Associate Director - ICT Risk Management

Scope Ratings GmbH

Poznań

On-site

PLN 210,000 - 290,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Scope Ratings GmbH is seeking an ICT Risk Manager to lead day-to-day execution of the ICT risk management framework, including risk assessments, registers, resilience testing, and reporting. You will collaborate with business and technology functions to strengthen controls and oversight across ICT risk domains.

The role requires 4+ years in risk, security or resilience, familiarity with frameworks such as ISO 27001/NIST and strong English skills.

Qualifications

  • Draft policies, methodologies and process documentation.
  • Design processes/workflows including vendor assessment and change risk review.
  • Respond to client security questionnaires and maintain library of responses.
  • Identify opportunities to streamline and automate the function's processes.
  • Build relationships with business, technology and control functions for ICT risks.
  • Design and run ICT business continuity and resilience exercises.
  • Run ICT security testing programmes including penetration testing and vulnerability management.
  • Maintain cyber threat landscape and translate intel into risk updates.
  • Consolidate findings from audits, risk assessments and incidents into a single ICT findings view.
  • Write executive summaries for Resilience Committee and senior management.

Responsibilities

  • Draft and maintain the ICT risk management framework, the underlying policies and methodologies.
  • Design the function's processes and workflows, including vendor assessment, finding management and change risk review, in collaboration with business and technology functions.
  • Respond to client security questionnaires and ad-hoc security and resilience disclosure requests, and maintain a library of standard responses.
  • Identify opportunities to streamline and automate the function's processes.
  • Build and maintain effective relationships with business, technology and control functions, supporting them in identifying ICT risks, including vendor assessments, BIAs and control documentation.
  • Design and run ICT business continuity and resilience exercises, including scenarios, facilitation and capturing lessons learned.
  • Run the ICT security testing programme, including penetration testing, vulnerability scanning, social engineering and phishing simulations, and breach scenario exercises.
  • Maintain the cyber threat landscape through active monitoring of threat intelligence sources, ISAC participation and sectoral information sharing, and translate threat intel into scenarios and risk profile updates.
  • Consolidate findings from audits, risk assessments, security testing and incidents into a single ICT findings view, and track remediation through to closure across business and technology functions, escalating delays and blockers to the Head of ICT Risk Management.
  • Write executive summaries and briefings on ICT risk topics for the Resilience Committee, Senior and Executive Management and the Boards.

Skills

ICT risk management
Policy drafting
Security testing programs
Business continuity
Vendor risk management
ISO/IEC 27001
NIST Cybersecurity Framework
DORA familiarity
English fluency

Job description

Scope Ratings is looking for an ICT Risk Manager as part of the ICT Risk management function, and will be responsible for executing the ICT risk management framework on a day-to-day basis, including running the ICT risk assessment cycle, maintaining the function's registers, coordinating resilience testing and producing the function's reporting.

ICT Risk Management owns the ICT risk management framework and provides independent oversight of its implementation. The function incorporates oversight of Information Security, ICT business continuity and ICT third-party risk management.

Duties & responsibilities
  • Draft and maintain the ICT risk management framework, the underlying policies and methodologies.
  • Design the function's processes and workflows, including vendor assessment, finding management and change risk review, in collaboration with business and technology functions.
  • Respond to client security questionnaires and ad-hoc security and resilience disclosure requests, and maintain a library of standard responses.
  • Identify opportunities to streamline and automate the function's processes.
  • Build and maintain effective relationships with business, technology and control functions, supporting them in identifying ICT risks, including vendor assessments, business impact analyses (BIAs) and control documentation.
  • Design and run ICT business continuity and resilience exercises, including scenarios, facilitation and capturing lessons learned.
  • Run the ICT security testing programme, including penetration testing (scoping, rules of engagement, vendor triage, oversight, finding triage), vulnerability scanning, social engineering and phishing simulations, and breach scenario exercises.
  • Maintain the cyber threat landscape through active monitoring of threat intelligence sources, ISAC participation and sectoral information sharing, and translate threat intel into scenarios and risk profile updates.
  • Consolidate findings from audits, risk assessments, security testing and incidents into a single ICT findings view, and track remediation through to closure across business and technology functions, escalating delays and blockers to the Head of ICT Risk Management.
  • Write executive summaries and briefings on ICT risk topics for the Resilience Committee, Senior and Executive Management and the Boards.
Professional & personal qualifications
  • 4+ years of experience in a risk, security, or resilience discipline, such as ICT/technology risk, information security, or operational resilience, within financial services or another regulated industry.
  • Experience drafting policies, methodologies and process documentation.
  • Practical experience in one or more of the following: running ICT risk assessment cycles, commissioning or overseeing security testing programmes (including penetration testing and vulnerability management), designing and facilitating business continuity exercises, reviewing and challenging incident investigations and problem management led by first-line teams.
  • Experience working with first-line business and technology functions on risk or security-related topics.
  • Working knowledge of security or resilience frameworks, such as DORA, the EBA Guidelines on ICT and Security Risk Management, and of recognised standards including ISO/IEC 27001 and NIST Cybersecurity Framework.
  • Awareness of the threat landscape relevant to financial services and of current developments in cyber, AI and ICT third-party risk.
  • Preferred experience in third-party or vendor risk management, or in a related discipline involving vendor oversight, such as procurement, vendor governance, or supplier relationship management.
  • Preferred working knowledge of secure software development practices and the controls embedded in application, model and infrastructure-as-code development lifecycles.
  • Preferred certification in information security or ICT risk management demonstrating expertise across security programmes and operational risk practices, such as CISM or CRISC.
  • Fluent in English (written and spoken)
Compensation Range:

