LOG IN
SIGN UP
Tech Job Finder - Find Software, Technology Sales and Product Manager Jobs.
Sign In
OR continue with e-mail and password
E-mail address
Password
Don't have an account?
Reset password
Join Tech Job Finder
OR continue with e-mail and password
E-mail address
First name
Last name
Username
Password
Confirm Password
How did you hear about us?
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Find your job and make it yours

at ING Bank

Back to all Cybersecurity jobs
ING Bank logo
Investment Banking

Find your job and make it yours

at ING Bank

Mid LevelNo visa sponsorshipCybersecurity

Posted 19 days ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Bucharest
Country
Romania

ING Hubs Romania is hiring an OpsRisk Engineer to support the Financial Markets domain by acting as a central SPOC for IT risk assessments, control evidencing and deviation management. You will work closely with DevOps squads in an Agile/SCRUM environment to implement IT controls, provide documentation and evidence, and liaise with 1st/2nd line risk and auditors. The role includes conducting walkthroughs, leading technical due diligence with third-party vendors, and participating in automation of IT risk processes. Strong communication, knowledge of IT control frameworks (SOX, GDPR, ISO/NIST) and experience in IT risk or cybersecurity are required.

Discover ING Hubs Romania

ING Hubs Romania offers 130 services in software development, data management, non-financial risk & compliance, audit, and retail operations to 24 ING units worldwide, with the help of ๐จ๐ฏ๐ž๐ซ ๐Ÿ๐ŸŽ๐ŸŽ๐ŸŽ ๐ก๐ข๐ ๐ก-๐ฉ๐ž๐ซ๐Ÿ๐จ๐ซ๐ฆ๐ข๐ง๐  ๐ž๐ง๐ ๐ข๐ง๐ž๐ž๐ซ๐ฌ, ๐ซ๐ข๐ฌ๐ค, ๐š๐ง๐ ๐จ๐ฉ๐ž๐ซ๐š๐ญ๐ข๐จ๐ง๐ฌ ๐ฉ๐ซ๐จ๐Ÿ๐ž๐ฌ๐ฌ๐ข๐จ๐ง๐š๐ฅ๐ฌ.

We started out in 2015 as INGโ€™s software development hub, then steadily expanded our range to include more services and competencies. Now we provide borderless services with bank-wide capabilities and ๐จ๐ฉ๐ž๐ซ๐š๐ญ๐ž ๐Ÿ๐ซ๐จ๐ฆ ๐ญ๐ฐ๐จ ๐ฅ๐จ๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ: ๐๐ฎ๐œ๐ก๐š๐ซ๐ž๐ฌ๐ญ ๐š๐ง๐ ๐‚๐ฅ๐ฎ๐ฃ-๐๐š๐ฉ๐จ๐œ๐š.

๐Ž๐ฎ๐ซ ๐ญ๐ž๐œ๐ก ๐œ๐š๐ฉ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ ๐ซ๐ž๐ฆ๐š๐ข๐ง ๐ญ๐ก๐ž ๐œ๐จ๐ซ๐ž ๐จ๐Ÿ ๐จ๐ฎ๐ซ ๐›๐ฎ๐ฌ๐ข๐ง๐ž๐ฌ๐ฌ, with more than 1800 colleagues active in Data Management, Touchpoint Channels & Integration, Core Banking, and Global Products.

We enjoy a flexible way of working and a highly collaborative environment, where fair and constructive feedback is encouraged.

For us, impact isn't a perk. It's the driver of our work. We are guided and rewarded by a shared desire to make the world a better place, one innovative solution at a time. Our colleagues make it their job to do impactful things and they love doing it in good company. Do you?

Your  mission

As an OpsRisk Engineer will be part of the Financial Markets domain. 

You will help on risk subjects like:        

  • Act as a central SPOC for all incoming IT risk assessments and control evidencing requirements adhering the established control framework, SOx requirements and industry best practices.

  • Monitoring, tracking and managing deviations to established IT Risk controls.

  • Mediating between 1st LOD/2nd LOD and DevOps teams.

  • Conducting walkthroughs with auditors to review and validate IT Risk control processes.

  • Lead technical due diligence sessions with third party vendors.

You will work in an AGILE environment, following SCRUM methodology together with DevOps squads, helping to maintain a safe and secure application.

