ICT Risk Assurance Specialist
2 weeks ago
Your area of work:
The Chief ICT Risk Office / CISO department combines IT & IS Risk Management in the 2nd Line of Defense (LoD). Its mandate is to:
- Define ICT risk governance and framework.
- Set control objectives, review methodology, and risk assessment methodology.
- Conduct independent oversight of 1st LoD IT and IS controls.
- Monitor and report on ICT risk levels.
- Drive transformation and collaboration across the organization.
You will ensure continuous monitoring and oversight of ICT risk to provide reasonable assurance that ICT controls are properly designed, implemented, and operating effectively.
Your responsibilities:
- Plan & Prepare - Develop annual/multi-year assurance plans, define scope, and prepare workbooks with control requirements and test steps.
- Assess & Monitor - Perform Test of Design (ToD) and Test of Implementation (ToI) for ICT controls; test operating effectiveness (ToE) using inquiry, observation, inspection, and re-performance.
- Request evidence – Collect and analyze evidence (policies, procedures, system configs, logs); escalate delays when needed.
- Report & Communicate – Document observations and improvement opportunities; share preliminary results for validation; deliver structured reports with severity ratings and remediation timelines.
- Follow-up & Track – Monitor remediation progress, escalate overdue items, validate closure evidence, and update status reports.
- Continuously Improve – Enhance methodologies, templates, and processes; ensure alignment with regulatory requirements (e.g., DORA) and internal frameworks.
Your profile:
- University degree (Bachelor/Master) in IT, Information Security, Risk Management, or related field.
- Minimum 2 years of experience in IT/Information Security, ideally in internal/external audit, second-line assurance, or control implementation roles.
- Experience in the financial sector, preferably within EU-regulated environments; familiarity with BAIT, MaRisk, CSSF, and DORA is a plus.
- Strong understanding of ICT risk frameworks, control design and implementation principles, and the Three Lines of Defense model.
- Familiarity with common IT standards (CSA-CCM, COBIT, BSI Grundschutz, ITIL, ISO/IEC 27000 series).
- Professional certifications such as CISA, CISM, CISSP, CEH, or CIA are preferred.
- Ability to apply assurance techniques (inquiry, observation, inspection, re-performance) and sampling methodologies.
- High analytical skills and conceptual thinking; ability to interpret complex technical and regulatory requirements.
- Strong interpersonal and communication skills for engaging senior stakeholders.
- Experience in Cloud Security, Network Security, Vulnerability Management, Security Information and Event Management (SIEM), Privileged Access Management (PAM), Threat Intelligence, Incident Response, or related domains is an advantage.
- Excellent English (written and spoken); German is an advantage.
-
ICT Risk Assurance Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Full time 1,200,000 - 2,400,000 per yearBuild the future of financial markets. Build yours.Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 15,000 colleagues around the globe, we actively shape the future of financial markets. Join our One...
-
Student - Risk & Control Assurance (f/m/d)
1 week ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Group Full timeYour area of work:Clearstream Risk Management ("CRM") is responsible for measurement, controlling and reporting of operational, business and liquidity risks of the Clearstream Group. The CRM team reports to the Chief Risk Officer of Clearstream. As part of this responsibility, the function is tasked with the identification, measurement, reporting and...
-
IT Governance Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Group Full time 30,000 - 90,000 per yearArea of work:As IT Governance Specialist in the IT Risk & Information Domain Unit of IT Governance, Risk & Transformation (GRT) you will join the Deutsche Börse Group CIO/COO team. The position will be instrumental in shaping the future IT Risk and Information Domain Unit, directly supporting the Unit Head to achieve the intended outcomes. In our fast-paced...
-
ISO 27001 Analyst
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Insight Assurance Full time 40,000 - 60,000 per yearAbout Insight AssuranceInsight Assurance is a global audit firm on a mission to transform how organizations achieve cybersecurity and compliance. Founded by former Big 4 (EY) professionals, we deliver next-generation audit services across SOC 2, ISO 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks.We're not your traditional audit...
-
Student - Risk & Control Assurance (f/m/d)
1 week ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Full timeBuild the future of financial markets. Build yours.Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 15,000 colleagues around the globe, we actively shape the future of financial markets. Join our One...
-
IT Governance Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Full time 40,000 - 60,000 per yearBuild the future of financial markets. Build yours.Ready to make a real impact in the financial industry? At Deutsche Börse Group, we'll empower you to grow your career in a supportive and inclusive environment. With our unique business model, driven by 15,000 colleagues around the globe, we actively shape the future of financial markets. Join our One...
-
Configuration/ Deployment Specialist
3 days ago
Prague, Hlavní město Praha, Czech Republic Serco Full timePackage DescriptionCompetitive Salary Corporate Benefits Package Chance to make a positive difference in a company passionate about diversity and inclusion.Further information available from the Serco Europe Recruitment Team Job Introduction Serco is the preferred partner for European Institutions and International Organisations, offering ICT services...
-
Security Risk Management Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Canonical - Jobs Full time 80,000 - 120,000 per yearIn security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support...
-
Navision Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Watson Health & Beauty Europe Full time 30,000 - 60,000 per yearNavision SpecialistAre you looking for a job where youcan really make IT work effectively? Are you experienced with working in anAgile IT environment and do you want to work in a dynamic and internationalenvironment? Then we are looking for youAs an Navision Specialist, you are part of the Innovation team within the Central European ITdepartment of A.S....
-
Contract Specialist
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Huawei Full time 40,000 - 60,000 per yearAbout HuaweiHuawei is a leading global provider of information and communications technology (ICT) infrastructure and smart devices. With integrated solutions across four key domains – telecom networks, IT, smart devices, and cloud services – we are committed to bringing digital to every person, home and organization for a fully connected, intelligent...