Senior IT Risk Specialist
Brak informacji o wynagrodzeniu
SeniorFull-time
#423275·Dodano 19 dni temu·0
Źródło: NexiTech Stack / Keywords
NetworkITILCybersecurityAIPRINCE2
Firma i stanowisko
Nexi is an international company with over 10,000 employees across 25 countries, operating in the digital payments industry. The role is based in Kraków, Poland, within a larger Risk Management & Regulatory Compliance department, with a network across Europe to share knowledge and experiences.
Wymagania
- Familiarity with industry standard IT standards and frameworks such as IRAM2, COBIT, ITIL, and ISO27001.
- Strong understanding of regulatory requirements and standards including EBA, DORA, GDPR, ISO 27001/27002, NIST, PSD2, ISO 22301, and NIS2 related to IT risk management and cybersecurity.
- Self-driven with the ability to take full ownership of responsibilities and proactively address challenges.
- Strong interpersonal, communication, and presentation skills for interaction across all organizational levels.
- A passion for continuous learning and professional growth.
- Ability to foster a respectful and culturally aware work environment.
- Knowledge of financial services and payment processing industries is a plus.
- Curiosity and experience in designing or applying emerging technologies such as AI agents and automation solutions to improve IT risk processes.
- Degree in Engineering, Computer Science, Information Systems, or related field; advanced degrees or certifications like CISSP, CISM, CRISC, CISA, PRINCE2, PMP are preferred.
- At least 10 years of experience in IT risk management, cybersecurity, IT audit, or related fields.
- Excellent command of spoken and written English.
Obowiązki
- Work with cross-functional teams and the first line of defence to identify, assess, and support mitigation of IT risks across critical services, new products, and projects, ensuring alignment with internal policies.
- Provide second line oversight, delivering independent review and challenge of IT risk assessments to ensure compliance with frameworks, regulatory requirements, and industry standards.
- Respond to internal control inquiries, track remediation efforts to resolution, and support the design and effectiveness of IT controls.
- Conduct IT Project Risk Assessments (ITPRA) for strategic, high-criticality, or complex projects, including scenario definition, risk identification, impact assessment, and evaluation of project risk exposure.
- Recommend mitigation actions for unacceptable risks based on the methodology's risk acceptance criteria.
- Participate in ongoing risk monitoring meetings to continuously assess emerging risks, evolving complexities, and project dependencies during project execution.
- Prepare and maintain risk reports using standard templates such as risk scenarios, heatmaps, and risk registers.
Benefity
- Attractive salary and a competitive overall package.
- Well-structured job training and continuous managerial support.
- Hybrid working model with flexibility in working hours and location.
- Provided equipment including laptop and mobile phone with monthly subscription.
Elastyczne godziny
Telefon
Nexi
4 aktywne oferty