Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Responsibilities:
Design and implement risk-based assurance plans aligned with internal and regulatory requirements.
Lead and execute IT and IS assurance assessments to evaluate risks across applications, infrastructure, cloud platforms, and network/security processes.
Ensure IT systems and processes comply with relevant laws, regulations, and standards, including DORA, MaRisk, CSSF, NIST, ISO 27000 etc.
Test the effectiveness of IT General Controls (ITGC) and cybersecurity controls across Access Management, SDLC and Change Management, Encryption, Third Party Risk, Patch and Vulnerability Management, SIEM, Penetration Testing, IT Operations, and other security domains to identify gaps and improvement areas.
Prepare high-quality assurance reports with clear observations, identified risks, and actionable recommendations for management; effectively communicate complex technical issues to both technical and non-technical stakeholders.
Track and monitor remediation actions, validate closure, and ensure sustainability of corrective measures.
Collaborate with IT, Security teams, and other cross-functional stakeholders to provide risk insights or guidance on risk and control expectations for new and existing systems.
Contribute to the continuous improvement of assurance methodologies, frameworks, and processes.
Stay updated with emerging cyber threats, industry trends, evolving technologies, cloud risks, and changes in the regulatory landscape.
Requirements:
A minimum of 3+ years of dedicated experience in IT/ cyber audit, second-line assurance, cybersecurity implementation or a GRC role, with a proven track record of active involvement in complex audits/assurance reviews or implementation projects from planning to reporting.
Bachelor's or Master's degree in IT, Information Security, Risk Management, or a related field.
Strong technical proficiency in Cloud Security, Network Security, Vulnerability Management and Penetration Testing.
Exposure to SIEM / SOC /CERT and Encryption.
Expertise with Identity and Access Management / Privileged Access Management (PAM).
Experience in Software Development and Change Management.
Knowledge of Artificial Intelligence (AI) Risk / AI Governance.
Strong knowledge of IT governance and control frameworks such as COBIT, CSA CCM, ISO/IEC 27000 series, ITIL, and relevant EU regulations.
Certifications such as CISA, ISO 27001 LA/LI, CISM, CISSP, and CRISC are preferred.
Experienced in audit/assurance techniques, developing risk-based testing strategies, sampling methodologies, and mentoring junior team members.
Ability to identify root causes, understand cross-domain risk impacts, and translate complex technical and regulatory issues into business implications.
Strong communication, negotiation, and influencing skills; comfortable presenting findings and building credibility with senior stakeholders.
Strong understanding of the Three Lines of Defence model.
Experience
4-8 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.