Cloud Risk and Cyber Security Senior Officer

Há 6 horas


Lisboa, Portugal BNP Paribas Tempo inteiro

**About the job**

This role is in alignment with 2LoD involvement required on BNP Paribas dedicated hybrid Cloud that is core of Cloud Strategy. The scope of the role involves developing, implementing and managing:
1) Cloud technology risk and operational risk management framework including Cloud security controls, operational risk management procedures, standards and processes for identifying, assessing, monitoring, reporting and mitigating operational risks related to dedicated Cloud.

2) Periodic and ad hoc reviews of cloud security controls to ensure they are integrated and operating effectively by the cloud security risk profile solutions

3) Cloud risk register with Cloud security control and risk assessments integrated for Cloud risk reporting to CROs, operational risk officers of poles and entities, IT Group Cloud and Cloud security teams, Cloud service providers, internal and external auditors on operational risk matters.

**Your Main Activities Are**

Lead and coordinate Cloud technology and operational risk identification, assessment, monitoring, reporting and mitigation activities for the dedicated Cloud using appropriate tools and methodologies

Develop and maintain the Cloud technology and operational risk management framework, policies, standards, procedures and controls for the Dedicated Cloud services in alignment with BNP Paribas 1LoD and 2LoD risk management policies

Coordinate and manage the Cloud technology and risk governance structure including committees, forums and reporting lines for the Dedicated Cloud services

Periodic (weekly, monthly, quarterly, half yearly, annual) and ad hoc reports and dashboards on the Cloud technology and operational risk profile, trends, issues, incidents and remediation action plans for the dedicated Cloud services to senior management, risk management committees, supporting regulatory reporting, internal and external auditors

Provide Cloud security expert advice and guidance to CRO, operational risk officers, IT Group Cloud program, Group CISO, IT Group production teams, cloud service providers, internal and external auditors on Cloud technology and operational risk matters including risk assessments, controls, testing, audits and remediation

Participate in multiple Group Cloud program and operations governance committees for Cloud security controls and risk management with Operational Risk officers, IT Group Cloud Program, Group CISO, IT Group Production teams, Cloud service provider, Independent Software Vendors (ISVs) etc. covering topics of Cloud security & ICT risks, Cloud adoption, operational security, remediation actions, etc

Coordinate with operational risk officers of poles and entities for move to Cloud technology and operational risks

Review and update minimum baseline Cloud security controls in collaboration with IT Group Production security teams, Cloud security experts, Operational risk officers, ICT risk officers, etc

Review and update process and workflow for monitoring and reporting of compliance to minimum baseline dedicated hybrid Cloud security controls on Cloud security posture management solutions in collaboration with IT Group Production teams, Cloud service provider, ICT risk officers, operational risk officers, etc

Develop and identify and update risk reporting methods using automated solutions, leveraging existing or new solutions of Governance, Risk and Compliance (GRC) tools for dedicated hybrid Cloud services asset register, risk register, remediation tracking, etc. Cloud Security Posture Management solutions, operational risk management solutions, IT service management solutions, reporting & dashboard solutions, etc

Overall high quality report writing, documentation and presentation for dedicated hybrid Cloud security topics of operational risk frameworks and operating models, cloud security baseline controls, identifying control gaps, residual risks, questions to identify root causes, risk implications, short term and long term remediation measures, recommendations and appropriate risk opinions

**Profile and Skills to Success**

Good knowledge of ICT risks, IT Control, Information Security, Business Continuity, IT operations and IT Audit and assessment methodologies and concepts

Experience working with ICT risks, business continuity, IT Management and operations, IT risk and IT audit teams

Ability to articulate risk management concepts in business language

Excellent written and verbal communication (English)

Proficient with Microsoft Office Suite

Prior experience documenting tool requirements to support risk management

Ability to travel to BNP Paribas and vendor sites, and perform assessments as necessary

Proven ability to manage issues through to resolution; skilled at making judgment calls

Ability to successfully multitask and complete difficult assignments within deadlines which may have short lead times

Industry certifications (e.g. CISA, CRISC, COBIT) or willingness to obtain the same

Works itera



  • Lisboa, Portugal BNP Paribas Tempo inteiro

    CLOUD RISK AND CYBER SECURITY SENIOR OFFICER (JOB NUMBER: 2402RSK17645_L) **About the job** - This role is in alignment with 2LoD involvement required on BNP Paribas dedicated hybrid Cloud that is core of Cloud Strategy. The scope of the role involves developing, implementing and managing: 1) Cloud technology risk and operational risk management framework...


  • Lisboa, Lisboa, Portugal Coda Technology Services Tempo inteiro

    **About Us**Coda Technology Services is a global Engineering organisation dedicated to delivering innovative solutions.**Job Description**We are seeking a highly skilled Cyber Security / Risk Management Lead to establish a robust risk management function. This role will be based in Portugal and will require occasional site/office visits to Lisbon.**Key...


  • Lisboa, Portugal CODA Technology Services Tempo inteiro

    We are seeking a Cyber Security / Risk Management Lead on an initial 6 month contract basis to establish a robust risk management function for a global Engineering organisation. This role will be be based in Portugal - hybrid with with occasional site/office visits to Lisbon. Key Responsibilities Develop and implement a comprehensive cyber risk management...


  • Lisboa, Portugal Coda Technology Services Tempo inteiro

    We are seeking a Cyber Security / Risk Management Lead on an initial 6 month contract basis to establish a robust risk management function for a global Engineering organisation.This role will be be based in Portugal - hybrid with with occasional site/office visits to Lisbon.Key Responsibilities Develop and implement a comprehensive cyber risk management...


