Назад
Company hidden
3 часа назад

Senior Risk & Controls Lead

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
Poland/Romania/Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk & Controls Lead (Technology Risk, ITGC): Owning technology risk and compliance across OLX markets with an accent on enterprise risk management, ITGC controls, and audit coordination. Focus on maintaining risk registers, coordinating internal and external audit testing, resolving control findings, and advising CTO and security stakeholders.

Location: Hybrid, three days per week from the office in Warsaw, Poznań, or Krakow, Poland; Bucharest, Romania; or Lisbon, Portugal.

Company

hirify.global operates online marketplaces that connect people to buy and sell cars, find homes and jobs, and trade secondhand goods across multiple markets.

What you will do

  • Own the identification, assessment, mitigation, and monitoring of technology risks across product platforms and maintain the Technology Risk Register.
  • Develop and coordinate IT risk treatment strategies while ensuring risk owners remain accountable.
  • Partner with Internal Audit on audit planning and monitor the closure of audit issues.
  • Coordinate year-end external auditor ITGC testing and drive findings through to resolution.
  • Advise the CTO and security teams on IT risk and security matters.
  • Lead implementation of the group’s Risk & Compliance system and support internal ITGC testing capability.

Requirements

  • Expertise in technology risk, IT audit, or IT governance, preferably in a multi-market environment.
  • Experience in an internal Risk & Controls function, IT-focused internal audit team, or Big Four IT/Technology Risk Assurance practice.
  • Working knowledge of ISO 27001 and NIST control and security frameworks.
  • Practical experience with internal and external audits, risk registers, controls testing, and issue tracking.
  • Strong communication, presentation, negotiation, and stakeholder-influence skills, including influencing owners without formal authority.
  • Technology-savvy, collaborative, pragmatic, and comfortable constructively challenging decisions.

Nice to have

  • Experience with GRC or risk-register tooling, including platform migration or implementation.
  • CISA or CRISC certification.

Culture & Benefits

  • International environment spanning multiple markets and nationalities.
  • Informal, collaborative workplace focused on outcomes over hierarchy.
  • Training and e-courses for ongoing professional development.
  • Annual performance-based bonus, medical insurance, and flexible benefits.
  • Hybrid work with three office days per week.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →