3 часа назад
Senior Risk & Controls Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Risk & Controls Lead (Technology Risk, ITGC): Owning technology risk and compliance across OLX markets with an accent on enterprise risk management, ITGC controls, and audit coordination. Focus on maintaining risk registers, coordinating internal and external audit testing, resolving control findings, and advising CTO and security stakeholders.
Location: Hybrid, three days per week from the office in Warsaw, Poznań, or Krakow, Poland; Bucharest, Romania; or Lisbon, Portugal.
Company
operates online marketplaces that connect people to buy and sell cars, find homes and jobs, and trade secondhand goods across multiple markets.
What you will do
- Own the identification, assessment, mitigation, and monitoring of technology risks across product platforms and maintain the Technology Risk Register.
- Develop and coordinate IT risk treatment strategies while ensuring risk owners remain accountable.
- Partner with Internal Audit on audit planning and monitor the closure of audit issues.
- Coordinate year-end external auditor ITGC testing and drive findings through to resolution.
- Advise the CTO and security teams on IT risk and security matters.
- Lead implementation of the group’s Risk & Compliance system and support internal ITGC testing capability.
Requirements
- Expertise in technology risk, IT audit, or IT governance, preferably in a multi-market environment.
- Experience in an internal Risk & Controls function, IT-focused internal audit team, or Big Four IT/Technology Risk Assurance practice.
- Working knowledge of ISO 27001 and NIST control and security frameworks.
- Practical experience with internal and external audits, risk registers, controls testing, and issue tracking.
- Strong communication, presentation, negotiation, and stakeholder-influence skills, including influencing owners without formal authority.
- Technology-savvy, collaborative, pragmatic, and comfortable constructively challenging decisions.
Nice to have
- Experience with GRC or risk-register tooling, including platform migration or implementation.
- CISA or CRISC certification.
Culture & Benefits
- International environment spanning multiple markets and nationalities.
- Informal, collaborative workplace focused on outcomes over hierarchy.
- Training and e-courses for ongoing professional development.
- Annual performance-based bonus, medical insurance, and flexible benefits.
- Hybrid work with three office days per week.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Cybersecurity Risk Analyst – Financial Services (ISO 27001/NIST)
6 дней назад
IT Risk & Compliance Engineer (DevOps/Agile)
9 600 - 12 000PLN
6 дней назад
Senior Risk Management Analyst (Cybersecurity)
4 дня назад
Risk Analyst & Permanent Control (French speaker) (Cybersecurity Governance & Risk)
5 дней назад
IT Security Analyst - Senior (Vulnerability Management)
3 дня назад
Senior Information Security Officer (Cybersecurity)
5 700 - 7 000€