We are looking for an experienced IT Risk Analyst to join a strategic IT Risk Management team within the financial services sector. The ideal candidate has a strong background in IT Risk, IT Governance, Cybersecurity, and Operational Risk, with experience assessing technology risks, supporting governance frameworks, and working closely with business and IT stakeholders to ensure regulatory compliance and risk mitigation.
The successful candidate will be comfortable working across multiple stakeholders, producing risk assessments and reports, monitoring remediation plans, and contributing to the continuous improvement of IT Risk processes.
Professional Experience & Main Tasks
- Proven experience in IT Risk Management, IT Audit, or IT Security.
- Identify and assess IT risks related to applications, infrastructure, projects, and production environments.
- Perform IT risk assessments and define appropriate mitigation and remediation plans.
- Monitor and coordinate remediation activities while ensuring compliance with the organization's IT Risk framework.
- Maintain and update IT risks within Governance, Risk & Compliance (GRC) tools.
- Assess operational risks related to production incidents and project-related issues.
- Analyse operational risk information, including Risk & Control Self-Assessments (RCSA), incident management, control plans, and risk profiles.
- Produce IT Risk dashboards, reports, KPIs, and management presentations.
- Support Internal Control and Risk Committees through reporting and risk analysis.
- Contribute to the maintenance of IT Risk policies, procedures, and governance processes.
- Collaborate with Business, IT, Security, Compliance, Legal, Data Governance, Vendor Management, and other key stakeholders.
- Support the use and adoption of collaboration tools such as SharePoint and Microsoft Teams.
- Strong knowledge of IT Risk Management frameworks and methodologies.
- Good understanding of Information Systems within the banking or financial services industry.
- Knowledge of Cybersecurity, Information Security, and Fraud Risk.
- Understanding of Data Governance and Data Protection principles.
- Familiarity with Software Development Life Cycle (SDLC) processes.
- Experience with Governance, Risk & Compliance (GRC) platforms, preferably ServiceNow GRC.
- Strong analytical and data analysis skills.
- Excellent stakeholder management and communication skills.
- Ability to work autonomously and manage multiple priorities.
- High attention to detail, integrity, and confidentiality.
- Knowledge of regulatory requirements and risk management best practices.
- Project Management experience is considered an advantage.
- IT Risk certifications (e.g., CRISC, ISO 31000, or equivalent) are a plus.
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- Approximately 10–15 years of professional experience in IT Risk Management, IT Audit, IT Security, or related areas.
- Previous experience in the banking or financial services sector is highly valued.