IT Risks Specialist

Porto, Porto District, Portugal | Cybersecurity | Full-time | Hybrid

Apply

Overview:

Manage IT risks; Ensure the implementation of IT Governance; Oversee and report on IT governance and risks; Ensure the monitoring and deployment of DORA governance.

What will you do?

  • Ensure the regular review of IT risks and complete the risk sheets in Service Now.
  • Ensure the annual GKSP BI control campaign and record the results in Service Now.
  • Monitor the GKSP action plans and provide a regular progress status (Excel).
  • Organize and present the quarterly IT Risk and Cyber Committee (Risk KPIs, IG Recommendations, Obsolescence, Shadow IT, Historical Incidents, CLV Maturity in relation to group governance, Outsourcing) with the help of CORPORATE teams.
  • Assist the CIO in organizing and preparing the quarterly IT Steering Committee.
  • Ensure updates to procedures to adapt them to Group governance by relying on the owners of the relevant processes.
  • Ensure the implementation of IT Governance.
  • Break down and deploy our Group IT governance (procedures, rules, requirements, controls), ensuring formalization of proper documentation. 
  • Support IT managers and IT teams in implementing IT Governance rules – adapting the rules to the context of Lux Vie, identifying controls, optimizing their implementation, formalizing, and updating procedures.
  • Monitor the actual implementation of IT Governance within Lux Vie, track the level of compliance and associated remediation plans.
  • Contribute to the establishment of Lux Vie's IT management system.
  • Manage IT risks.
  • Deploy IT risk management practices and promote awareness of IT risk culture.
  • Maintain the IT risk register and ensure the proper handling of IT risks (identification, assessment, treatment, reporting) – in coordination with operatives and Security teams.
  • Contribute to feeding the various risk mappings on the IT aspect (ORSA, RCSA).
  • Identify, if necessary, the local controls and KRIs to be implemented.
  • Monitor operational incidents of IT nature.
  • Lead the various IT control plan campaigns (organization, methodology support, review/challenge results, evidence and action plans, present reports of campaign results).
  • Monitor IT audits and, if necessary, the implementation of recommendations.
  • Establish the inventory of shadow IT.
  • Manage and report IT governance and risks.
  • Prepare various reports related to IT risks and IT governance expected locally and at our Group level.
  • Serve as a liaison with our headquarters teams on matters related to IT.
  • Governance and risks (reporting, considering specific requests, etc.).
  • Consolidate and manage the remediation portfolio on various IT risks and non-compliances.
  • Participate in the preparation of the IT & Cyber risk committee at local and headquarters levels, as well as other IT governance bodies (cybersecurity committee, obsolescence committee, asset committee, etc.).
  • Ensure the monitoring and deployment of DORA governance.
  • Prepare the various reports related to DORA governance at the local level.
  • Conduct the review of intragroup contracts with subcontractors and ensure the compliance of DORA clauses.
  • Implement governance requirements (deployment and support of the various services for Araques, specific due diligence, etc.).
  • Monitor and set up DORA steering committees with the different entities and subcontractors.
  • Participate in the contractual review of suppliers.

What are we looking for?

  • Domain in Finance/Insurance.
  • Expertise in IT and IT Security.
  • Norms & Processes : know-how in governance and risk management standards (COBIT, COSO, ISO 31000, ITIL, NIST, DORA etc.).
  • Technical: Office package, Service Now.
  • Fluent in French (C1 mandatory).
  • Fluent in English (C1 valuable).
  • Very good organisational and communication skills (both written and spoken) in a multi-cultural environment.
  • Ability to manage/facilitate a meeting.
  • Aim to deliver very high quality results, respecting the deadlines.
  • Respect the procedures, methodologies and directives.
  • Good listening, questioning ability and result-driven personality.
  • Ability to travel within the Portugal.
  • Ability to travel outside the Portugal.

What can you expect from us?

  • A permanent job contract for a long term project;
  • Tech equipment + SIM Card + personal smartphone;
  • Health and Life Insurance;
  • Social events and team buildings;
  • The commitment of letting you grow with us, and be rewarded accordingly;
  • A dynamic and young team that will be always there to support you;
  • Training in the latest technologies;
  • Coffee, fruits, snacks and a warm welcoming when you pass by the office.