
Senior Information Risk Specialist @ING Hubs Romania
- București
- Permanent
- Full-time
- Participate in and challenge risk assessments (including Business Impact Assessment and IT Asset Risk Assessment);
- Communicate, provide interpretation & training for IT Risk tooling and IT Risk Policies, Minimum Standards, Procedures, Methods and Techniques;
- Perform 2nd line IT Risk and Operational Resilience & Business Continuity Management review and challenge of related controls implementation;
- Perform 2nd line IT Risk monitoring of IT and ORBC issues;
- Participate in, challenge and periodically report upon the risks of key strategic (IT/ ORBC) programs and projects;
- Measure and report on the implementation of Information (Technology) or Continuity Risk frameworks throughout the organization;
- Support the identification of the impact of and the coordination of responses to law and regulatory changes, internal & external audit reports, etc. and monitoring the follow-up on the regulatory issue solving;
- Be a trusted IRM/ORBC advisor towards 1st line of defense management and other Non-Financial Risk specialists;
- Raise, review & challenge opening or review for closure of risk remediation actions for IT Risk of Continuity Risk gaps identified;
- Participate and contribute to IT controls & ORBC controls deep-dive or thematic reviews;
- Contribute to the development and maintenance of a risk awareness curriculum and training program, and deliver risk awareness trainings to the organization;
- Perform and assist in other information risk activities where the requirements arise.
- University Degree, preferably IT field;
- 5-7 years’ experience in Information Security/IT Security/Technology Risk/IT Audit;
- Knowledge of and experience with IT Risk Assessments, IT Control Assessments or IT Audit assignments;
- Familiarity with Information Security and Technology Risk / Cyber Security Standards and Regulations (such as NIST, COBIT, ITIL);
- Exposure to & understanding technical & business-related threats facing banking industry. Ability to identify and pursue solutions to manage IT risks;
- Collaboration skills and ability to work across both functional and geographical lines;
- Pro-activeness and persuasiveness;
- Ability to demonstrate critical thinking and discuss findings, recommendations with senior management;
- Good analytical skills and sound judgement;
- Fluent in English (written and spoken);
- Having professional education and training in Information Security and Technology Risk (e.g., ISC2, CISSP);
- Knowledgeable of Banking business, processes, procedures and systems and associated laws and regulations.