Associate Director - ICT Risk Management

Scope Ratings

Poznań

On-site

PLN 220,000 - 320,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Benefits package

Job summary

Scope Ratings seeks an ICT Risk Manager to run the ICT risk management framework day-to-day, including risk assessments, policy maintenance, resilience testing, and reporting. The role oversees information security, ICT business continuity and third-party risk, coordinating with business and technology functions.

The successful candidate will draft policies, oversee testing programs (including penetration testing and vulnerability management), and communicate risk insights to the Resilience

Qualifications

  • 4+ years of experience in risk, security, or resilience discipline in financial services or regulated industry.
  • Experience drafting policies, methodologies and process documentation.
  • Practical experience in ICT risk assessment cycles and security testing oversight.
  • Experience working with first-line business and technology functions on risk topics.
  • Awareness of threat landscape in financial services and cyber developments.

Responsibilities

  • Draft and maintain ICT risk management framework, policies and methodologies.
  • Design processes for vendor assessment, change risk review, and risk reporting.
  • Respond to client security questionnaires and maintain standard responses library.
  • Run ICT risk assessment cycles and oversee security testing programs.
  • Maintain cyber threat landscape through threat intelligence and ISAC participation.
  • Consolidate findings into a single ICT findings view and track remediation.
  • Write executive summaries for Resilience Committee and senior management.

Skills

Risk management
Information security
Resilience
Vendor risk management
English fluency
Policy drafting
Security testing oversight
Threat intelligence
Business continuity

Education

Experience in financial services or regulated industry

Tools

ISO 27001
NIST CSF
DORA

Job description

Scope Ratings is looking for an ICT Risk Manager as part of the ICT Risk management function, and will be responsible for executing the ICT risk management framework on a day-to-day basis, including running the ICT risk assessment cycle, maintaining the function's registers, coordinating resilience testing and producing the function's reporting.

ICT Risk Management owns the ICT risk management framework and provides independent oversight of its implementation. The function incorporates oversight of Information Security, ICT business continuity and ICT third-party risk management.

Duties & responsibilities
  • Draft and maintain the ICT risk management framework, the underlying policies and methodologies.
  • Design the function's processes and workflows, including vendor assessment, finding management and change risk review, in collaboration with business and technology functions.
  • Respond to client security questionnaires and ad-hoc security and resilience disclosure requests, and maintain a library of standard responses.
  • Identify opportunities to streamline and automate the function's processes.
  • Build and maintain effective relationships with business, technology and control functions, supporting them in identifying ICT risks, including vendor assessments, business impact analyses (BIAs) and control documentation.
  • Design and run ICT business continuity and resilience exercises, including scenarios, facilitation and capturing lessons learned.
  • Run the ICT security testing programme, including penetration testing (scoping, rules of engagement, vendor triage, oversight, finding triage), vulnerability scanning, social engineering and phishing simulations, and breach scenario exercises.
  • Maintain the cyber threat landscape through active monitoring of threat intelligence sources, ISAC participation and sectoral information sharing, and translate threat intel into scenarios and risk profile updates.
  • Consolidate findings from audits, risk assessments, security testing and incidents into a single ICT findings view, and track remediation through to closure across business and technology functions, escalating delays and blockers to the Head of ICT Risk Management.
  • Write executive summaries and briefings on ICT risk topics for the Resilience Committee, Senior and Executive Management and the Boards.
  • 4+ years of experience in a risk, security, or resilience discipline, such as ICT/technology risk, information security, or operational resilience, within financial services or another regulated industry.
  • Experience drafting policies, methodologies and process documentation.
  • Practical experience in one or more of the following: running ICT risk assessment cycles, commissioning or overseeing security testing programmes (including penetration testing and vulnerability management), designing and facilitating business continuity exercises, reviewing and challenging incident investigations and problem management led by first-line teams.
  • Experience working with first-line business and technology functions on risk or security-related topics.
  • Working knowledge of security or resilience frameworks, such as DORA, the EBA Guidelines on ICT and Security Risk Management, and of recognised standards including ISO/IEC 27001 and NIST Cybersecurity Framework.
  • Awareness of the threat landscape relevant to financial services and of current developments in cyber, AI and ICT third-party risk.
  • Preferred experience in third-party or vendor risk management, or in a related discipline involving vendor oversight, such as procurement, vendor governance, or supplier relationship management.
  • Preferred working knowledge of secure software development practices and the controls embedded in application, model and infrastructure-as-code development lifecycles.
  • Preferred certification in information security or ICT risk management demonstrating expertise across security programmes and operational risk practices, such as CISM or CRISC.
  • Fluent in English (written and spoken)
Compensation Range:

The compensation range disclosed may encompass multiple title levels (Scope internal levels of seniority). Your actual compensation will depend on a variety of factors, including but not limited to your individual experience, education, and seniority, and the final salary will be determined during the interview and evaluation process.

Bonus:

Discretionary

Benefits:

Scope offers an extensive range of benefits, please check our benefits page for more details.

Please note: For non-EU applicants, a valid work and residence permit is a prerequisite for this job position. Unfortunately, we are unable to sponsor relocation from outside of the EU at this time.

About Scope

With more than 250 employees operating from offices in Berlin, Frankfurt, London, Madrid, Milan, Oslo and Paris, Scope Group is the leading European provider of independent credit ratings, ESG and fund analysis. Based on forward-looking and innovative methodologies, Scope offers a European perspective that contributes to greater diversity of opinion for institutional investors worldwide. Scope Ratings is the largest European credit rating agency, registered in accordance with EU and UK rating agency regulation, offering opinion-driven and non-mechanistic credit risk analysis. Scope ESG Analysis provides tools for analysing and reporting on ESG impact and risk, as well as second-party opinions on green, social and sustainable bonds. Scope Fund Analysis rates more than 10,000 funds and asset managers across all major asset classes.

We embrace people from all backgrounds, regardless of culture, ethnicity and gender. We ensure that our application processes are free from discrimination. By valuing each individual's unique background and perspectives, we strive to create an environment where all employees can thrive and contribute their best. Our dedication to equality and inclusivity reflects our belief that diversity drives innovation and success.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Director - ICT Risk Management
Associate Director - ICT Risk Management

Scope Ratings GmbH • Poznań

On-site
PLN 210,000 - 290,000
Sales Support & Process Digitalisation Specialist
Sales Support & Process Digitalisation Specialist

Scope Ratings • Poznań

On-site
PLN 92,000 - 135,000
Discretionary bonus
Comprehensive benefits
Risk Manager
Risk Manager

Banking Circle • Warszawa

Hybrid
PLN 240,000 - 360,000
Manager, Business Risks & Controls, Workflows
Manager, Business Risks & Controls, Workflows

London Stock Exchange Group • Polska

On-site
PLN 178,000 - 281,000
Cyber Security Risk Analyst
Cyber Security Risk Analyst

Euroclear • Kraków

Hybrid
PLN 180,000 - 300,000
Director, Non Financial Risk
Director, Non Financial Risk

London Stock Exchange Group • Gdynia

On-site
PLN 291,000 - 484,000
Annual Bonus Plan
Benefits program
Director, Non Financial Risk
Director, Non Financial Risk

LSEG • Gdynia

On-site
PLN 291,000 - 484,000
Manager, Business Risks & Controls, Workflows
Manager, Business Risks & Controls, Workflows

LSEG • Gdynia

On-site
PLN 178,000 - 281,000
Director, ICT Risk & Resilience Strategy
Director, ICT Risk & Resilience Strategy

Scope Ratings GmbH • Poznań

On-site
PLN 210,000 - 290,000
Cyber Incident & Response Team Analyst
Cyber Incident & Response Team Analyst

Euroclear • Poland

On-site
PLN 180,000 - 260,000
Competitive benefits
Hybrid work model