In this role you will become the primary operational owner of the ICT Risk Management Framework within the second line of defence. In this role, you will be responsible for the day-to-day execution, monitoring, and reporting of ICT risk and information security activities in line with DORA, ISO 27001, and PCI DSS requirements.
Furthermore you will become responsible for:
- Maintaining and developing the ICT risk register, executing the RCSA cycle for ICT risk domains, and monitoring key ICT controls including KRI dashboard management
- Owning the ISMS policy suite in line with ISO 27001, DORA, and document standards, and coordinating security monitoring oversight from a 2LoD perspective
- Supporting DORA Chapter II obligations including ICT incident classification and major incident reporting, and monitoring the external threat landscape to translate developments into 2LoD risk signals
- Leading PCI DSS 2LoD governance as primary owner of PCI DSS v4.0 compliance oversight, coordinating PCI-3DS as a separate project stream, and acting as primary contact for QSA and internal stakeholders
- Owning the Eramba GRC platform including data structure, user access, and module configuration, and driving its rollout to new modules and processes as the ICT risk framework matures
- Providing second line of defence oversight of ICT third-party risk, acting as primary liaison for the annual EY IT audit, and supporting the annual Group IT risk reporting cycle.