Your Day to Day

Your primary mission is to help the squads to implement IT Controls and to prove the controls are implemented effectively:

  • ensure we are in control of our risk appetite

  • define and document adequate risk processes and collect the evidences in regards; make sure that the different risk parties agree with the evidences

  • responsible for creating documents and project management requirements or specifications

  • provide documentation support to the technical team; interface with developers and operation engineers to define the specifications

  • liaison between the team and other IT Risk professionals

  • understand the need for security and apply it using the existing framework; constant communication about changes

  • participate in automation program for process and evidence for IT risk

  • show proactivity and flexibility, come up with plans of action and adapt approaches if necessary

  • understand the corporate climate and culture and act as an ambassador; IT custodianship/asset owner role.

What youโ€™ll bring to the team

Experience:

  • Degree and/or experience in IT risk management, cybersecurity, or related field.

  • Understanding of fundamental IT risk and security concepts and ability to think critically across technical control domains.

  • Knowledge of IT control frameworks (eg. SOX, GDPR, CSA CCM) and industry standards (eg. ISO2700x, NIST).

  • Proven track record of conducting IT control evidencing, qualitative risk assessments and developing mitigation strategies.

Risk reporting and communication:

  • ability to communicate risk-related concepts to technical stakeholders.

  • experience in liaising with second line risk functions.

  • strong written and verbal communications skills in English.

  • Certifications such as CISSP, CISM, CRISC or equivalent are a plus.

Knowledge:

Mandatory:

  • Ability to understand the risk processes in an IT environment

  • Experience with IT risk standards

  • Ability to make clear and convincing statements related to risk procedures Proven planning and organizing experience

Nice to have:

  • Project management experience

  • Ability to track, plan and coordinate projects related to third party risk management,  technical compliance, and/or IT risk automation

  • Experience in working with Dev(Sec)Ops teams across vulnerability management, threat hunting, security detection and response and developing, or contributing to information security policies and procedures

  • Knowledge of Agile methodology

Foreign languages: English (advanced)

Education: nice to have Bachelorโ€™s Degree (or higher) in an IT related field.

If you want to deep dive into the processing of personal data conducted by ING Hubs Romania during the recruitment process and your rights related to it, read the privacy notices on our website (make sure to scroll until you reach the Data Protection section/ Candidates tab). 

Find your job and make it yours

at ING Bank

Back to all Cybersecurity jobs
ING Bank logo
Investment Banking

Find your job and make it yours

at ING Bank

Mid LevelNo visa sponsorshipCybersecurity

Posted 19 days ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Bucharest
Country
Romania

ING Hubs Romania is hiring an OpsRisk Engineer to support the Financial Markets domain by acting as a central SPOC for IT risk assessments, control evidencing and deviation management. You will work closely with DevOps squads in an Agile/SCRUM environment to implement IT controls, provide documentation and evidence, and liaise with 1st/2nd line risk and auditors. The role includes conducting walkthroughs, leading technical due diligence with third-party vendors, and participating in automation of IT risk processes. Strong communication, knowledge of IT control frameworks (SOX, GDPR, ISO/NIST) and experience in IT risk or cybersecurity are required.

Discover ING Hubs Romania

ING Hubs Romania offers 130 services in software development, data management, non-financial risk & compliance, audit, and retail operations to 24 ING units worldwide, with the help of ๐จ๐ฏ๐ž๐ซ ๐Ÿ๐ŸŽ๐ŸŽ๐ŸŽ ๐ก๐ข๐ ๐ก-๐ฉ๐ž๐ซ๐Ÿ๐จ๐ซ๐ฆ๐ข๐ง๐  ๐ž๐ง๐ ๐ข๐ง๐ž๐ž๐ซ๐ฌ, ๐ซ๐ข๐ฌ๐ค, ๐š๐ง๐ ๐จ๐ฉ๐ž๐ซ๐š๐ญ๐ข๐จ๐ง๐ฌ ๐ฉ๐ซ๐จ๐Ÿ๐ž๐ฌ๐ฌ๐ข๐จ๐ง๐š๐ฅ๐ฌ.

