Clera home
·Dashboard

Jobs at Upvest (Now Hiring) — 2 open

Upvest logoUpvest

Lead IT Risk Manager (f/m/d)

Berlin, Germany · Hybrid

Senior$324M raised

At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and re…

Skills: IT Risk Management, IT Governance, Compliance Management, ISO 27001, DORA

Upvest logoUpvest

Senior Data Product Engineer (f/m/d)

Berlin, Germany · Remote OK

Senior$324M raised

At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and re…

Skills: Kafka, Python, Go, SQL, Terraform

Upvest logo

Lead IT Risk Manager (f/m/d)

Upvest

Berlin, Germany • Hybrid

Apply
Senior

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

  • Full-time
  • bachelor degree
  • AI Tools Budget, 30 Days Annual Leave, Sports Benefits, Professional Coaching, Remote Work Abroad (up to 183 days), Paid Sabbatical (UpRest)
  • Posted 5d ago
  • ~40 hrs/week

Responsibilities

Own and evolve the IT Risk and Business Continuity Management Framework while providing second-line oversight to the IT GRC team. Lead regulatory alignment for DORA and manage IT risk reporting to senior stakeholders and the Risk Committee.

Requirements

Requires a university degree in Computer Science or IT and at least 5 years of IT GRC experience within a regulated financial environment. Must possess deep knowledge of ISO 27001, BaFin BAIT/MaRisk, and DORA regulations.

Full job description

At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business.

We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in 2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent - serves as a massive catalyst for our growth, allowing us to offer premier investment experience.


About the role:

As the Lead IT Risk Manager, you will play a pivotal role in owning and evolving our IT Risk Framework within the second-line risk function. Operating in a highly growth-oriented and regulated financial services environment, this role demands an exceptional blend of technical governance expertise, independent challenge capabilities, and strategic stakeholder management. You will serve as the primary second-line authority for IT risk matters, providing oversight to the first-line IT GRC team, leading comprehensive risk assessments, and ensuring strict alignment with Upvest's overarching Risk Appetite Framework.


What you’ll do:

Risk Framework Ownership & Oversight

  • Own and evolve the IT Risk and Business Continuity Management Framework within the second line, keeping it scalable as the business grows.

  • Provide independent second-line oversight and challenge to the first-line IT GRC team on the design and effectiveness of IT controls.

  • Lead IT risk identification, assessment, and mitigation across cyber, technology resilience, third-party, and data security, linking back to the Risk Appetite Framework.

IT Governance & Compliance Management

  • Mature the ISMS by guiding policies, standards, and procedures with the relevant process owners.

  • Define baseline controls and run continuous ISMS maturity assessments against ISO/IEC 27001:2022 and related standards.

  • Oversee third-party IT risk, internal technology exposures, and business continuity assessments.

IT Audit & 2nd Line Assurance

  • Drive second-line assurance reviews and deep-dives across critical IT risk domains, reporting findings and tracking remediation to closure.

  • Support internal and external audits, including IT General Controls (ITGC) and Application Controls.

  • Run preliminary internal IT audits to prepare engineering, product, and business teams for official engagements.

Regulatory Alignment & Stakeholder Management

  • Lead Upvest's DORA obligations, including ICT risk management, incident classification, and third-party ICT risk oversight.

  • Track the regulatory landscape (BaFin, EBA, ESMA, ECB) and translate requirements into actionable risk guidance.

  • Act as the primary second-line contact for IT risk, reporting posture and material risk events to senior stakeholders, the C-suite, and the Risk Committee

What you bring:

  • Education: University degree in Computer Science, Information Technology, Information Security, or an equivalent academic/professional background.

  • Experience: Minimum of 5+ years of progressive professional experience in IT Governance, Risk, Compliance, and Security (IT GRC / IT Security) within a regulated financial institution, bank, fintech, or fast-scaling B2B platform environment.

  • Technical Depth: Deep operational understanding of IT governance standards (e.g., ISO 27001), regulatory risk requirements (BaFin BAIT/MaRisk), and modern resilience standards like DORA.