The compensation range disclosed may encompass multiple title levels (Scope internal levels of seniority). Your actual compensation will depend on a variety of factors, including but not limited to your individual experience, education, and seniority, and the final salary will be determined during the interview and evaluation process.

Associate Director - ICT Risk Management: 210,000.00 - 290,000.00 PLN

Bonus: Discretionary

Benefits: Scope offers an extensive range of benefits, please check our benefits page for more details.

About Scope

With more than 250 employees operating from offices in Berlin, Frankfurt, London, Madrid, Milan, Oslo and Paris, Scope Group is the leading European provider of independent credit ratings, ESG and fund analysis. Based on forward-looking and innovative methodologies, Scope offers a European perspective that contributes to greater diversity of opinion for institutional investors worldwide. Scope Ratings is the largest European credit rating agency, registered in accordance with EU and UK rating agency regulation, offering opinion-driven and non-mechanistic credit risk analysis. Scope ESG Analysis provides tools for analysing and reporting on ESG impact and risk, as well as second-party opinions on green, social and sustainable bonds. Scope Fund Analysis rates more than 10,000 funds and asset managers across all major asset classes.

We embrace people from all backgrounds, regardless of culture, ethnicity and gender. We ensure that our application processes are free from discrimination. By valuing each individual's unique background and perspectives, we strive to create an environment where all employees can thrive and contribute their best. Our dedication to equality and inclusivity reflects our belief that diversity drives innovation and success.

For non-EU applicants, a valid work and residence permit is a prerequisite for this job position. Unfortunately, we are unable to sponsor relocation from outside of the EU at this time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Director - ICT Risk Management
Associate Director - ICT Risk Management

Scope Ratings • Poznań

On-site
PLN 220,000 - 320,000
Benefits package
Infrastructure & Enterprise Applications Engineer
Infrastructure & Enterprise Applications Engineer

Scope Ratings GmbH • Poznań

On-site
PLN 248,000 - 384,000
Sales Support & Process Digitalisation Specialist
Sales Support & Process Digitalisation Specialist

Scope Ratings • Poznań

On-site
PLN 92,000 - 135,000
Discretionary bonus
Comprehensive benefits
Risk Manager
Risk Manager

Banking Circle • Warszawa

Hybrid
PLN 240,000 - 360,000
Cyber / Tech 2nd LOD Senior Lead Analyst, Senior Vice President
Cyber / Tech 2nd LOD Senior Lead Analyst, Senior Vice President

Citigroup • Warszawa

Hybrid
PLN 341,000 - 581,000
6% pension contribution
Private medical care
Life insurance
+2
Risk Reporting Senior Manager
Risk Reporting Senior Manager

Citigroup Inc. • Warszawa

On-site
PLN 341,000 - 581,000
Pension Plan 6% PPE Program
Private Medical Care for employees and
Life Insurance for employees
+4
Credit Portfolio Analyst II
Credit Portfolio Analyst II

Citigroup Inc. • Warszawa

Hybrid
PLN 86,000 - 136,000
Pension plan
Private medical care
Life insurance
+3
Regulatory Capital Risk Senior Analyst
Regulatory Capital Risk Senior Analyst

Citigroup Inc. • Warszawa

On-site
PLN 165,000 - 281,000
Pension Plan 6%
Private Medical Care
Life Insurance
+5
Director, Non Financial Risk
Director, Non Financial Risk

LSEG • Gdynia

On-site
PLN 291,000 - 484,000
Manager, Business Risks & Controls, Workflows
Manager, Business Risks & Controls, Workflows

London Stock Exchange Group • Polska

On-site
PLN 178,000 - 281,000