Operations Risk & Security Audit Manager

NTT America, Inc.

Roma

Ibrido

EUR 90.000 - 130.000

Tempo pieno

2 giorni fa
Candidati tra i primi
Generatore di candidature

Trasforma questo ruolo in un colloquio — un curriculum e una lettera di presentazione personalizzati in base a ciò che cerca questo datore di lavoro.

Supera i filtri ATS

Vantaggi offerti da questo lavoro

Private Health Insurance
Training & Certification
Flexible working style
Team events

Descrizione del lavoro

NTT DATA Romania is seeking an experienced Operational Risk & Security Audit Manager to lead programme-level risk management and security audit activities within a large IT services environment. You will coordinate across delivery teams, contractors and senior stakeholders to drive risk mitigation and governance.

You will maintain risk registers, perform risk assessments, and develop formal risk communications for executive governance.

Competenze

  • Experience in operational risk management within large IT services environments.
  • Hands-on security and compliance auditing experience.
  • Ability to coordinate across multiple delivery teams and stakeholders.

Mansioni

  • Maintain and develop the Programme Risk Register across risk types.
  • Coordinate programme-level risks with workstreams and delivery teams.
  • Perform qualitative and quantitative risk assessments and monitor mitigations.
  • Develop risk communications and escalation materials for governance bodies.
  • Ensure risks and mitigations are reflected in project plans and SOWs.
  • Maintain risk dashboards, KPIs, and management reporting.
  • Contribute to ISMS and information security programme reporting.
  • Facilitate risk workshops and executive-level risk reporting.
  • Coordinate risk management across multiple workstreams and partners.
  • Align risk methods with ISO 27001 and European cybersecurity regulations.

Conoscenze

Operational risk management
Enterprise risk management
Information security risk management
Security auditing
Risk assessment
Stakeholder management
Audit coordination
Data-driven reporting
Analytical thinking
Governance & compliance

Descrizione del lavoro

Who we are

We are looking for an experienced Operational Risk & Security Audit Manager t o assume combined responsibility for programme-level operational risk management and security audit activities within a large-scale, complex IT services environment.

The role requires strong experience in enterprise risk management, information security, audit and compliance, together with the ability to coordinate effectively across multiple delivery teams, contractors and senior stakeholders.

What you'll be doing
  • Maintain and continuously develop the overall Programme Risk Register, covering strategic, operational, financial, contractual, security and delivery risks, while ensuring appropriate integration with security risk management activities.

  • Identify, assess and coordinate programme-level risks in collaboration with workstream leads, business owners, delivery teams and other relevant stakeholders.

  • Perform qualitative and quantitative risk assessments, including likelihood and impact analysis, residual risk evaluation and ongoing monitoring of agreed mitigation measures.

  • Develop formal risk communications, mitigation plans and escalation materials for senior management and relevant programme governance bodies.

  • Ensure identified risks, dependencies and mitigation measures are appropriately reflected in project plans, statements of work and strategic planning activities.

  • Monitor the overall programme risk profile and maintain risk dashboards, KPIs and management reporting, providing clear visibility of key risks, trends, mitigation progress and areas requiring management attention.

  • Maintain operational risk information required for security, operational and management dashboards and contribute risk-related analysis to periodic strategic, operational and financial programme reporting.

  • Facilitate risk workshops, periodic risk reviews and executive-level risk reporting, ensuring appropriate ownership, follow-up and escalation of identified risks.

  • Coordinate risk management activities across multiple workstreams, delivery organisations and third-party contractors, promoting a consistent approach to risk identification, assessment and treatment.

  • Work with internal and external delivery partners to align risk assessment methodologies, proposed mitigation actions and residual risk acceptance.

  • Ensure appropriate traceability of risks, decisions, mitigation activities, approvals and lessons learned within the programme's knowledge management environment.

  • Contribute to continuous service improvement by incorporating lessons learned from risk events, incidents, audit findings and completed mitigation activities.

  • Align programme risk management activities with recognised information security and risk management standards and frameworks, including ISO 27001, while considering applicable European cybersecurity and operational resilience requirements, including NIS2, CRA and DORA.

  • Plan, coordinate, execute and report on periodic internal security audits covering relevant security controls, processes, systems and supporting evidence.

  • Conduct security and compliance assessments across areas including security controls, risk treatment plans, vulnerability and patch management, incident handling, access control and supply-chain security.

  • Identify non-conformities, control weaknesses and improvement opportunities, prepare formal audit findings and recommendations, and monitor remediation through agreed corrective action plans.

  • Support external audits and regulatory or customer inspections, including the preparation, review and coordination of required evidence packages.

  • Represent the service provider during relevant audit, compliance and inspection activities and coordinate responses with internal stakeholders and delivery partners.

  • Maintain the audit universe, audit calendar, audit evidence, findings and associated documentation, ensuring appropriate governance, traceability and record keeping.

  • Ensure appropriate audit independence and objectivity, remaining organisationally independent from the activities and teams being audited.

  • Contribute to periodic security programme, risk, compliance and management reporting, providing clear visibility of audit findings, remediation status and recurring control issues.

  • Support continuous improvement of the Information Security Management System (ISMS) based on audit findings, risk assessments, incidents and lessons learned.

  • Drive continuous improvement and, where appropriate, automation of risk and audit processes, dashboards, KPIs, evidence management and management reporting.

