Senior Information Risk Specialist @ING Hubs Romania
Bucharest - Dacia One, Romania
โ ๏ธ We'll shut down after Aug 1st - try foo๐ฆ for all jobs in tech โ ๏ธ
ING Hubs Romania offers 130 services in software development, data management, non-financial risk & compliance, audit, and retail operations to 24 ING units worldwide, with the help of ๐จ๐ฏ๐๐ซ ๐๐๐๐ ๐ก๐ข๐ ๐ก-๐ฉ๐๐ซ๐๐จ๐ซ๐ฆ๐ข๐ง๐ ๐๐ง๐ ๐ข๐ง๐๐๐ซ๐ฌ, ๐ซ๐ข๐ฌ๐ค, ๐๐ง๐ ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง๐ฌ ๐ฉ๐ซ๐จ๐๐๐ฌ๐ฌ๐ข๐จ๐ง๐๐ฅ๐ฌ.
We started out in 2015 as INGโs software development hub, then steadily expanded our range to include more services and competencies. Now we provide borderless services with bank-wide capabilities and ๐จ๐ฉ๐๐ซ๐๐ญ๐ ๐๐ซ๐จ๐ฆ ๐ญ๐ฐ๐จ ๐ฅ๐จ๐๐๐ญ๐ข๐จ๐ง๐ฌ: ๐๐ฎ๐๐ก๐๐ซ๐๐ฌ๐ญ ๐๐ง๐ ๐๐ฅ๐ฎ๐ฃ-๐๐๐ฉ๐จ๐๐.
๐๐ฎ๐ซ ๐ญ๐๐๐ก ๐๐๐ฉ๐๐๐ข๐ฅ๐ข๐ญ๐ข๐๐ฌ ๐ซ๐๐ฆ๐๐ข๐ง ๐ญ๐ก๐ ๐๐จ๐ซ๐ ๐จ๐ ๐จ๐ฎ๐ซ ๐๐ฎ๐ฌ๐ข๐ง๐๐ฌ๐ฌ, with more than 1800 colleagues active in Data Management, Touchpoint Channels & Integration, Core Banking, and Global Products.
We enjoy a flexible way of working and a highly collaborative environment, where fair and constructive feedback is encouraged.
For us, impact isn't a perk. It's the driver of our work. We are guided and rewarded by a shared desire to make the world a better place, one innovative solution at a time. Our colleagues make it their job to do impactful things and they love doing it in good company. Do you?
The Mission
The NFR Specialist IV (Information Risk Management Officer) is a 2nd line of defence (2LoD) independent role, is an expert in Information Risk and Operational Resilience & Business Continuity Management (ORBC) and shall provide expertise review, challenge and advice to ING Hubs Romania.
You will provide expert advice within the organization, on, but not limited to external/ internal events, risk identification & assessment, risk mitigation & tracking, risk reporting, you will perform regular review and challenge on IT & ORBC control implementation and ensure monitoring of the related issues.
Your day-to-day
- Participate in and challenge risk assessments (including Business Impact Assessment and IT Asset Risk Assessment);
- Communicate, provide interpretation & training for IT Risk tooling and IT Risk Policies, Minimum Standards, Procedures, Methods and Techniques;
- Perform 2nd line IT Risk and Operational Resilience & Business Continuity Management review and challenge of related controls implementation;
- Perform 2nd line IT Risk monitoring of IT and ORBC issues;
- Participate in, challenge and periodically report upon the risks ofย key strategic (IT/ ORBC) programs and projects;
- Measure and report on the implementation of Information (Technology) or Continuity Risk frameworks throughout the organization;
- Support the identification of the impact of and the coordination of responses to law and regulatory changes, internal & external audit reports, etc. and monitoring the follow-up on the regulatory issue solving;
- Be a trusted IRM/ORBC advisor towards 1stย line of defense management and other Non-Financial Risk specialists;
- Raise, review & challenge opening or review for closure of risk remediation actions for IT Risk of Continuity Risk gaps identified;
- Participate and contribute to IT controls & ORBC controls deep-dive or thematic reviews;
- Contribute to the development and maintenance of a risk awareness curriculum and training program, and deliver risk awareness trainings to the organization;
- Perform and assist in other information risk activities where the requirements arise.
What we are looking for
- University Degree, preferably IT field;
- 5-7 yearsโ experience in Information Security/IT Security/Technology Risk/IT Audit;
- Knowledge of and experience with IT Risk Assessments, IT Control Assessments or IT Audit assignments;
- Familiarity with Information Security and Technology Risk / Cyber Security Standards and Regulations (such as NIST, COBIT, ITIL);
- Exposure to & understanding technical & business-related threats facing banking industry. Ability to identify and pursue solutions to manage IT risks;
- Collaboration skills and ability to work across both functional and geographical lines;
- Pro-activeness and persuasiveness;
- Ability to demonstrate critical thinking and discuss findings, recommendations with senior management;
- Good analytical skills and sound judgement;
- Fluent in English (written and spoken);
Would be considered a plus
- Having professional education and training in Information Security and Technology Risk (e.g., ISC2, CISSP);
- Knowledgeable of Banking business, processes, procedures and systems and associated laws and regulations.
If you want to deep dive into the processing of personal data conducted by ING Hubs Romania during the recruitment process and your rights related to it, read theย privacy noticesย on ourย websiteย (make sure to scroll until you reach the Data Protection section/ Candidates tab)
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index ๐ฐ
Tags: Audits Banking CISSP COBIT Compliance ITIL Monitoring NIST Privacy Risk assessment Risk management
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.