ICT Risk Analyst
Capco Visualizza tutti gli annunci
- Milano
- Tempo indeterminato
- Full time
- Support the development and maintenance of the ICT and Cyber Risk Management framework, ensuring alignment with regulatory requirements and industry standards
- Contribute to the identification, assessment, and monitoring of ICT and cyber risks across systems and processes
- Perform ICT risk assessments, including RCSA and scenario analysis
- Define, monitor, and report KRIs, KPIs, and other ICT risk metrics
- Support second line of defense activities within the ERM framework, focusing on ICT risk exposure monitoring
- Contribute to the ICT Risk Appetite Framework, including thresholds, limits, and escalation mechanisms
- Analyze ICT vulnerabilities and ensure tracking of mitigation and remediation action
- Prepare dashboards, heatmaps, and reports to provide visibility on ICT risk to stakeholders
- Support the definition and update of ICT and cyber risk policies, standards, and guidelines
- Collaborate with IT and Cybersecurity teams on risk monitoring, incident analysis, and response
- Bachelor's degree in scientific, engineering, economic or IT-related fields
- 2-5 years of experience in ICT Risk, Cyber Risk, Operational Risk or Risk & Regulatory environments
- Knowledge of ICT Risk Management frameworks (e.g. ISO 31000, NIST, ISO 27005 or similar)
- Understanding of core ICT technologies and cybersecurity domains
- Experience in defining risk indicators, metrics and reporting
- Strong analytical skills and ability to synthesize risk data
- Proficiency in Microsoft Office 365 tools
- Strong communication skills and ability to work with cross-functional stakeholders
- Knowledge of Digital Operational Resilience Act (DORA) and operational resilience topics
- Experience with data analytics and dashboarding tools (e.g. Power BI)
- Relevant certifications (e.g. CRISC, CISA, CISM, ISO 27001)
- A work culture focused on innovation and building lasting value for our clients and employees
- Ongoing learning opportunities to help you acquire new skills or deepen existing expertise
- A flat, non-hierarchical structure that will enable you to work with senior partners and directly with clients
- A diverse, inclusive, meritocratic culture