Job description
The final candidate will perform the following activities:
Governance & steering:**
- Perform recurrent meetings with Asset Management Companies to monitor the execution of the ICT Risk management activities
- Consolidate on a quarterly basis the results of the ICT Risk Management activities at GIH level and report the results to GIH Risk and Control Committee
- Prepare annual consolidated reporting for GIH Board of Directors on the evolution of the ICT Risk management framework and its operating effectiveness
- Support the design, implementation and maintenance of the overall ICT Risk Management Framework
- Coordinate the Local CRO of newly acquired Group Asset Manager for the implementation of the ICT Risk framework
ICT Risk Management:
- Identifying and updating ICT & Cyber risk events related to business area managed
- Reviewing ICT & Cyber risk Scenarios based on its peculiarities
- Execute quantitative and qualitative risk methodologies
- Performing the economic quantification of ICT and Security Major incidents to evaluate DORA relevance
- Setting of ICT Risk Appetite Framework together with CISO and COO
- Analyzing of Operative risk tolerances quarterly evidence monitoring collected and defined mitigation actions
- Overseeing escalation process in case of hard limits breach and formalizing detailed risk evaluation
- Reviewing reports and evidence shared by IT and Security functions (e.g., Backup and restore reports, Vulnerability assessments)
- Formalizing executive reporting providing update on ICT Risk Management Framework risk evidence and key enhancements
- Formalizing and annual Reviewing ICT & Cyber Risk reports (e.g., ICT & Cyber Risk Report and IT Booklet)