  • Act as backup for the Security Risk Management function when required and support broader programme security governance activities.

What you'll bring along
  • Strong professional experience in operational risk management, enterprise risk management, information security risk management and security auditing, ideally within large-scale or complex IT services environments.

  • Demonstrable experience maintaining enterprise or programme-level risk registers and coordinating risk identification, assessment, mitigation and escalation across multiple teams and stakeholders.

  • Hands-on experience planning and conducting security and compliance audits, documenting findings, identifying control weaknesses and managing corrective action plans through to closure.

  • Strong knowledge of ISO 27001, ISMS principles and recognised information security, audit and risk management practices and frameworks.

  • Good understanding of relevant European cybersecurity and operational resilience regulations, including NIS2, the Cyber Resilience Act (CRA) and DORA.

  • Experience working within complex multi-vendor or multi- contractor delivery environments, coordinating effectively across internal teams, customers, suppliers and external delivery partners.

  • Strong analytical capabilities, including experience with qualitative and quantitative risk assessment, likelihood and impact analysis, residual risk evaluation and mitigation effectiveness monitoring.

  • Experience developing, maintaining and improving risk and audit KPIs, dashboards, metrics and management reporting.

  • Ability to facilitate risk assessments, workshops, audit meetings and management reviews and to translate complex risk and security topics into clear, actionable information.

  • Strong understanding of security controls and compliance areas such as vulnerability and patch management, incident management, access control, supply-chain security and risk treatment.

  • Experience supporting external audits, customer assessments, regulatory inspections or similar assurance activities, including evidence preparation and stakeholder coordination.

  • Strong documentation and governance capabilities, with particular attention to auditability, evidence quality, traceability and consistency.

  • Excellent stakeholder-management and communication skills, with the ability to engage effectively with technical specialists, delivery teams, management and executive stakeholders.

  • Ability to challenge constructively, maintain appropriate audit independence and provide objective, evidence-based risk and compliance assessments.

  • A structured, analytical and proactive approach, with the ability to operate independently while coordinating effectively across security, operational, technical, commercial and management functions.

What’s in it for you
  • New beginnings can be a challenge. We promise a smooth integration and a supportive mentor

  • Pick your working style: choose from Remote, Hybrid or Office work opportunities

  • Early bird or night owl? Our projects have different working hours to suit your needs

  • Nobody is born an expert. Sharpen your tech skills with our sponsored certificates, trainings and top e-learning platforms

  • We want you to stay healthy! Enjoy our Private Health Insurance – it’s custom-made for you

  • A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School

  • Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ancestry, age, sex, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic protected by law. We are committed to creating a diverse and inclusive environment for all employees.

What’s in it for you
  • New beginnings can be a challenge. We promise a smooth integration and a supportive mentor

  • Pick your working style: choose from Remote, Hybrid or Office work opportunities

  • Early bird or night owl? Our projects have different working hours to suit your needs

  • Nobody is born an expert. Sharpen your tech skills with our sponsored certificates, trainings and top e-learning platforms

  • We want you to stay healthy! Enjoy our Private Health Insurance – it’s custom-made for you

  • A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School

  • Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

Make this the place you grow

Your unique talent is what matters. NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ethnicity, age, gender, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic.

#LI-AR2

Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Senior Backend Engineer_Spring Security
Senior Backend Engineer_Spring Security

NTT America, Inc. • Roma

Ibrido
EUR 32.000 - 49.000
Remote work options
Hybrid or Office work options
Sponsored certifications and trainings
+2
Full-Stack Developer with German
Full-Stack Developer with German

NTT America, Inc. • Roma

Ibrido
EUR 55.000 - 80.000
Remote/Hybrid/Office options
Private Health Insurance
Sponsored certifications
+2
Java Developer with GraphQL
Java Developer with GraphQL

NTT America, Inc. • Roma

Ibrido
EUR 23.000 - 34.000
Private Health Insurance
Sponsored certifications
Coaching & Training
+2
SAP Basis Administrator
SAP Basis Administrator

NTT America, Inc. • Roma

Ibrido
EUR 17.000 - 28.000
Private Health Insurance
Certifications & training
Coaching & development
Senior SAP EWM Consultant
Senior SAP EWM Consultant

NTT America, Inc. • Roma

Ibrido
EUR 50.000 - 75.000
Remote work options
Private health insurance
Coaching sessions
+2
Java Developer with AWS
Java Developer with AWS

NTT America, Inc. • Roma

Ibrido
EUR 65.000 - 90.000
Remote/Hybrid/Office work options
Private Health Insurance
Sponsored certifications and trainings
+2
Senior Network & Security Technical Lead (Cisco & Palo Alto)
Senior Network & Security Technical Lead (Cisco & Palo Alto)

NTT DATA, Inc. • Milano

In loco
EUR 110.000 - 150.000
Hybrid Working
Remote Field Service Engineer (L1)
Remote Field Service Engineer (L1)

NTT America, Inc. • Milano

Ibrido
EUR 32.000 - 48.000
Hybrid Working
IT Security Business Analyst
IT Security Business Analyst

NTT DATA Europe & Latam • Emilia-Romagna

In loco
EUR 60.000 - 90.000
Remote Field Service Engineer (L1)
Remote Field Service Engineer (L1)

NTT Limited • Segrate

Remoto
EUR 34.000 - 46.000