  • Communication Skills: Exceptional verbal and written articulation skills in English, with a proven ability to engage credibly with a multilingual international stakeholder base, technical engineering leads, and C-level executives.

  • Mindset: A strong product engineering and security-focused mindset, combined with commercial pragmatism and the ability to operate confidently under ambiguity.


How we Upvest in you:

  • Best-in-class AI tools: Every Upvenger has €20,000 per year to spend on the best AI tools available — so you're always working with the most powerful models and tooling on the market.

  • Impact-driven work: We’re building the infrastructure that will power the future of investing in Europe. It’s complex, ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no limits.

  • Wellbeing: Recharge with 30 days of annual leave and maintain a healthy lifestyle with sports benefits. Access confidential professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a one-month fully paid sabbatical after every 4 years of working at Upvest.

  • Development: Growth is in our DNA. Each Upvenger has access to a personal development budget and the freedom to decide how to use it.

  • Flexible work environment: Work from any of our hubs in Berlin, London or Tallinn hybrid or remotely across Europe, depending on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose.

  • Compensation and equity: We believe that all Upvengers contribute to our success and deserve a competitive, above-market salary and a participation in our employee equity program.

  • Team celebrations: Participate in company-wide events, such as UpFest, dinners, offsites and our Holiday party, to connect with colleagues and celebrate our achievements.

  • Inclusion: We’re committed to a culture where everyone belongs and thrives. Our Employee Resources Groups foster inclusion and connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies.


Our Values:

  • Make it easy for others. We simplify the complex and act with the best intentions

  • Own the outcome. We are proactive, fast and confident to get the job done, valuing progress over perfection.

  • Rise to the challenge. We aim high and push the boundaries. We stay curious, learn and celebrate our wins together.

  • Tell the story. We start with the Why to align on purpose. We are transparent and share knowledge to empower and inspire others.

Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Related keywords

IT GRCISO 27001:2022DORABaFinBAITMaRiskEBAESMAECBISMSITGCApplication ControlsBusiness Continuity ManagementRisk Appetite FrameworkFintechCyber Security

About Upvest

LinkedInVisit site

The Investment API

Industry
Financial Services
Company size
201-500 employees
Founded
2017
Headquarters
Berlin
LinkedIn followers
23,534
Total funding
$324M

