IT Risk and Cyber Security Senior Officer

2 semanas atrás


Porto, Portugal BNP Paribas Tempo inteiro

IT RISK AND CYBER SECURITY SENIOR OFFICER (JOB NUMBER: 2402RSK17645)

**About the job**
- This role is in alignment with 2LoD involvement required on BNP Paribas dedicated hybrid Cloud that is core of Cloud Strategy. The scope of the role involves developing, implementing and managing:
1) Cloud technology risk and operational risk management framework including Cloud security controls, operational risk management procedures, standards and processes for identifying, assessing, monitoring, reporting and mitigating operational risks related to dedicated Cloud.

2) Periodic and ad hoc reviews of cloud security controls to ensure they are integrated and operating effectively by the cloud security risk profile solutions

3) Cloud risk register with Cloud security control and risk assessments integrated for Cloud risk reporting to CROs, operational risk officers of poles and entities, IT Group Cloud and Cloud security teams, Cloud service providers, internal and external auditors on operational risk matters.

**Your Main Activities Are**
- Lead and coordinate Cloud technology and operational risk identification, assessment, monitoring, reporting and mitigation activities for the dedicated Cloud using appropriate tools and methodologies
- Develop and maintain the Cloud technology and operational risk management framework, policies, standards, procedures and controls for the Dedicated Cloud services in alignment with BNP Paribas 1LoD and 2LoD risk management policies
- Coordinate and manage the Cloud technology and risk governance structure including committees, forums and reporting lines for the Dedicated Cloud services
- Periodic (weekly, monthly, quarterly, half yearly, annual) and ad hoc reports and dashboards on the Cloud technology and operational risk profile, trends, issues, incidents and remediation action plans for the dedicated Cloud services to senior management, risk management committees, supporting regulatory reporting, internal and external auditors
- Provide Cloud security expert advice and guidance to CRO, operational risk officers, IT Group Cloud program, Group CISO, IT Group production teams, cloud service providers, internal and external auditors on Cloud technology and operational risk matters including risk assessments, controls, testing, audits and remediation
- Participate in multiple Group Cloud program and operations governance committees for Cloud security controls and risk management with Operational Risk officers, IT Group Cloud Program, Group CISO, IT Group Production teams, Cloud service provider, Independent Software Vendors (ISVs) etc. covering topics of Cloud security & ICT risks, Cloud adoption, operational security, remediation actions, etc
- Coordinate with operational risk officers of poles and entities for move to Cloud technology and operational risks
- Review and update minimum baseline Cloud security controls in collaboration with IT Group Production security teams, Cloud security experts, Operational risk officers, ICT risk officers, etc
- Review and update process and workflow for monitoring and reporting of compliance to minimum baseline dedicated hybrid Cloud security controls on Cloud security posture management solutions in collaboration with IT Group Production teams, Cloud service provider, ICT risk officers, operational risk officers, etc
- Develop and identify and update risk reporting methods using automated solutions, leveraging existing or new solutions of Governance, Risk and Compliance (GRC) tools for dedicated hybrid Cloud services asset register, risk register, remediation tracking, etc. Cloud Security Posture Management solutions, operational risk management solutions, IT service management solutions, reporting & dashboard solutions, etc
- Overall high quality report writing, documentation and presentation for dedicated hybrid Cloud security topics of operational risk frameworks and operating models, cloud security baseline controls, identifying control gaps, residual risks, questions to identify root causes, risk implications, short term and long term remediation measures, recommendations and appropriate risk opinions

**Profile and Skills to Success**
- Good knowledge of ICT risks, IT Control, Information Security, Business Continuity, IT operations and IT Audit and assessment methodologies and concepts
- Experience working with ICT risks, business continuity, IT Management and operations, IT risk and IT audit teams
- Ability to articulate risk management concepts in business language
- Excellent written and verbal communication (English)
- Proficient with Microsoft Office Suite
- Prior experience documenting tool requirements to support risk management
- Ability to travel to BNP Paribas and vendor sites, and perform assessments as necessary
- Proven ability to manage issues through to resolution; skilled at making judgment calls
- Ability to successfully multitask and complete difficult assignments within deadlines which may have short lead times
- Ind


  • IT Risk

    4 semanas atrás


    Porto, Portugal askblue Tempo inteiro

    **Do you know AskBlue?** We were born in 2013, and we provide information technology consulting services. We are looking for a **IT Risk & Cyber security - Project Manager** to join a project in a client based in Lisbon or Porto (banking area). As Project Manager You will have to coordinate several streams of the WM Cyber Security program with various...

  • Information Security Officer

    2 semanas atrás


    Porto, Portugal Euronext Tempo inteiro

    Information Security Officer - Governance, Risk and Compliance page is loaded Information Security Officer - Governance, Risk and Compliance Apply locations Porto time type Full time posted on Posted 2 Days Ago job requisition id R15459 Key accountabilities Assisting with the implementation and maintenance of the Information Security Programme; Assisting...

  • Information Security Officer

    4 semanas atrás


    Porto, Portugal Euronext Tempo inteiro

    Key accountabilities - Assisting with the implementation and maintenance of the Information Security Programme; - Assisting with efforts to align internal security practices with industry best practices and security frameworks commensurate with strategy and the expectations of our clients and regulators; - Stay abreast of the threat landscape specific to...

