
ICT & Security Risk Manager
- Milano
- Tempo indeterminato
- Full time
- Updating policies, methodologies, and processes for managing ICT and Security risks;
- Contributing to the definition of the Summary Report on the ICT and Security Risk situation;
- Continuously monitoring exposure to cyber risk, also through the ongoing evolution of the set of KRIs;
- Ensuring the effective integration of the measurement of the ICT and Security risk profile into the Bank's Risk Appetite Framework;
- Assessing the ICT and Security risk profile of Third Parties, as well as the risks related to ICT projects;
- Supporting first-level functions in identifying controls in the face of any weaknesses found;
- Keeping constantly updated on the evolution of external regulations, international standards, and Group Policies;
- Participating in the incident management process to evaluate the severity of incidents and the effectiveness of the identified remediation plans;
- Managing internal reporting to corporate bodies and functions;
- Training and raising awareness among staff about the importance of information security and the practices to follow.
- A minimum of 5 years of experience in the banking sector, ideally within the risk management function (non-financial risks) or ICT/Security;
- In-depth knowledge of information security standards (e.g., DORA, ISO/IEC 27001);
- Knowledge of core banking systems;
- Ability to create presentations and draft documents;
- Project management skills;
- Fluent knowledge of the English language;
- Knowledge of GRC tools is a plus
- Data Analytic
- Knowledge of ChatGPT
- Determination, flexibility, and ability to work in a team