This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
A proactive and highly analytical IT Risk SME to join our client’s IT Control team in Amsterdam. In this role, you will serve as a domain expert guiding internal and external IT audits, ensuring the timely completion of evidence requests, and driving risk mitigation across a global IT landscape. This is a key 1LoD Control role where you will actively improve IT Audit processes and the IT Risk & Control (R&C) Framework.
Job Responsibility
Provide 1LoD IT Audit guidance within the IT Control & Service Management team across all aspects of the global IT landscape
Organize, control, and monitor progress on follow-ups for audit assessments and questionnaires
Document IT Audit and questionnaire handling processes to ensure business continuity
Maintain, monitor, and continuously improve the IT R&C Framework
Prepare, coordinate, execute, and document 1LoD workshops and supporting evidence to resolve OSI findings
Liaise between the IT Center of Excellence, IT teams across regions (NL, US, AP), suppliers, and 2LoD Risk Management
Execute risk assessments, analyze compliance data, and present results and mitigating strategies to senior management
Educate global employees on IT Risk management best practices
Review/revise IT procedures
Align multi-regional stakeholders on standardized risk initiatives
Requirements
7+ years of professional experience working in a complex IT, Risk, or Compliance environment
Minimum of 5 years of dedicated IT Risk experience, collaborating closely with both internal and external IT Risk & Control/Audit teams
Proven experience working within a regulated, financial, or highly structured IT industry
Hands-on knowledge of the Audit Lifecycle and frameworks like ITIL, COBIT, and NIST (NIST experience is highly preferred)
Education: Bachelor’s or Master’s degree (or equivalent professional level) in IT, Information Security, or a related field
Mandatory Certification (at least one of the following is required): CISA (Certified Information Systems Auditor)
RE (Register EDP-Auditor)
ISO 27001 Lead Auditor
CRISC or CGEIT
Preferred Certifications: CISM or CISSP
Soft Skills: A self-starter mindset
you naturally take the lead and stay "in the driver’s seat" without waiting for direction
Communication: Excellent written and verbal English communication skills, with a proven ability to present and advise senior stakeholders and management
Attention to Detail: Exceptional documentation skills