ICT Risk Management Chief Expert
DSK Bank · Sofia, Sofia City, Bulgaria · Mid
Умения
Сертификати
Описание
We are DSK Bank, a proud member of OTP Group, a leading financial institution in CEE, leader in the Bulgarian banking sector. As member of our team, you will be part of one of the largest banking groups in Bulgaria, which plays an important role in creating and maintaining business relationships with leading companies in the country, as well as with several million individual customers.
Join our ICT Risk Management team and help shape the way technology risks are identified, assessed, challenged and managed across the Bank.
We are looking for an experienced ICT Risk Management Expert to join our team and contribute to the further development of the Bank’s ICT Risk Management framework in line with regulatory expectations, industry practices and the Bank’s risk appetite. This is a Second Line of Defense control function, providing independent challenge, oversight and assurance over ICT risks and controls while working closely with IT, Information Security, Business, Procurement and other stakeholders.
You will work in one of the most dynamic and increasingly important areas of the financial industry. As banks become more interconnected and dependent on technology, critical services and third-party providers, operational resilience is receiving growing attention from regulators and senior management.
This role offers broad cross-functional exposure across Business, IT, Information Security, Risk, Crisis Management and Procurement. You will work on topics such as Business Impact Analysis, resilience testing, crisis management, third-party dependencies and Operational Continuity in Resolution, helping strengthen the Bank’s ability to protect its critical services against disruption.
What you will be responsible for:
ICT Risk Governance
- Develop, maintain and continuously improve the ICT Risk Management and Third-Party Risk Management frameworks, policies, procedures and methodologies.
- Support the effective implementation of ICT Risk Management requirements across the Bank.
- Prepare reporting for senior management and relevant governance bodies.
- Support communication and regulatory reporting to competent authorities, regulators and supervisors on ICT and Third-Party Risk Management matters.
ICT Risk Assessment & Control Assurance
- Coordinate ICT risk assessments covering technology, applications, infrastructure, information assets, services and ICT processes.
- Challenge the identification, assessment and treatment of ICT risks performed by First Line functions.
- Develop and maintain an ICT control testing and assurance approach.
- Perform independent Second Line assessments of the design and operating effectiveness of ICT controls.
- Track the remediation of ICT risk and control deficiencies and provide independent assurance over their closure.
Third-Party and ICT Supplier Risk Management
- Coordinate third-party risk assessments, including assessments of ICT services supporting critical or important functions.
- Challenge risk assessments, due diligence, contractual risk mitigation measures and exit strategies.
- Oversee the effective implementation of third-party service management requirements.
- Aggregate, analyse and report third-party monitoring data and key risk information to senior management and relevant governance bodies.
What we are looking for:
- Experience in ICT Risk Governance, IT and Third-Party Risk Management, Technology Risk, IT Audit, Information Security Governance, Internal Control or a related field.
- Understanding of IT infrastructure, applications, technology services and associated risks.
- Practical experience in risk assessments and control testing or assurance.
- Good understanding of DORA, EBA and ECB expectations and ICT risk management principles, with the ability to translate them into internal policies, procedures and methodologies.
- Ability to analyse complex technology, regulatory and non-financial risk topics and translate them into clear risk conclusions for senior stakeholders.
- Strong communication and stakeholder-management skills, including the ability to challenge experienced IT and business professionals constructively.
- Structured, analytical and independent approach to work.
- Professional certification such as CISA, CRISC, CISM, CISSP or equivalent would be an advantage.
What we offer:
- Competitive multi-component remuneration and attractive bonus scheme;
- An additional 102,26 euro per month is provided in the form of food vouchers;
- 20+5 days paid leave;
- Additional Health Insurance;
- Promo price for Multisport Cards;
- Perfect opportunities for professional and career development in a leading Bank in Bulgaria;
- Professional training for specific knowledge and skills;
- Unique banking service package – special loan interest for employees on housing and consumer loans;
- Top technologies to use;
- Discount program with external vendors;
- Great working environment within a team of professionals.
If you are challenged by this opportunity, we would be glad to review your application.
Only short-listed candidates will be contacted. All applications will be treated with strict confidentiality.
История на обявата
- 7 октомври 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.
Само 2 обяви за тази роля и ниво публикуват заплата — твърде малко за средна стойност.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.