This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
A professional specialized in identifying, assessing, and mitigating risks associated with information technology systems and infrastructure. Based in Amsterdam, you will join the IT Control & Service Management team. Your mission is to help manage and reduce the organization’s information risks through continuous management and reporting related to the IT Risk & Control (R&C) Framework.
Job Responsibility:
Act as a domain expert for IT audit evidence requests and action items
Collaborate closely with IT Risk SMEs globally (NL, AP, and US regions), 2LoD Risk Management, and external suppliers
Manage, maintain, and monitor the IT R&C Framework on a continuous basis
Contribute to solving IT Risk-related OSI findings, specifically focusing on framework and RSA process improvements
Prepare, coordinate, and execute 1LoD workshops and document supporting evidence
Execute various risk assessments, analyze data, and present results/conclusions to senior management
Research deviations and advise on risk-mitigating actions and the development of new standards
Provide 1LoD IT Risk guidance across all aspects of the IT landscape, including Client and Third-Party questionnaires
Educate employees on IT Risk management best practices and review/revise IT procedures
Requirements:
Bachelor’s or Master’s degree (or equivalent degree/experience)
Minimum of 5 to 7 years of IT Risk experience, working with both internal and external IT Risk & Control and Audit teams
Must hold at least one of the following: CISM, CISA, CISSP, CRISC, or CGEIT
Deep understanding of NIST, COBIT, and ITIL frameworks (NIST experience is highly preferred)
Familiarity with IT best practices within the financial services industry
Taking the lead without waiting for direction – coupled with excellent oral and written communication skills
Ability to effectively communicate with all levels of the organization, including senior management
Nice to have:
Preferred Certification: Cloud Audit Academy (AWS), Cybersecurity Practical Applications, Certificate of Cloud Auditing (ISACA), or CIA (IIA)
Familiarity with Atlassian products (Jira, Confluence), AGRC, and/or ServiceNow is considered a plus