Skip to main content
Enregistré

IT Risk Engineer



Apply now

Job Overview

You will help on risk subjects like:        

  • Act as a central SPOC for all incoming IT risk assessments and control evidencing requirements adhering the established control framework, SOx requirements and industry best practices.
  • Monitoring, tracking and managing deviations to established IT Risk controls.
  • Mediating between 1st LOD/2nd LOD and DevOps teams.
  • Conducting walkthroughs with auditors to review and validate IT Risk control processes.
  • Lead technical due diligence sessions with third party vendors.

You will work in an agile environment, following Scrum methodology together with DevOps squads, helping to maintain a safe and secure application.

Key Responsibilities

Your primary mission is to help the squads to implement IT Controls and to prove the controls are implemented effectively:

  • ensure we are in control of our risk appetite
  • define and document adequate risk processes and collect the evidences in regards; make sure that the different risk parties agree with the evidences
  • responsible for creating documents and project management requirements or specifications
  • provide documentation support to the technical team; interface with developers and operation engineers to define the specifications
  • liaison between the team and other IT Risk professionals
  • understand the need for security and apply it using the existing framework; constant communication about changes
  • participate in automation program for process and evidence for IT risk
  • show proactivity and flexibility, come up with plans of action and adapt approaches if necessary
  • understand the corporate climate and culture and act as an ambassador; IT custodianship/asset owner role.

Key Capabilities and Experience

Capabilities:

Mandatory:

Ability to understand the risk processes in an IT environmentExperience with IT risk standardsAbility to make clear and convincing statements related to risk proceduresProven planning and organizing experience

Nice to have:

Project management experience. Ability to track, plan and coordinate projects related to third party risk management,  technical compliance, and/or IT risk automation.Experience in working with Dev(Sec)Ops teams across vulnerability management, threat hunting, security detection and response and developing, or contributing to information security policies and procedures.3.Knowledge of Agile methodology

Education: nice to have Bachelor’s Degree (or higher) in an IT related field.

Experience:

Degree and/or experience in IT risk management, cybersecurity, or related field.

Understanding of fundamental IT risk and security concepts and ability to think critically across technical control domains.

Knowledge of IT control frameworks (eg. SOX, GDPR, CSA CCM) and industry standards (eg. ISO2700x, NIST).

Proven track record of conducting IT control evidencing, qualitative risk assessments and developing mitigation strategies.

Risk reporting and communication:

•           ability to communicate risk-related concepts to technical stakeholders.

•           experience in liaising with second line risk functions.

•           strong written and verbal communications skills in English.

Certifications such as CISSP, CISM, CRISC or equivalent are a plus.

Apply now

Questions? Just ask
ING Recruitment team

Apply now

Chez ING, nous voulons libérer tout le potential de nos collaborateurs, grâce notamment à une culture inclusive où tout le monde peut se développer et avoir un impact sur nos clients et sur la société. Nous veillons à ce que la diversité, l'équité et l'inclusion soient prioritaires. En tant qu'employeur souscrivant au principe de l'égalité des chances, nous ne tolérons aucune forme de discrimination, qu’elle soit liée à l'âge, au sexe, à l'identité sexuelle, à l'origine culturelle, à l'expérience, à la religion, à la race, à l'origine ethnique, au handicap, aux responsabilités familiales, à l'orientation sexuelle, à l'origine sociale ou à tout autre statut protégé par la législation. Si vous avez besoin d'aide lors du processus de candidature et/ou d'entretien, veuillez contacter le (la) recruteur(se) du poste concerné. Nous serons heureux de vous accompagner pour garantir un processus équitable et accessible. Apprenez-en plus sur notre engagement en faveur de la diversité, de l’inclusion et de l’appartenance.

Plus pour vous

Rejoindre notre Talent Community

Interessé(e) parSaisissez les premières lettres d'une catégorie puis choisissez parmi les suggestions. Saisissez ensuite les premières lettres d'un lieu puis choisissez parmi les suggestions. Enfin, cliquez sur "Ajouter" pour créer votre alerte.

By submitting your information, you acknowledge that you have read our privacy policy and consent to receive email communication from ING.