Offer investments to your end users via our Investment API. Regulatory licenses included. 𝐏𝐥𝐞𝐚𝐬𝐞 𝐛𝐞 𝐚𝐰𝐚𝐫𝐞: 𝐔𝐩𝐯𝐞𝐬𝐭 𝐢𝐬 𝐚 𝐁𝟐𝐁 𝐜𝐨𝐦𝐩𝐚𝐧𝐲 𝐚𝐧𝐝 𝐝𝐨𝐞𝐬 𝐧𝐨𝐭 𝐨𝐟𝐟𝐞𝐫 𝐢𝐧𝐯𝐞𝐬𝐭𝐦𝐞𝐧𝐭 𝐩𝐫𝐨𝐝𝐮𝐜𝐭𝐬 𝐝𝐢𝐫𝐞𝐜𝐭𝐥𝐲 𝐭𝐨 𝐢𝐧𝐝𝐢𝐯𝐢𝐝𝐮𝐚𝐥𝐬. 𝐈𝐟 𝐲𝐨𝐮'𝐯𝐞 𝐛𝐞𝐞𝐧 𝐜𝐨𝐧𝐭𝐚𝐜𝐭𝐞𝐝 𝐛𝐲 𝐬𝐨𝐦𝐞𝐨𝐧𝐞 𝐜𝐥𝐚𝐢𝐦𝐢𝐧𝐠 𝐭𝐨 𝐫𝐞𝐩𝐫𝐞𝐬𝐞𝐧𝐭 𝐔𝐩𝐯𝐞𝐬𝐭 𝐰𝐢𝐭𝐡 𝐚 𝐩𝐞𝐫𝐬𝐨𝐧𝐚𝐥 𝐢𝐧𝐯𝐞𝐬𝐭𝐦𝐞𝐧𝐭 𝐨𝐩𝐩𝐨𝐫𝐭𝐮𝐧𝐢𝐭𝐲, 𝐨𝐫 𝐝𝐢𝐫𝐞𝐜𝐭𝐞𝐝 𝐭𝐨 𝐚𝐧𝐲 𝐰𝐞𝐛𝐬𝐢𝐭𝐞 𝐨𝐭𝐡𝐞𝐫 𝐭𝐡𝐚𝐧 𝐮𝐩𝐯𝐞𝐬𝐭.𝐜𝐨, 𝐢𝐭 𝐢𝐬 𝐥𝐢𝐤𝐞𝐥𝐲 𝐚 𝐬𝐜𝐚𝐦. 𝐁𝐢𝐭𝐭𝐞 𝐛𝐞𝐚𝐜𝐡𝐭𝐞𝐧 𝐒𝐢𝐞: 𝐔𝐩𝐯𝐞𝐬𝐭 𝐢𝐬𝐭 𝐞𝐢𝐧 𝐁𝟐𝐁-𝐔𝐧𝐭𝐞𝐫𝐧𝐞𝐡𝐦𝐞𝐧 𝐮𝐧𝐝 𝐛𝐢𝐞𝐭𝐞𝐭 𝐏𝐫𝐢𝐯𝐚𝐭𝐩𝐞𝐫𝐬𝐨𝐧𝐞𝐧 𝐤𝐞𝐢𝐧𝐞 𝐀𝐧𝐥𝐚𝐠𝐞𝐩𝐫𝐨𝐝𝐮𝐤𝐭𝐞 𝐝𝐢𝐫𝐞𝐤𝐭 𝐚𝐧. 𝐖𝐞𝐧𝐧 𝐒𝐢𝐞 𝐯𝐨𝐧 𝐣𝐞𝐦𝐚𝐧𝐝𝐞𝐦 𝐤𝐨𝐧𝐭𝐚𝐤𝐭𝐢𝐞𝐫𝐭 𝐰𝐮𝐫𝐝𝐞𝐧, 𝐝𝐞𝐫 𝐯𝐨𝐫𝐠𝐢𝐛𝐭, 𝐔𝐩𝐯𝐞𝐬𝐭 𝐳𝐮 𝐯𝐞𝐫𝐭𝐫𝐞𝐭𝐞𝐧 𝐮𝐧𝐝 𝐈𝐡𝐧𝐞𝐧 𝐞𝐢𝐧𝐞 𝐩𝐞𝐫𝐬𝐨̈𝐧𝐥𝐢𝐜𝐡𝐞 𝐈𝐧𝐯𝐞𝐬𝐭𝐢𝐭𝐢𝐨𝐧𝐬𝐦𝐨̈𝐠𝐥𝐢𝐜𝐡𝐤𝐞𝐢𝐭 𝐚𝐧𝐛𝐢𝐞𝐭𝐞𝐭, 𝐨𝐝𝐞𝐫 𝐰𝐞𝐧𝐧 𝐒𝐢𝐞 𝐚𝐮𝐟 𝐞𝐢𝐧𝐞 𝐚𝐧𝐝𝐞𝐫𝐞 𝐖𝐞𝐛𝐬𝐢𝐭𝐞 𝐚𝐥𝐬 𝐮𝐩𝐯𝐞𝐬𝐭.𝐜𝐨 𝐰𝐞𝐢𝐭𝐞𝐫𝐠𝐞𝐥𝐞𝐢𝐭𝐞𝐭 𝐰𝐞𝐫𝐝𝐞𝐧, 𝐡𝐚𝐧𝐝𝐞𝐥𝐭 𝐞𝐬 𝐬𝐢𝐜𝐡 𝐡𝐨̈𝐜𝐡𝐬𝐭𝐰𝐚𝐡𝐫𝐬𝐜𝐡𝐞𝐢𝐧𝐥𝐢𝐜𝐡 𝐮𝐦 𝐞𝐢𝐧𝐞𝐧 𝐁𝐞𝐭𝐫𝐮𝐠.

