General duties
ICT Risk Governance
- Develop, maintain and continuously improve the ICT Risk Management and Third-Party Risk Management frameworks, policies, procedures and methodologies.
- Support the effective implementation of ICT Risk Management requirements across the Bank.
- Prepare reporting for senior management and relevant governance bodies.
- Support communication and regulatory reporting to competent authorities, regulators and supervisors on ICT and Third-Party Risk Management matters.
ICT Risk Assessment & Control Assurance
- Coordinate ICT risk assessments covering technology, applications, infrastructure, information assets, services and ICT processes.
- Challenge the identification, assessment and treatment of ICT risks performed by First Line functions.
- Develop and maintain an ICT control testing and assurance approach.
- Perform independent Second Line assessments of the design and operating effectiveness of ICT controls.
- Track the remediation of ICT risk and control deficiencies and provide independent assurance over their closure.
Third-Party and ICT Supplier Risk Management
- Coordinate third-party risk assessments, including assessments of ICT services supporting critical or important functions.
- Challenge risk assessments, due diligence, contractual risk mitigation measures and exit strategies.
- Oversee the effective implementation of third-party service management requirements.
- Aggregate, analyse and report third-party monitoring data and key risk information to senior management and relevant governance bodies.
Requirements
- Experience in ICT Risk Governance, IT and Third-Party Risk Management, Technology Risk, IT Audit, Information Security Governance, Internal Control or a related field.
- Understanding of IT infrastructure, applications, technology services and associated risks.
- Practical experience in risk assessments and control testing or assurance.
- Good understanding of DORA, EBA and ECB expectations and ICT risk management principles, with the ability to translate them into internal policies, procedures and methodologies.
- Ability to analyse complex technology, regulatory and non-financial risk topics and translate them into clear risk conclusions for senior stakeholders.
- Strong communication and stakeholder-management skills, including the ability to challenge experienced IT and business professionals constructively.
- Structured, analytical and independent approach to work.
- Professional certification such as CISA, CRISC, CISM, CISSP or equivalent would be an advantage.
DSK Bank offers
- Competitive multi-component remuneration and attractive bonus scheme;
- An additional 102,26 euro per month is provided in the form of food vouchers;
- 20+5 days paid leave;
- Additional Health Insurance;
- Promo price for Multisport Cards;
- Perfect opportunities for professional and career development in a leading Bank in Bulgaria;
- Professional training for specific knowledge and skills;
- Unique banking service package - special loan interest for employees on housing and consumer loans;
- Top technologies to use;
- Discount program with external vendors;
- Great working environment within a team of professionals.
Documents for application
CV