Welcome to the team: (Senior) ICT Strategy (m/f/diverse)

-
FunctionFunction:
Risk / Credit / Financing -
LocationLocation:
Praha
As an ICT Strategy (Senior) Specialist in the "ICT Risk management and Resilience" division, you will shape and steer the bank’s ICT Risk strategy as part of the 2nd Line of Defense for ICT Risk. You ensure alignment of ICT risk strategy with business objectives, enterprise risk management, and regulatory expectations.
Your tasks
Showcase your expertise and expand your skills by taking responsibility for the following 2nd Line of Defense tasks:
- Monitor and assess emerging ICT risks and technology trends through horizon scanning, cyber threat intelligence, regulatory analysis, and strategic research to identify potential impacts on the organization.
- Provide independent strategic risk insights and guidance by delivering 2LoD assessments, risk trend reporting, and recommendations that support strategic decision-making, risk appetite calibration, threat steering, and long-term capability investments.
- Defining and maintaining the ICT/DOR risk strategy and ensuring alignment with enterprise-wide strategic priorities (such as AI and regulatory requirements (e.g., DORA, NIS2).
- Monitoring and controlling the execution of the ICT Risk strategy against defined milestones, deliverables, and timelines.
- Conducting horizon scanning and strategic research to identify emerging ICT risks, cyber threats, and regulatory developments.
- Developing and calibrating the ICT risk appetite as part of the Group Risk Appetite Framework, including thresholds, KRIs, and escalation triggers.
- Providing independent oversight of the ICT risk portfolio including identifying risk concentration and obsolescence risks.
- Maintaining and advancing the ICT risk capabilities (people, process, technology) to support maturity and strategic decisions.
Your Profile
- You hold a university degree in Business Administration, Information Systems, Informatics, or a comparable discipline;
- You have extensive experience in ICT risk management, digital operational resilience, or strategy development within financial institutions.
- You are familiar with key regulatory frameworks (particularly DORA) and their strategic implications.
- You demonstrate strong analytical skills and the ability to translate complex topics into clear, structured strategic messages for senior stakeholders.
- You show high initiative, strategic thinking, and the ability to challenge effectively from a 2nd Line of Defense perspective.
- Relevant professional certifications such as CRISC, CGEIT, CISM, CISSP, TOGAF, or COBIT are advantageous, but equivalent practical experience is equally valued.
- Communication and documentation in English come naturally to you. German would be beneficial.
Our Benefits
30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance
The company
Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create a positive impact in the banking world.
Contact
In case of interest please apply via this job portal.