Offices: Prenzlauer Allee 242-247, Haus 8, Berlin, 10405 , DE

FintechAPICapital MarketsFinancial servicesInvestment featuresand Investment APIFinanceInformation TechnologyBankingSoftware
View all jobs at Upvest

About Upvest

LinkedInVisit site

The Investment API

Industry
Financial Services
Company size
201-500 employees
Founded
2017
Headquarters
Berlin
LinkedIn followers
23,534
Total funding
$324M

Offer investments to your end users via our Investment API. Regulatory licenses included. 𝐏𝐥𝐞𝐚𝐬𝐞 𝐛𝐞 𝐚𝐰𝐚𝐫𝐞: 𝐔𝐩𝐯𝐞𝐬𝐭 𝐢𝐬 𝐚 𝐁𝟐𝐁 𝐜𝐨𝐦𝐩𝐚𝐧𝐲 𝐚𝐧𝐝 𝐝𝐨𝐞𝐬 𝐧𝐨𝐭 𝐨𝐟𝐟𝐞𝐫 𝐢𝐧𝐯𝐞𝐬𝐭𝐦𝐞𝐧𝐭 𝐩𝐫𝐨𝐝𝐮𝐜𝐭𝐬 𝐝𝐢𝐫𝐞𝐜𝐭𝐥𝐲 𝐭𝐨 𝐢𝐧𝐝𝐢𝐯𝐢𝐝𝐮𝐚𝐥𝐬. 𝐈𝐟 𝐲𝐨𝐮'𝐯𝐞 𝐛𝐞𝐞𝐧 𝐜𝐨𝐧𝐭𝐚𝐜𝐭𝐞𝐝 𝐛𝐲 𝐬𝐨𝐦𝐞𝐨𝐧𝐞 𝐜𝐥𝐚𝐢𝐦𝐢𝐧𝐠 𝐭𝐨 𝐫𝐞𝐩𝐫𝐞𝐬𝐞𝐧𝐭 𝐔𝐩𝐯𝐞𝐬𝐭 𝐰𝐢𝐭𝐡 𝐚 𝐩𝐞𝐫𝐬𝐨𝐧𝐚𝐥 𝐢𝐧𝐯𝐞𝐬𝐭𝐦𝐞𝐧𝐭 𝐨𝐩𝐩𝐨𝐫𝐭𝐮𝐧𝐢𝐭𝐲, 𝐨𝐫 𝐝𝐢𝐫𝐞𝐜𝐭𝐞𝐝 𝐭𝐨 𝐚𝐧𝐲 𝐰𝐞𝐛𝐬𝐢𝐭𝐞 𝐨𝐭𝐡𝐞𝐫 𝐭𝐡𝐚𝐧 𝐮𝐩𝐯𝐞𝐬𝐭.𝐜𝐨, 𝐢𝐭 𝐢𝐬 𝐥𝐢𝐤𝐞𝐥𝐲 𝐚 𝐬𝐜𝐚𝐦. 𝐁𝐢𝐭𝐭𝐞 𝐛𝐞𝐚𝐜𝐡𝐭𝐞𝐧 𝐒𝐢𝐞: 𝐔𝐩𝐯𝐞𝐬𝐭 𝐢𝐬𝐭 𝐞𝐢𝐧 𝐁𝟐𝐁-𝐔𝐧𝐭𝐞𝐫𝐧𝐞𝐡𝐦𝐞𝐧 𝐮𝐧𝐝 𝐛𝐢𝐞𝐭𝐞𝐭 𝐏𝐫𝐢𝐯𝐚𝐭𝐩𝐞𝐫𝐬𝐨𝐧𝐞𝐧 𝐤𝐞𝐢𝐧𝐞 𝐀𝐧𝐥𝐚𝐠𝐞𝐩𝐫𝐨𝐝𝐮𝐤𝐭𝐞 𝐝𝐢𝐫𝐞𝐤𝐭 𝐚𝐧. 𝐖𝐞𝐧𝐧 𝐒𝐢𝐞 𝐯𝐨𝐧 𝐣𝐞𝐦𝐚𝐧𝐝𝐞𝐦 𝐤𝐨𝐧𝐭𝐚𝐤𝐭𝐢𝐞𝐫𝐭 𝐰𝐮𝐫𝐝𝐞𝐧, 𝐝𝐞𝐫 𝐯𝐨𝐫𝐠𝐢𝐛𝐭, 𝐔𝐩𝐯𝐞𝐬𝐭 𝐳𝐮 𝐯𝐞𝐫𝐭𝐫𝐞𝐭𝐞𝐧 𝐮𝐧𝐝 𝐈𝐡𝐧𝐞𝐧 𝐞𝐢𝐧𝐞 𝐩𝐞𝐫𝐬𝐨̈𝐧𝐥𝐢𝐜𝐡𝐞 𝐈𝐧𝐯𝐞𝐬𝐭𝐢𝐭𝐢𝐨𝐧𝐬𝐦𝐨̈𝐠𝐥𝐢𝐜𝐡𝐤𝐞𝐢𝐭 𝐚𝐧𝐛𝐢𝐞𝐭𝐞𝐭, 𝐨𝐝𝐞𝐫 𝐰𝐞𝐧𝐧 𝐒𝐢𝐞 𝐚𝐮𝐟 𝐞𝐢𝐧𝐞 𝐚𝐧𝐝𝐞𝐫𝐞 𝐖𝐞𝐛𝐬𝐢𝐭𝐞 𝐚𝐥𝐬 𝐮𝐩𝐯𝐞𝐬𝐭.𝐜𝐨 𝐰𝐞𝐢𝐭𝐞𝐫𝐠𝐞𝐥𝐞𝐢𝐭𝐞𝐭 𝐰𝐞𝐫𝐝𝐞𝐧, 𝐡𝐚𝐧𝐝𝐞𝐥𝐭 𝐞𝐬 𝐬𝐢𝐜𝐡 𝐡𝐨̈𝐜𝐡𝐬𝐭𝐰𝐚𝐡𝐫𝐬𝐜𝐡𝐞𝐢𝐧𝐥𝐢𝐜𝐡 𝐮𝐦 𝐞𝐢𝐧𝐞𝐧 𝐁𝐞𝐭𝐫𝐮𝐠.

