CyberSecurity Frontline Risk and Control Manager

UBP - Union Bancaire Privée

Genf

Hybrid

CHF 180.000 - 240.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

UBP - Union Bancaire Privée in Geneva seeks an experienced cybersecurity risk leader to own first line of defence, shaping risk and controls across FINMA, EU, UK, HK, and Singapore. You will lead cross‑functional teams, partner with Tech, Risk, Compliance, and business units to mature risk posture and ensure regulatory adherence.

Hybrid arrangement with Swiss residence required; you will mentor staff and report to senior management, delivering clear risk insights and resilient security

Qualifikationen

  • 8–12+ years in cybersecurity with first line risk and control management in a regulated bank.
  • Designing and operating cyber risk and control frameworks (policies, KRIs, KPIs).
  • Leading enterprise vulnerability management, governance, and remediation.
  • Strong regulatory engagement, audit responses, and evidence management.
  • Cross‑border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS).

Aufgaben

  • Oversee risk management framework, policies, standards, and controls catalog for first line.
  • Lead vulnerability management strategy, risk-based prioritization, and remediation.
  • Engage with regulators and auditors; prepare evidence and responses.
  • Mentor a small team and develop junior staff; report to risk committees.
  • Communicate complex cyber risk topics to senior management and stakeholders.

Kenntnisse

Cybersecurity leadership
Regulatory engagement
Stakeholder management
Communication
Risk governance
First line of defense

Ausbildung

Bachelor’s or Master’s in information security or related field
Security certifications preferred: CISSP, CRISC, ISO 27001 lead

Tools

Qualys/Tenable/Rapid7
SAST/DAST/SCA
CSPM
EDR/XDR
Cloud platforms (AWS/Azure/GCP)

Jobbeschreibung

Mission

Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management. Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore). Partner with Technology, Business, Risk, and Compliance stakeholders to proactively manage cyber risks, ensure regulatory adherence, and safeguard UBP’s clients and assets.

Governance & Risk Management
  • Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
  • Drive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales.
  • Maintain risk registers and key risk indicators (KRIs). Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap.
  • Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005).
Vulnerability Management
  • Lead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties).
  • Oversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs.
  • Partner with Infrastructure, DevSecOps, and application owners to embed secure‑by‑design principles and shift‑left controls.
  • Report on exposure, trends, and risk posture to senior management and risk committees.
Regulatory Compliance & Audit Support
  • Interpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS).
  • Prepare evidence and responses for internal/external audits, regulatory exams, and board‑level reporting.
  • Maintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings.
  • Manage and mentor a small team; build capabilities and career growth for junior staff.
  • Communicate complex cyber risk topics clearly to senior management and non‑technical stakeholders.
  • Champion a risk‑aware culture across technology and business functions.
Leadership & Stakeholder Management
  • Manage and mentor a small team; build capabilities and career growth for junior staff.
  • Communicate complex cyber risk topics clearly to senior management and non‑technical stakeholders.
  • Champion a risk‑aware culture across technology and business functions.
Your Profile
  • Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
  • Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
  • Strategic thinker with hands‑on rigor—able to sustain current frameworks while maturing them for scalability and transparency.
  • Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff.
Education
  • Bachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field.
  • Relevant certifications preferred: CISSP, BISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent.
Experience Technical Skills
  • 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank.
  • Proven track record in:
  • Designing and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing).
  • Leading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance).
  • Regulatory engagement, audit response, and evidence management.
  • Cross‑border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS).
  • Practical familiarity with:
  • Frameworks/standards: NIST CSF, NIST 800‑53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATT&CK.
  • VM tooling & ecosystems: Qualys/Tenable/Rapid7, SAST/DAST, SCA, container and cloud posture management (CSPM), EDR/XDR.
  • Enterprise environments: Windows/Unix, networks, databases, microservices, SaaS, public cloud (AWS/Azure/GCP).
  • Secure SDLC/DevSecOps and CI/CD integration of controls.
  • Reporting and metrics for executive forums and risk committees.
Languages
  • English: fluent (written and spoken).
  • French - strong advantage.
Personal skills
  • Leadership: coaching mindset, able to build high‑performing teams and upskill junior colleagues.
  • Communication: clear, concise, and audience‑appropriate; strong presentation and writing skills.
  • Decision‑making: risk‑based prioritisation, data‑driven, and pragmatic under time pressure.
  • Collaboration: strong stakeholder management across IT, Risk, Compliance, and business lines.
  • Adaptability: navigates ambiguity; balances regulatory rigor with business practicality.
  • Integrity: high professional ethics and commitment to client and bank protection.
Others
  • Location: Geneva
  • Swiss Residence
  • Hybrid working arrangements aligned with UBP policy.
  • Candidates must have the right to work in the relevant jurisdiction.
  • Background checks required consistent with banking standards.
Core Competencies
  • Adherence to the company’s values: Dedication, Conviction, Agility, and Responsibility - Compliance with regulations and internal directives
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

CyberSecurity Frontline Risk and Control Manager
CyberSecurity Frontline Risk and Control Manager

Union Bancaire Privée • Genf

Hybrid
CHF 120.000 - 160.000
Hybrid working arrangements
Professional development opportunities
Competitive salary and benefits
Head of Cyber Security Engineering
Head of Cyber Security Engineering

Union Bancaire Privée • Genf

Vor Ort
CHF 120.000 - 160.000
Business Information Risk Officer – 6-9 months fixed-term assignment
Business Information Risk Officer – 6-9 months fixed-term assignment

Syz Group • Genf

Vor Ort
CHF 120.000 - 160.000
Frontline Cyber Risk & Controls Lead
Frontline Cyber Risk & Controls Lead

UBP - Union Bancaire Privée • Genf

Hybrid
CHF 180.000 - 240.000
Head of Information Security
Head of Information Security

PHOENIQS • Basel

Vor Ort
CHF 120.000 - 150.000
Leadership role with end-to-end ownership of information security
Opportunities for long-term development
High visibility within senior management
Security engineer
Security engineer

UBP - Union Bancaire Privée • Genf

Vor Ort
CHF 110.000 - 140.000
Security engineer
Security engineer

UNION BANCAIRE PRIVÉE, UBP SA • Genf

Vor Ort
CHF 120.000 - 180.000
Security engineer
Security engineer

Union Bancaire Privée • Genf

Hybrid
CHF 120.000 - 170.000
Senior Operational Risk Specialist - Private Banking
Senior Operational Risk Specialist - Private Banking

Finders SA • Genf

Vor Ort
CHF 150.000 - 210.000
Cyber Risk & Controls Lead, First Line Defence
Cyber Risk & Controls Lead, First Line Defence

Union Bancaire Privée • Genf

Hybrid
CHF 120.000 - 160.000
Hybrid working arrangements
Professional development opportunities
Competitive salary and benefits