  • Lisboa, Portugal Coda Technology Services Tempo inteiro

    We are seeking a Cyber Security / Risk Management Lead on an initial 6 month contract basis to establish a robust risk management function for a global Engineering organisation. This role will be be based in Portugal - hybrid with with occasional site/office visits to Lisbon. Key Responsibilities Develop and implement a comprehensive cyber risk management...


  • Lisboa, Portugal Deco Proteste Tempo inteiro

    Working at Group level the **Information Security Officer **will have an impact in the protection of the organization's information by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. **About the role** Reporting to the Group Business Technology Director this...


  • Lisboa, Portugal Nordea Bank Norge Asa Tempo inteiro

    Senior Data, IT Information Security Officer Specialist Job ID: 25353 We are looking for a Senior Information Security Specialist to join the Information Security function in Nordea Asset Management.As a Senior Information Security Specialist you will play a vital role in embedding information security practices, controls and culture within Nordea Asset...


  • Lisboa, Lisboa, Portugal Phiture Tempo inteiro

    At Phiture, we're committed to innovation and technology leadership across mobile, fixed and cloud networks. As a Cyber Security Specialist for Threat Detection and Prevention, your career will have a positive impact on people's lives and help us build the capabilities needed for a more productive, sustainable, and inclusive world.About Our TeamWe challenge...


  • Lisboa, Portugal Robert Walters Plc Tempo inteiro

    Our client is an international bank specialising in private banking and corporate investment.They're looking for an ICT and Security Risk Officer to join their team in Lisbon.In this role, you'll focus on managing ICT and information security risks, overseeing third-party ICT service providers, conducting operational resilience tests, supporting the Business...


  • Lisboa, Lisboa, Portugal Nokia Tempo inteiro

    Nokia is committed to innovation and technology leadership across mobile, fixed, and cloud networks. Our strategy and technology vision lays the path for Nokia's future technology innovation and identifies the most promising areas for Nokia to create new value.Our Cyber Security ApproachWe take a proactive approach to cyber security, partnering with our...


  • Lisboa, Portugal KPMG Tempo inteiro

    **Ref.** - 0000000152 **Função** - Cyber Security Manager **Localidade** - Lisboa **Descrição**: **Requisitos**: **Oferta**: WHO WE ARE KPMG is a global network of professional services firms providing Audit, Tax and Advisory services, currently operating in 146 countries with more than 227.000 people around the world. In Portugal, with offices in...


  • Lisboa, Portugal KPMG Tempo inteiro

    Ref. - 0000000152 - **Função**: - Cyber Security Manager - Localidade - Lisboa **Descrição**:. **Requisitos**:. **Oferta**: WHO WE ARE KPMG is a global network of professional services firms providing Audit, Tax and Advisory services, currently operating in 146 countries with more than 227.000 people around the world. In Portugal, with offices in...


  • Lisboa, Portugal Michael Page Tempo inteiro

    Join a Consumer Services company Join a dynamic team Sobre o nosso cliente Our client is a Consumer Services Multinational Group.Descrição IT Security Framework: Development, implementation and maintenance of security policies, standards, and procedures aligned with industry best practices, regulatory requirements and internal guidelines (aligned with Data...


  • Lisboa, Portugal Michael Page Tempo inteiro

    Sobre o nosso cliente Our client is a Consumer Services Multinational Group. Descrição - IT Security Framework: Development, implementation and maintenance of security policies, standards, and procedures aligned with industry best practices, regulatory requirements and internal guidelines (aligned with Data Security Officer); - Risk Assessment &...


  • Lisboa, Portugal Boost It Tempo inteiro

    We are BYT, a specialized tech recruitment company launched in December 2021, with the ambition of achieving success for over 3 years, coupled with an experienced management team of over 15 years.During this time, we successfully delivered more than 400 specialized recruitment processes for 20 clients in Portugal and internationally.Our expertise stems from...


  • Lisboa, Portugal Boost It Tempo inteiro

    We are BYT, a specialized tech recruitment company launched in December 2021, with the ambition of achieving success for over 3 years, coupled with an experienced management team of over 15 years.During this time, we successfully delivered more than 400 specialized recruitment processes for 20 clients in Portugal and internationally.Our expertise stems from...

  • Cybersecurity Officer

    Há 6 horas


    Lisboa, Portugal askblue Tempo inteiro

    **Askblue **is looking for an **Cybersecurity Officer **that will: - Identity & Access Management (IAM) - Cyber Security Incident - Cyber Project Manager **Technical Skills**: - Strong knowledge on Identity and Access Management and/or Cyber Security Incident - Good knowledge of Cloud environment - Good knowledge of Microsoft Office suite, PowerBi - NIST,...


  • Lisboa, Portugal N2 Technology Tempo inteiro

    What will you do: - Lead a skilled multi-discipline cyber security team, ensuring the appropriate operating model is adopted. - Attract & retain talent, leading the cyber security team to continually evolve & improve. - Build strong relationships to support a collaborative and agile approach to achieving security goals, including internal squads, third...

  • IT Security Officer

    Há 2 dias


    Lisboa, Portugal Sterlington, PLLC Tempo inteiro

    **Position Title**:IT Security Officer - remote **Contract**:Full-time, Independent Contractor **Location**:100% remote working **Description**: A well-established and growing international law firm is looking for an IT Security Officer to support our growing team. **Our Firm**: **The Role**: - Advise and assess system design/architecture as well as...


  • Lisboa, Portugal 1Global Tempo inteiro

    Welcome to 1GLOBAL, a dynamic and innovative force in the intersection of telecommunications and technology. Founded by two visionary technology entrepreneurs, Hakan Koç and Pyrros Koussios, 1GLOBAL is a privately owned company with a clear mission to connect the world, seamlessly. With over 100 million dollars in revenue and being both profitable and cash...