Welcome to the team: Head of GRM CRIS Information Security Prague (m/f/diverse)

-
FunctionFunction:
Information Technology -
LocationLocation:
Praha
GRM CRIS Information Security acts as second line of defense for ICT risks (Information & Communication Technology Risks) and does own the ICT Policy & Control Framework as a standard setter. Furthermore, CRIS IS managing the Governance Risk & Compliance (GRC) processes to assess ICT impacts, compliance and analyze associated ICT risks to be managed. In addition risk based control testing is performed to verify 1LoD adherence to ICT requirements.
We are now establishing a new team in Prague and looking for an experienced manager to lead the ramp up of this team supporting our 2LoD ICT GRC risk management duties. Your experience in Information Security, Cyber Security and IT Risk Management will be crucial to establish a strong 2LoD ICT GRC risk management function in Prague adhering to regulatory requirements e.g. Digital Operational Resilience Act (DORA).
Your tasks
- Maintain and continuously develop the ICT Policy & Control Framework (ISPF/ISCF) as a standard setter and 2nd LoD.
- Oversee completeness and effectiveness of the ICT control structure of the cyber & Information security and IT-risk based on continuous auditing of the 1st LoD controls using the 2nd LoD control framework and the implementation of 2nd LoD audits.
- Manage the Governance Risk & Compliance (GRC) processes to assess ICT impacts, compliance and analyze associated ICT risks to be managed.
- Conceptual support of the 1st LoD in the definition and planning of ICT controls and measures for the implementation of ICT requirements.
Your profile
- Master or at least bachelor’s degree in computer science or related field.
- At least 7 years’ experience in Information Security and 3 years’ leadership experience.
- Profound Information Security and Risk Management knowledge including regulatory requirements ideally in the financial sector
- Excellent communication skills in English written and spoken. German skills are a plus.
- Strong problem solving and analytical skills, be able to work in the complex and the fast-changing banking environment.
- Personal certificates e.g., CISM, CRISC, CISSP, or ISO 27000 Lead Auditor are a plus.
Our Benefits
30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance
The company
Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in the area of IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create positive impact in the banking world.
Contact
In case of interest please apply via this jobportal.