Welcome to the team: (Senior) ICT Risk Management Specialist (m/f/diverse)

-
FunctionFunction:
Information Technology -
LocationLocation:
Praha
GRM-ICT Risk & Resilience Management (GRM-ICT RRM) is responsible for the group-wide management of cyber and information security risks and ensures an appropriate (cyber) security level at Commerzbank by clearly defining roles and responsibilities within the security organization.
The department ICT Risk Management as part of GRM-ICT RRM operates as the "Second Line of Defense" (2nd LoD) for ICT risks. Our key responsibilities include:
- Governance of the ICT risk management process at 2nd Line level, covering identification, assessment, treatment, monitoring and escalation in line with the Bank’s risk appetite.
- Development and maintenance of an overarching ICT risk inventory, including classification, aggregation and identification of ICT risk hot spots.
- Definition and enhancement of ICT risk methodologies, taxonomies and assessment approaches, including review and challenge of the 1st Line.
- Enhancement of standardized models, processes, metrics and indicators for Group-wide ICT GRC risk management.
- Execution of 2nd Line controls.
Your tasks
Play a key role in overseeing the bank's ICT risks. You will ensure that relevant ICT risks are identified, assessed, and coordinated.
Showcase your expertise and expand your skills by taking responsibility for the following 2nd Line of Defense tasks:
- Review and challenge ICT risk assessments and risk treatment plans of the 1st Line, and prepare, recommend and track risk acceptance decisions.
- Identify, assess and monitor ICT risks, including concentration risks such as provider, technology, location or key-person dependencies.
- Translate ICT risks into the OpRisk framework in coordination with Operational Risk Management and escalate unacceptable risks.
- Implement regulatory requirements in a solution-oriented manner and derive audience-specific recommendations to steer and mitigate ICT risks.
- Cooperate with relevant internal interfaces, the 1st Line, governance functions, internal audit, compliance and internal/external committees within the area of responsibility.
- Act as a knowledge multiplier within the relevant area of expertise and share expertise within the team in a needs- and task-oriented manner.
- Prepare and maintain meaningful ICT risk reporting for Senior Management, including clear insights on the ICT risk profile, key risk indicators, trends, material issues and decision-relevant recommendations.
- Prepare decision-oriented materials for Senior Management and relevant governance bodies, including clear options, risk implications, escalation needs and recommended actions.
- Ensure the quality, consistency and usability of ICT risk data in relevant GRC tools and reporting systems, supporting reliable risk transparency and effective management decisions.
Your Profile
- A university or university of applied sciences degree, preferably in business informatics, computer science, mathematics, natural sciences, business administration, law, engineering or a degree program with a focus on information technology, risk management or resilience.
- Very good knowledge of regulatory requirements (e.g. DORA) and recognized standards (e.g. ISO 27001, NIST) in the relevant subject area, particularly ICT risk management, governance/compliance, information security, BCM/ITSCM and operational resilience.
- Significant experience and specialized knowledge in (digital) operational resilience and ICT risk processes across the 1st, 2nd, or 3rd Line of Defense.
- Strong analytical skills, structured working style, audience-specific communication, ability to operate in committees and capability to derive regulatory-compliant and implementable solutions in a complex interface environment.
- A proactive mindset, openness to addressing critical issues, and the ability to work collaboratively in developing and implementing constructive solutions within a team setting.
- Preferred expertise in leading information security and IT security frameworks, such as CISSP, CISM, ISO 27001, or ICT DORA Risk Manager certification.
- Excellent communication and documentation skills in English, with German being an added advantage
Our Benefits
30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance
The company
Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create a positive impact in the banking world.
Contact
In case of interest plase applz via this job portal.

