As a Technology and Cybersecurity Operational Risk Manager within the Tech & Cyber ORM Team, you will be familiar with Operational Risk Management processes and measuring Operational Risk. You will play a critical role in key initiatives, oversight of programs and regulatory dialogue. You will use experience and leadership skills to give guidance and best practice advice across the Cybersecurity discipline. The role requires confident self-starters who can understand program objectives, understand mitigating cybersecurity controls using an analytical approach to independently assess the control environment.
Job responsibilities:
- Test & Monitor - Perform oversight of operational risks through targeted tests of global and regional technology/ cyber security processes and controls
- Asses the IT Risk Profile, KRIs, Loss Data, CORE and Scenario Analysis, as well as, liaise with EU regulators in respect of Operational Risk matters
- Review of material internal events, including but not limited to, examination of event and resolution, back-testing against Operational Risk and Control Assessment results, metrics, escalations, reporting, and scenarios
- Participate in assessment of emerging risks as part of strategic business risk reviews, analysis of regulatory and market developments, New Business Initiative Approvals and review of external operational risk events
- Stay abreast of new technologies and regulatory developments to facilitate a proactive approach to risk identification and mitigation
Required qualifications, capabilities and skills:
- 5+ years of proven experience in cybersecurity / with roles involving technology risk oversight combined with financial services experience
- Working knowledge and interest of current and emerging technologies
- Ability to understand complex technical systems and the business processes they support and synthesize the corresponding risks and controls and recommend adjustments if required
- Knowledge of Cyber and technology controls, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies
- Ability to collaborate and establish relationships across organizations and employee levels, including senior leaders and regulators, with the confidence to formulate, advocate and drive ideas forward
- Ability to work with limited supervision and manage multiple tasks while exceling in a dynamic, demanding environment
- Strong communication skills, both verbal and written and attention to detail required
- Working knowledge of English and at least another European Language such as German or French
- EU and German Technology regulations knowledge is a pre-requisite (e.g. DORA, CBI, BaFin, CSSF, EBA Guidelines)