ICT Risk Governance & Oversight - Assistant Vice President
182k PLN182 004 PLN/ rok.UoP
MidFull-time·Umowa o pracę
#435317·Dodano 19 dni temu·2
Źródło: State StreetTech Stack / Keywords
DORAICT Risk ManagementCybersecurityOperational ResilienceEBA ICTCRISCCISACISMCISSPISO 27001
Firma i stanowisko
State Street is a global financial services company serving institutional investors, focusing on risk management, operational resilience, and regulatory compliance.
Wymagania
- 4-8 years of experience in ICT Risk Management, Operational Risk Management, Information Security Risk, Operational Resilience, Technology Controls, Internal or External Audit, or Regulatory Risk Management.
- Experience in financial services or another highly regulated industry preferred.
- Bachelor’s or Master’s degree in Risk Management, Information Technology, Information Security, Finance, Business Administration, or related discipline.
- Strong analytical and risk assessment skills with ability to interpret regulatory requirements.
- Good understanding of DORA, ICT risk management, cybersecurity risk, operational resilience, and outsourcing/third-party ICT risk frameworks.
- Understanding of risk management principles within the Three Lines of Defense model.
- Ability to provide effective second-line challenge based on evidence and sound judgement.
- Excellent written and verbal communication skills, with strong stakeholder management and influencing capabilities.
- Awareness of EBA ICT and security risk management guidelines and outsourcing expectations.
- Professional certifications such as CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor or Lead Implementer, CIA, RIMS-CRMP, FRM or equivalent preferred; demonstrated experience may substitute formal certification.
Obowiązki
- Support the maintenance and continuous enhancement of the SSBI ICT Risk Management Framework to ensure alignment with DORA and operational resilience requirements.
- Prepare materials and perform analysis for ICT governance committees, management forums, and senior management reporting.
- Conduct independent review and challenge of ICT risk assessments, control evaluations, risk acceptance decisions, and supporting evidence.
- Escalate emerging ICT risk concerns, weaknesses, and thematic observations to ICT Risk Manager and ORM leadership.
- Support development, maintenance, monitoring, and reporting of ICT risk appetite metrics, thresholds, and Key Risk Indicators.
- Produce risk reporting, trend analysis, and management information for senior stakeholders.
- Support oversight and challenge of ICT control testing, resilience testing, scenario testing, and threat-led testing outputs.
- Review management responses and remediation actions related to ICT incidents, testing exercises, and technology-related operational events.
- Support second-line oversight activities on ICT third-party and outsourcing risk.
- Assist in monitoring regulatory developments related to DORA, ICT risk, cybersecurity, and operational resilience.
- Contribute to broader SSBI Operational Risk Management activities including LERA, RCSA, SAOR, TRA, new business reviews, outsourcing oversight, regulatory and audit engagements, policy development, and risk committee reporting.
Benefity
- Permanent contract from day one.
- Additional holidays including Birthday Day Off and anniversary days off.
- Gold Medical Package for employees and their families.
- Premium life insurance package and private pension plan.
- Variety of soft skills training, technical workshops, language classes, and development programs.
- Opportunities to volunteer for company initiatives and employee networks.
- Variety of well-being programs.
- Additional benefits depending on role seniority.
Płatne święta
Opieka zdrowotna
Ubezpieczenie
Dofinansowanie szkoleń
Kursy językowe
Płatny urlop
Inne informacje
The role requires a minimum of 3 days per week working from the office.
State Street
71 aktywnych ofert