We are looking for an experienced IT Risk Analyst to join an international team focused on strengthening IT Risk Management, Operational Risk, Governance, and Cybersecurity practices within a highly regulated environment.
This role offers the opportunity to work closely with technology, security, risk, compliance, and business stakeholders, contributing to the identification, assessment, monitoring, and mitigation of IT and Cyber risks across critical systems and projects.
Key Responsibilities
- Identify, assess, and manage IT risks related to systems, applications, projects, and production environments.
- Collaborate with Business, IT, Security, Architecture, Compliance, Legal, Data Governance, and Risk teams to ensure comprehensive risk assessments.
- Produce IT risk analyses, define remediation plans, and monitor mitigation activities.
- Maintain and update risks within Governance, Risk & Compliance (GRC) platforms.
- Monitor IT and Cyber risks through indicators, dashboards, and risk management processes.
- Assess operational risks associated with projects and production incidents.
- Evaluate potential financial, legal, regulatory, and compliance impacts resulting from incidents.
- Support Risk & Control Self-Assessments (RCSA), risk profiling, control plans, and incident management activities.
- Produce risk reports, dashboards, KPIs, and presentations for management and governance committees.
- Contribute to the development and maintenance of policies, procedures, and governance frameworks.
- Support reporting activities related to Internal Control, Risk, Security, and Continuity committees.
Required Skills & Experience
- Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field.
- 10+ years of experience in IT Risk Management, IT Audit, IT Security, Governance, Risk & Compliance, or related areas.
- Strong practical experience in IT Risk Management frameworks and methodologies.
- Good understanding of Information Systems within the Banking or Financial Services sector.
- Knowledge of Cybersecurity, Fraud Risk, Data Governance, and Data Protection principles.
- Familiarity with Software Development Life Cycle (SDLC) processes and methodologies.
- Strong analytical and problem-solving skills.
- Experience in risk reporting, KPI production, and executive-level communication.
- Experience with GRC platforms, preferably ServiceNow GRC.
- Excellent communication and stakeholder management skills.
- Fluent English, both written and spoken.
Nice to Have
- Previous experience in the Banking or Financial Services industry.
- Risk Management certifications such as CRISC, ISO 31000, or equivalent.
- Experience with regulatory and compliance frameworks.
- Background in IT Audit or Information Security.
- Experience producing executive dashboards, reporting, and committee presentations.
If you are looking for an opportunity where you can combine IT Risk Management, Cybersecurity, Governance, and Regulatory Compliance within a complex international environment, we'd love to hear from you.