Welcome to the team:
Department Head of Supply Chain Risk Management (m/f/diverse)

  • Function
    Function:
    Risk / Credit / Financing
  • Location
    Location:
    Praha

With our strategic upgrade, we are further developing the organizational structure and operating model within ICT Risk & Resilience Management with a clear focus on the future. Our goal is to embed regulatory requirements, enterprise-wide steering, and effective governance in a clear and high-performing target operating model.

As Department Head of Supply Chain Risk Management, you will take on a central leadership role in establishing and further developing the bank-wide steering framework for ICT-related third-party and supply chain risks. This requires developing and managing the dedicated ICT Supply Chain Risk Management function and connect it to the bank’s broader Third-Party-Risk-Management function and as well as the ICT-risk management functions with the goal of appropriately managing the ICT risks arising from the bank’s multiple third-party-relationships.  

If you are motivated to translate regulatory requirements into effective standards as well as assessment and steering processes for providers, outsourcing arrangements, and ICT supply chains, and to strategically steer their implementation, we look forward to receiving your application.

Your tasks

  • You will establish the Supply Chain Risk Management department and develop a high-performing team to steer ICT-related third-party and supply chain risks within the 2nd Line of Defence.
  • You will define methods, criteria, and processes for the risk assessment of ICT service providers, cloud providers, outsourcing arrangements, and critical software and infrastructure providers, among others.
  • You will define binding minimum ICT security, resilience, and incident management requirements for contracts, SLAs, and security schedules, and continuously enhance them.
  • You will assess concepts, contracts, and security requirements for new contracts, contract renewals, and material changes, and provide well-founded 2nd Line statements and recommendations for approval.
  • You will continuously monitor the risk profile of critical service providers, identify concentration risks within the supply chain, conduct third-party-audits and initiate escalations and/or establish additional controls where risks are not acceptable.
  • You will prepare the department’s results in a target group-oriented manner in English and, if possible, in German for management, governance committees, and relevant stakeholders.

Your Profile

  • You have successfully completed a degree in computer science/information technology, business informatics, business administration, or a comparable qualification.
  • You have 5 years of experience in third-party risk management, outsourcing management, ICT risk management, or comparable functions related to regulatory requirements and ICT service providers.
  • You bring sound knowledge of regulatory requirements in the context of DORA, outsourcing, cloud risks, and ICT supply chains, and you are able to translate them into practical steering approaches.
  • You have already gained experience in leading teams or projects as well as in steering demanding functional interfaces and stakeholder management.
  • You stand out through strong analytical thinking and the ability to assess and communicate risks, dependencies, and concentrations in a target group-oriented manner.
  • Communicating and documenting work results in English, and if possible in, German comes naturally to you.
  • You proactively drive topics forward, work in a structured manner, and combine assertiveness with a high degree of cooperation and communication skills.
  • You bring the necessary flexibility and adaptability to succeed in a dynamic regulatory and technological environment.

Our Benefits

  • 30 days of vacation
  • Employer-funded pension
  • Flexible work
  • Employee conditions
  • Digital learning
  • Diversity
  • Family & job friendly
  • Friendly work environment
  • Inspiring company culture
  • Work-life balance

30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance

The company

Group ICT Risk & Resilience Management (GRM-ICT RRM) is responsible, within the 2nd Line of Defence, for steering and further developing the bank-wide ICT risk management framework and digital operational resilience. The function sets the framework for dealing with ICT, information security and cyber risks and supports the sustainable implementation of regulatory requirements, in particular in the context of DORA.

ICT Enablement & Compliance makes a significant contribution by translating regulatory and business requirements into effective awareness, advisory, controls and third-party risk management processes. In this way, risk-oriented and compliant behaviour is strengthened across the bank, responsibilities are clearly embedded, and the organisation is effectively supported in sustainably implementing requirements.

Contact

Are you ready to start implementing the Momentum strategy in a strong team, either full-time or part-time? Then we look forward to receiving your online application by 16. September 2026.