We are growing. And we are looking for talented people.
At Decskill, we believe that technological excellence is driven by human talent.
We are an IT consulting company with more than 10 years of consolidated experience in the market, focused on building long-term relationships with both our clients and our people. Today, we are a community of over 800 professionals, working from Lisbon, Porto, and Madrid, contributing to impactful technology initiatives.
As part of the Astek Group, we combine a strong local culture with a global presence, being active in around 23 countries across 4 continents. This allows us to offer an international context, diverse challenges, and long-term career opportunities, while staying close to our teams.
We are looking for IT Risk Analyst!
Responsibilities:
- Implement and promote the organization's IT Risk Management framework.
- Identify and assess IT risks related to existing IT assets, projects, and production environments.
- Collaborate with cross-functional stakeholders, including Business, IT, Architecture, Security, Third-Party Risk, Data, Vendor Management, Risk, Legal, and Compliance teams.
- Perform IT risk assessments, define remediation plans, and monitor remediation activities.
- Record and maintain IT risks within the organization's Governance, Risk & Compliance (GRC) tool.
- Identify inherent IT and Cyber risks through monitoring activities and risk dashboards.
- Maintain the IT Risk Register and track mitigation actions to completion.
- Analyze and report on IT risk activities, including:
- Operational and historical incidents
- Control plans
- Produce IT risk reports, metrics, and Key Risk Indicators (KRIs).
Operational Risk & Incident Management
- Assess operational risks associated with production and project incidents.
- Evaluate financial, legal, regulatory, and compliance impacts of operational incidents.
- Record operational risk incidents in the risk management tool, ensuring complete and accurate risk analysis.
Reporting & Governance
- Deliver timely and accurate IT Key Risk Indicator (KRI) reporting to management.
- Prepare reports for Internal Control and Management Committees.
- Develop dashboards and presentations for senior management and IT Risk, Continuity, and Security Committees.
- Maintain IT risk policies and procedures in alignment with organizational governance standards.
- Support the use of collaboration platforms such as SharePoint and Microsoft Teams.
Requirements:
Education
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
Experience
- 10–15 years of relevant experience in one or more of the following areas:
- IT Audit
- IT Security
- Previous experience in IT Risk Management within the banking or financial services industry is preferred.
Technical Skills
- Strong knowledge of IT Risk Management frameworks and practices.
- Good understanding of Information Systems within the banking or financial services sector.
- Knowledge of Cybersecurity and Fraud Risk Management.
- Knowledge of Data Governance and Data Protection.
- Familiarity with the Software Development Life Cycle (SDLC) and related methodologies.
- Experience with Governance, Risk & Compliance (GRC) tools (e.g., ServiceNow GRC).
- Strong analytical and data analysis skills.
- Excellent written and verbal communication skills in English.
Certifications
- Professional Risk Management certification (e.g., CRISC, ISO 31000, or equivalent) is preferred.
Soft Skills
- High level of integrity and confidentiality.
- Understanding of regulatory requirements, industry standards, and emerging technologies.
- Strong interpersonal and stakeholder management skills.
- Ability to adapt to changing business priorities and management requests.
Are you looking for an environment that values curiosity and commitment? Here, your contribution has real impact and individual growth is taken seriously.
Find with us the right opportunity to grow!
What you can expect from us:
- Long-term projects with national and international context (if applicable)
- Opportunities to grow technically and professionally
- A people-first culture, focused on transparency and trust
- Teams that value ownership, collaboration and stability.
Thank you! :)
Decskill is committed to equality and non-discrimination with all our talents. We recruit and promote talent, based on diversity and inclusion, regardless of age, gender, ethnicity, race, nationality or any other form of discrimination incompatible with the dignity of the human being