Job Description
Main Responsibilities:
- Perform risk assessments on IT systems, applications, networks, and third-party vendors.
- Identify, analyze, and document technology risks and potential business impacts.
- Collaborate with IT, InfoSec, Compliance, and Business teams to address and mitigate identified risks
- Monitor and report on key risk indicators (KRIs), control effectiveness, and residual risk.
- Support the implementation of risk management frameworks such as NIST, ISO 27001, COBIT, or FAIR.
- Maintain up-to-date knowledge of emerging technology threats, vulnerabilities, and regulatory requirements.
- Assist in audits, regulatory examinations, and internal control assessments.
- Participate in development and enhancement of IT risk policies, standards, and procedures.
- Support incident response and post-incident risk reviews.
- Assess risk from third-party vendors and ensure appropriate controls are in place.
- Perform other tasks assigned by the Unit Manager/Chief Risk Officer.
Qualifications and Requirements:
- Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field.
- 2–3 years of experience in IT risk management, information security, or GRC roles.
- Solid understanding of IT systems, cloud environments, and cybersecurity principles.
- Experience with risk assessment methodologies and frameworks (e.g., NIST RMF, ISO 27001, COSO).
- Familiarity with regulatory and compliance requirements such as GDPR, SOX, HIPAA, PCI DSS.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills for reporting and stakeholder engagement.