Offices: Prenzlauer Allee 242-247, Haus 8, Berlin, 10405 , DE

FintechAPICapital MarketsFinancial servicesInvestment featuresand Investment APIFinanceInformation TechnologyBankingSoftware
View all jobs at Upvest

Similar companies hiring

JPMorganChase (2468)HSBC (2324)Wells Fargo (1588)Citi (1459)H&R Block (1410)Satori Mortgage (NMLS: 4190) (959)PNC (907)Truist (787)BMO (787)Tata Capital (786)State Street (580)WealthBridge Financial Group (568)
Clera home

Your AI-talent agent. Connecting talents with dream jobs.

Earn $5,000

Tools

  • Salary Calculator
  • Resume Review
  • Startup Map

Explore

  • Jobs
  • Discover Jobs
  • Companies
  • Acquihire
  • Referral

Company

  • Manifesto
  • Engineering
  • We are hiring!
  • FAQs
  • Blog
  • Press

Tools

  • Salary Calculator
  • Resume Review
  • Startup Map

Explore

  • Jobs
  • Discover Jobs
  • Companies
  • Acquihire
  • Referral

Company

  • Manifesto
  • Engineering
  • We are hiring!
  • FAQs
  • Blog
  • Press

© 2026 Clera Labs, Inc.

PrivacyTermsBug Bounty