Job Description
Associate Director - ICT Risk Management

Summary

Scope Ratings is looking for an ICT Risk Manager as part of the ICT Risk management function, and will be responsible for executing the ICT risk management framework on a day-to-day basis, including running the ICT risk assessment cycle, maintaining the function's registers, coordinating resilience testing and producing the function's reporting.

ICT Risk Management owns the ICT risk management framework and provides independent oversight of its implementation. The function incorporates oversight of Information Security, ICT business continuity and ICT third-party risk management.

Duties & responsibilities

  • Draft and maintain the ICT risk management framework, the underlying policies and methodologies.
  • Design the function's processes and workflows, including vendor assessment, finding management and change risk review, in collaboration with business and technology functions.
  • Respond to client security questionnaires and ad-hoc security and resilience disclosure requests, and maintain a library of standard responses.
  • Identify opportunities to streamline and automate the function's processes.
  • Build and maintain effective relationships with business, technology and control functions, supporting them in identifying ICT risks, including vendor assessments, business impact analyses (BIAs) and control documentation.
  • Design and run ICT business continuity and resilience exercises, including scenarios, facilitation and capturing lessons learned.
  • Run the ICT security testing programme, including penetration testing (scoping, rules of engagement, vendor triage, oversight, finding triage), vulnerability scanning, social engineering and phishing simulations, and breach scenario exercises.
  • Maintain the cyber threat landscape through active monitoring of threat intelligence sources, ISAC participation and sectoral information sharing, and translate threat intel into scenarios and risk profile updates.
  • Consolidate findings from audits, risk assessments, security testing and incidents into a single ICT findings view, and track remediation through to closure across business and technology functions, escalating delays and blockers to the Head of ICT Risk Management.
  • Write executive summaries and briefings on ICT risk topics for the Resilience Committee, Senior and Executive Management and the Boards.

Professional & personal qualifications

  • 4+ years of experience in a risk, security, or resilience discipline, such as ICT/technology risk, information security, or operational resilience, within financial services or another regulated industry.
  • Experience drafting policies, methodologies and process documentation.
  • Practical experience in one or more of the following: running ICT risk assessment cycles, commissioning or overseeing security testing programmes (including penetration testing and vulnerability management), designing and facilitating business continuity exercises, reviewing and challenging incident investigations and problem management led by first-line teams.
  • Experience working with first-line business and technology functions on risk or security-related topics.
  • Working knowledge of security or resilience frameworks, such as DORA, the EBA Guidelines on ICT and Security Risk Management, and of recognised standards including ISO/IEC 27001 and NIST Cybersecurity Framework.
  • Awareness of the threat landscape relevant to financial services and of current developments in cyber, AI and ICT third-party risk.
  • Preferred experience in third-party or vendor risk management, or in a related discipline involving vendor oversight, such as procurement, vendor governance, or supplier relationship management.
  • Preferred working knowledge of secure software development practices and the controls embedded in application, model and infrastructure-as-code development lifecycles.
  • Preferred certification in information security or ICT risk management demonstrating expertise across security programmes and operational risk practices, such as CISM or CRISC.
  • Fluent in English (written and spoken)

The compensation range disclosed may encompass multiple title levels (Scope internal levels of seniority). Your actual compensation will depend on a variety of factors, including but not limited to your individual experience, education, and seniority, and the final salary will be determined during the interview and evaluation process.

Pay Band:  Associate Director - ICT Risk Management
Minimum:  210,000.00 PLN
Maximum:  290,000.00 PLN

Bonus: Discretionary
Benefits: Scope offers an extensive range of benefits, please check our benefits page for more details.

Interested?
If this sounds like a journey for you, we look forward to learning more from your convincing application. Please note: For non-EU applicants, a valid work and residence permit is a prerequisite for this job position. Unfortunately, we are unable to sponsor relocation from outside of the EU at this time.

What we want to see

  • Current CV
  • Copy of your university degrees and certificates
  • Criminal record certificate (can be provided at a later date)
  • At least 3 letters of reference (can be provided at a later date)

About Scope Group
With more than 250 employees operating from offices in Berlin, Frankfurt, London, Madrid, Milan, Oslo and Paris, Scope Group is the leading European provider of independent credit ratings, ESG and fund analysis. Based on forward-looking and innovative methodologies, Scope offers a European perspective that contributes to greater diversity of opinion for institutional investors worldwide. Scope Ratings is the largest European credit rating agency, registered in accordance with EU and UK rating agency regulation, offering opinion-driven and non-mechanistic credit risk analysis. Scope ESG Analysis provides tools for analysing and reporting on ESG impact and risk, as well as second-party opinions on green, social and sustainable bonds. Scope Fund Analysis rates more than 10,000 funds and asset managers across all major asset classes. The shareholders of Scope Group include CEO and founder Florian Schoeller and anchor shareholder Stefan Quandt, numerous senior personalities in European finance and industry as well as institutional investors from several European countries. More on www.scopegroup.com 

At Scope Group, we are committed to fostering a diverse and inclusive workplace where everyone is treated with respect and fairness. We embrace people from all backgrounds, regardless of culture, ethnicity and gender. We ensure that our application processes are free from discrimination. By valuing each individual's unique background and perspectives, we strive to create an environment where all employees can thrive and contribute their best. Our dedication to equality and inclusivity reflects our belief that diversity drives innovation and success.