Назад
Company hidden
5 дней назад

IT OpsRisk Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Английский
c1
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT OpsRisk Engineer (Cybersecurity) (IT risk and security controls): Maintaining IT risk controls and evidence for Financial Markets applications with an accent on control frameworks, audit walkthroughs, and third-party technical due diligence. Focus on mediating between risk functions and DevOps squads, defining mitigation strategies, and automating risk processes and evidence collection.

Location: Bucharest, Romania — Dacia One

Company

hirify.global Romania provides software development, data management, non-financial risk and compliance, audit, and retail operations services to ING units worldwide.

What you will do

  • Act as the central point of contact for IT risk assessments and control evidence requirements within the established control framework.
  • Monitor, track, and manage deviations from IT risk controls while helping squads maintain application security.
  • Define risk processes, collect and validate evidence, and coordinate agreement among risk stakeholders.
  • Mediate between first- and second-line risk functions and DevOps teams in an Agile/Scrum environment.
  • Conduct auditor walkthroughs and lead technical due diligence sessions with third-party vendors.
  • Support IT risk automation, documentation, project requirements, and communication of security changes.

Requirements

  • Degree or experience in IT risk management, cybersecurity, or a related field.
  • Understanding of IT risk and security concepts, technical control domains, and risk processes in an IT environment.
  • Knowledge of IT control frameworks and standards, including SOX, GDPR, CSA CCM, ISO 2700x, and NIST.
  • Experience with IT control evidence, qualitative risk assessments, mitigation strategies, risk standards, and planning.
  • Ability to communicate risk concepts clearly to technical stakeholders and liaise with second-line risk functions.
  • Advanced English is required.

Nice to have

  • CISSP, CISM, CRISC, or equivalent certification.
  • Bachelor’s degree or higher in an IT-related field.
  • Project management and third-party risk management experience.
  • Experience with DevSecOps, vulnerability management, threat hunting, security detection and response, or IT risk automation.
  • Knowledge of Agile methodology.

Culture & Benefits

  • Flexible way of working in a collaborative environment.
  • Work with DevOps squads in an Agile/Scrum setup.
  • Constructive feedback and shared responsibility for secure, impactful solutions.
  • Exposure to Financial Markets and services supporting ING units worldwide.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →