alignment with ISO/IEC 27001, DORA, and company strategy, ensuring appropriate policies, controls, and awareness measures are in place., Monitor ICT and cyber risks across the institution, review and challenge first-line assessments, and ensure transparent reporting to the Management Board and Risk Committee., Coordinate the Local Security Incident Response Team (LSIRT) and act as the central contact for information security incidents, ensuring appropriate escalation, documentation, and regulatory notifications., Ensure that internal ICT and security policies, standards, and documentation are consistent, up to date, and embedded effectively across all departments., Responsible for performing and reviewing third-party and ICT-outsourcing risk assessments, ensuring external providers are evaluated and monitored for security and operational resilience in line with DORA and internal standards., Design and deliver awareness and training programs on information security and ICT risk topics, fostering a strong security and resilience culture across HFS., Stay informed about emerging regulatory, technological, and threat developments to proactively adapt HFS’s ICT risk and security frameworks to evolving requirements., Prepare and deliver ICT risk and security reports for internal governance bodies, auditors, and supervisory authorities, ensuring a clear and consistent communication of the institution's ICT risk profile., Prepare and deliver ICT-risk and security reports for internal governance bodies, auditors, and supervisory authorities, and contribute to audits, BaFin inspections, and Risk Committee meetings by providing clear analyses, professional reporting, and proactive recommendations., Work in close coordination with the ISO of Hubject GmbH, ensuring consistent alignment of security and ICT risk management practices across both organizations.