We started out in 2015 as INGโ€™s software development hub, then steadily expanded our range to include more services and competencies. Now we provide borderless services with bank-wide capabilities and ๐จ๐ฉ๐ž๐ซ๐š๐ญ๐ž ๐Ÿ๐ซ๐จ๐ฆ ๐ญ๐ฐ๐จ ๐ฅ๐จ๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ: ๐๐ฎ๐œ๐ก๐š๐ซ๐ž๐ฌ๐ญ ๐š๐ง๐ ๐‚๐ฅ๐ฎ๐ฃ-๐๐š๐ฉ๐จ๐œ๐š.

๐Ž๐ฎ๐ซ ๐ญ๐ž๐œ๐ก ๐œ๐š๐ฉ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ ๐ซ๐ž๐ฆ๐š๐ข๐ง ๐ญ๐ก๐ž ๐œ๐จ๐ซ๐ž ๐จ๐Ÿ ๐จ๐ฎ๐ซ ๐›๐ฎ๐ฌ๐ข๐ง๐ž๐ฌ๐ฌ, with more than 1800 colleagues active in Data Management, Touchpoint Channels & Integration, Core Banking, and Global Products.

We enjoy a flexible way of working and a highly collaborative environment, where fair and constructive feedback is encouraged.

For us, impact isn't a perk. It's the driver of our work. We are guided and rewarded by a shared desire to make the world a better place, one innovative solution at a time. Our colleagues make it their job to do impactful things and they love doing it in good company. Do you?

Your  mission

As an OpsRisk Engineer will be part of the Financial Markets domain. 

You will help on risk subjects like:        

  • Act as a central SPOC for all incoming IT risk assessments and control evidencing requirements adhering the established control framework, SOx requirements and industry best practices.

  • Monitoring, tracking and managing deviations to established IT Risk controls.

  • Mediating between 1st LOD/2nd LOD and DevOps teams.

  • Conducting walkthroughs with auditors to review and validate IT Risk control processes.

  • Lead technical due diligence sessions with third party vendors.

You will work in an AGILE environment, following SCRUM methodology together with DevOps squads, helping to maintain a safe and secure application.

Your Day to Day

Your primary mission is to help the squads to implement IT Controls and to prove the controls are implemented effectively:

  • ensure we are in control of our risk appetite

  • define and document adequate risk processes and collect the evidences in regards; make sure that the different risk parties agree with the evidences

  • responsible for creating documents and project management requirements or specifications

  • provide documentation support to the technical team; interface with developers and operation engineers to define the specifications

  • liaison between the team and other IT Risk professionals

  • understand the need for security and apply it using the existing framework; constant communication about changes

  • participate in automation program for process and evidence for IT risk

  • show proactivity and flexibility, come up with plans of action and adapt approaches if necessary

  • understand the corporate climate and culture and act as an ambassador; IT custodianship/asset owner role.

What youโ€™ll bring to the team

Experience:

  • Degree and/or experience in IT risk management, cybersecurity, or related field.

  • Understanding of fundamental IT risk and security concepts and ability to think critically across technical control domains.

  • Knowledge of IT control frameworks (eg. SOX, GDPR, CSA CCM) and industry standards (eg. ISO2700x, NIST).

  • Proven track record of conducting IT control evidencing, qualitative risk assessments and developing mitigation strategies.

Risk reporting and communication:

  • ability to communicate risk-related concepts to technical stakeholders.

  • experience in liaising with second line risk functions.

  • strong written and verbal communications skills in English.

  • Certifications such as CISSP, CISM, CRISC or equivalent are a plus.

Knowledge:

Mandatory:

  • Ability to understand the risk processes in an IT environment

  • Experience with IT risk standards

  • Ability to make clear and convincing statements related to risk procedures Proven planning and organizing experience

Nice to have:

  • Project management experience

  • Ability to track, plan and coordinate projects related to third party risk management,  technical compliance, and/or IT risk automation

  • Experience in working with Dev(Sec)Ops teams across vulnerability management, threat hunting, security detection and response and developing, or contributing to information security policies and procedures

  • Knowledge of Agile methodology

Foreign languages: English (advanced)

Education: nice to have Bachelorโ€™s Degree (or higher) in an IT related field.

If you want to deep dive into the processing of personal data conducted by ING Hubs Romania during the recruitment process and your rights related to it, read the privacy notices on our website (make sure to scroll until you reach the Data Protection section/ Candidates tab).