Senior IT Analyst – IT Risk, Security & Compliance (f/m)
Tech Stack / Keywords
Firma i stanowisko
The role is within a large financial organization requiring expertise in IT Risk & Audit, Compliance, IT Security, Infrastructure, and Project Management.
Wymagania
- Strong experience in IT Risk Management and end-to-end risk assessment processes.
- Expert knowledge of risk frameworks.
- Extensive experience in IT Audit, including designing and executing remediation plans.
- Experience collecting and documenting audit evidence and technical artefacts.
- Knowledge of regulatory compliance such as NIS2, DORA, FSA guidelines, and ECB requirements.
- Experience with large-scale, cross-organizational initiatives.
- Experience communicating risk and audit topics to senior management.
- Experience closing regulatory and internal audit findings is highly desirable.
- Expert knowledge of DNS, TCP/IP, and network architecture including cloud environments and internet-facing assets.
- Senior/expert knowledge of database security, including backup strategies, user management, authentication, version and patch management.
- Strong knowledge of vulnerability management, security testing, and scanning tools.
- Knowledge of security threat management, web-based threats, and mitigation strategies.
- Understanding of incident management, problem management, and CMDB systems.
- Senior-level knowledge of databases including Oracle, DB2, MSSQL, and PostgreSQL.
- Expert knowledge of IP/DNS systems, network architecture, cloud networking, and internet-based assets.
- Expert knowledge of SharePoint administration and development, including SharePoint Lists.
- Strong experience with Power Apps and Power Automate.
- Mid/senior level Python for data management and analytics.
- Experience in the banking or financial services sector.
- Knowledge of banking applications in transactions, corporate banking, asset management, and trading.
- Understanding of Business Continuity, Business Impact Analysis, and Business Analysis.
- Experience in project management including planning, stakeholder management, reporting, and communication.
- Strong organizational, planning, communication, negotiation, and delivery management skills.
Soft Skills:
- Strong organizational awareness and political sensitivity.
- Collaborative and proactive mindset.
- Ability to coach and upskill less experienced Risk/Audit professionals.
- Persuasiveness and strong negotiation skills.
- Trustworthiness and accountability.
- Ability to identify and advise on remediation of ineffective controls.
- Clear articulation of risks, process weaknesses, and control gaps.
- Strong analytical skills and proactive solution proposals.
- Openness to reconsider and adapt decisions.
Obowiązki
- Conduct IT risk assessments including identification, action planning, monitoring, and remediation.
- Design and coordinate audit remediation plans and audit closure strategies.
- Collect, prepare, and document evidence and technical artefacts for audit purposes.
- Support closure of complex internal and regulatory audit findings.
- Communicate risks, priorities, remediation plans, and outcomes to senior leadership and Risk & Control functions.
- Work with regulatory and compliance requirements including NIS2, DORA, FSA guidelines, and ECB requirements.
- Identify process and control weaknesses; recommend remediation actions.
- Assess and address network security, database security, vulnerability management, and threat management.
- Establish project plans, communication structures, and governance per industry-standard project management practices.
- Manage stakeholders, dependencies, risks, timelines, and expectations.
- Provide weekly reporting on progress, impediments, and identified risks.
- Proactively drive actions to deliver agreed results on time.
Inne informacje
Informujemy, że administratorem danych jest B2B.net S.A. z siedzibą w Lidzbarku, ul. Wielki Łęck 81A (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
B2Bnetwork
237 aktywnych ofert