Welcome to the team: (Senior) AI ICT Risk, Threat Modelling and Technology Research Specialist (m/f/diverse)

-
FunctionFunction:
Risk / Credit / Financing -
LocationLocation:
Praha
Group ICT-Risk and Resilience Management is responsible for the group-wide management of cyber and information security risks and ensures an adequate and sustainable level of (cyber) security at Commerzbank through clearly defined roles and responsibilities within the security organisation. GRM-ICT RRM serves as the second line of defence (2LoD) for managing cyber and information security risks across Commerzbank.
GRM-ICT RRM establishes the ICT Policy & Control Framework, sets standards, monitors compliance, and assesses ICT risks to ensure adherence to regulatory requirements, including the Digital Operational Resilience Act (DORA). In this role, GRM-ICT RRM provides independent challenge and oversight of the 1st LoD, monitors the effectiveness and completeness of security controls, and intervenes in a controlling manner where necessary.
Your tasks
- As a (Senior) AI ICT Risk, Threat Modelling and Technology Research Specialist, you are the central contact for ICT risks arising from the design, deployment, and operation of AI and machine-learning solutions, as well as emerging technologies relevant to the bank.
- You conduct structured ICT risk assessments and threat-modelling exercises for AI/ML deployments across the bank.
- You assess AI-specific risk areas, including data integrity and quality, model security, algorithmic bias, adversarial attack surfaces, privacy, third-party dependencies, and regulatory compliance.
- You research technology developments, innovations, and disruptions relevant to ICT risk management and assess their potential security implications, emerging attack vectors, and opportunities for enhanced controls.
- You monitor and assess relevant developments in AI technologies, AI security, regulatory requirements, standards, and industry practices.
- You prepare and publish research findings, technology-risk opinions, and recommendations to inform strategic, governance, and risk-management decisions.
- You advise and support internal stakeholders in identifying appropriate mitigating controls and defining risk-based requirements for the secure and compliant use of AI/ML solutions and emerging technologies.
- You contribute to the development and quality assurance of ICT security policies, procedures, standards, and control requirements relating to AI/ML risk management, emerging technologies, and secure technology deployment.
- You provide independent 2LoD challenge and residual-risk assessments to support management and governance decisions on AI/ML and technology initiatives.
- You work closely with colleagues across GRM-ICT RRM, IT, data and AI teams, architecture, and external service providers on the secure implementation and operation of AI/ML solutions and emerging technologies.
Your Profile
- University degree in computer science, mathematics, data science, artificial intelligence, cyber security, engineering, or a comparable field; alternatively, equivalent professional training and relevant practical experience.
- Proven professional experience in ICT security, ICT risk management, security architecture, data governance, AI/ML engineering, technology research, or model risk management, with sound knowledge of AI/ML-related threats and controls.
- In-depth knowledge of AI/ML technologies, data pipelines, model lifecycles, threat-modelling methodologies, and their implementation within complex ICT environments.
- Demonstrated ability to assess emerging technology developments, identify associated ICT risks and attack vectors, and translate research findings into practical control and governance recommendations.
- Demonstrated knowledge of relevant AI, ICT security, data-protection, and operational-resilience standards and regulatory requirements, as well as current AI security and industry developments.
- Very good analytical, conceptual, research-oriented, and solution-oriented thinking and acting.
- High self-initiative, independence, and service orientation, combined with the ability to communicate complex technical risks clearly to management and non-technical stakeholders.
- Business-fluent German and English skills, both written and spoken.
Our Benefits
30 days of vacation; Employer-funded pension; Employee conditions; Flexible work; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance
The company
Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create a positive impact in the banking world.
Contact
In case of interest please apply via this job portal.