  • Information Security Officer

    4 semanas atrás


    Porto, Portugal Hexa People Tempo inteiro

    What you can expectOur client is a prominent financial marketplace operating across multiple countries in Europe. It facilitates the trading of various financial instruments such as stocks, derivatives, commodities, and exchange-traded funds.What you will be doingAssist in implementing and maintaining the Information Security Programme.Assist efforts to...

  • IT Risk Analyst

    4 semanas atrás


    Porto, Portugal Natixis in Portugal Tempo inteiro

    Company Description Natixis is part of the Global Financial Services business unit, the global arm of Groupe BPCE, specialized in Asset & Wealth Management and Corporate & Investment Banking and counts nearly 16,000 employees across 38 countries. The Groupe BPCE, the second-largest banking group in France through its two retail banking networks, Banque...


  • Porto, Portugal KANTAR Tempo inteiro

    We go beyond the obvious, using intelligence, passion and creativity to inspire new thinking and shape the world we live in. To start a career that is out of the ordinary, please apply... Job Details Business Information Security Officer (BISO) | Worldpanel & EBS The Business Information Security Officer (BISO) is the cyber and risk lead for their...

  • Information Security Officer

    4 semanas atrás


    Porto, Portugal Euronext Tempo inteiro

    Key accountabilitiesAssisting with the implementation and maintenance of the Information Security Programme;Assisting with efforts to align internal security practices with industry best practices and security frameworks commensurate with strategy and the expectations of our clients and regulators;Stay abreast of the threat landscape specific to Euronext and...

  • Information Security Officer

    4 semanas atrás


    Porto, Portugal Mindera Tempo inteiro

    Here at Mindera, we are building a world class team and would love it for you to join us. As an Information Security Officer, you’ll be able to research, develop, implement, test and review Mindera’s Security policies in order to protect information and prevent unauthorised access to all of our projects, all while making sure you have fun learning,...


  • Porto, Portugal Körber Porto, Unipessoal Lda. Tempo inteiro

    Senior Security Operations Engineer As a Security Engineer, drive innovation to ensure continuous security and play a pivotal role in strengthening our defenses. Proactively address security incidents and vulnerabilities while delivering consistent solutions to secure our application stacks and fortify our IT infrastructure against evolving threats. ...


  • Porto, Portugal Dellent Tempo inteiro

    **Requirements**: - Relevant cybersecurity experience, ideally in the Rail Industry or a similar; - Identifying system security requirements, performing threat modelling; - Security architecture reviews and system security testing; - Experienced in IT/OT engineering methodologies; - Define systems cybersecurity architecture & design principles; -...

  • Senior Credit Risk Officer

    4 semanas atrás


    Porto, Portugal Natixis in Portugal Tempo inteiro

    Company Description Natixis in Portugal is fully integrated in the global organization of Natixis, a French multinational financial services firm specialized in Asset & Wealth Management, Corporate & Investment Banking, Insurance and Payments. A subsidiary of Groupe BPCE, Natixis counts nearly 16.000 employees across 38 countries. Based in Porto, Natixis...

  • IT Security Engineer

    4 semanas atrás


    Porto, Portugal Mindpal Tempo inteiro

    We are looking for IT Security Engineer Responsibilities:Implementation, management, and monitoring of IT security measures and protections within the organizationAnalysis and evaluation of potential threats, designing and implementing security solutionsMonitoring IT infrastructure to identify security vulnerabilities and taking appropriate corrective...


  • Porto, Portugal Unilabs Tempo inteiro

    The Internal Audit Department provides the Audit Committee of the Board of Directors with an independent and objective assessment of the reliability and integrity of financial and select operating information, the effectiveness and efficiency of Unilabs and its consolidated subsidiaries’ (systems and internal controls, and compliance with the Company’s...


  • Porto, Portugal Farfetch Tempo inteiro

    Senior Security Incident Response AnalystTHE ROLE We are looking for a passionate expert to join our security team who loves to reveal potential weaknesses and then think of creative solutions to eliminate any issues. Your expertise is key in building the foundation of security projects that protect the security and privacy of our clients. People will rely...

  • Senior IT Internal Auditor

    4 semanas atrás


    Porto, Portugal Unilabs Tempo inteiro

    The Internal Audit Department provides the Audit Committee of the Board of Directors with an independent and objective assessment of the reliability and integrity of financial and select operating information, the effectiveness and efficiency of Unilabs and its consolidated subsidiaries’ (systems and internal controls, and compliance with the Company’s...

  • Credit Risk Officer

    4 semanas atrás


    Porto, Portugal Natixis in Portugal Tempo inteiro

    Company Description Natixis in Portugal is fully integrated in the global organization of Natixis, a French multinational financial services firm specialized in Asset & Wealth Management, Corporate & Investment Banking, Insurance and Payments. A subsidiary of Groupe BPCE, Natixis counts nearly 16.000 employees across 38 countries. Based in Porto, Natixis...


  • Porto, Porto, Portugal KWAN Tempo inteiro

    At KWAN, we don't just offer jobs - we provide platforms for growth, harnessing your unique skills, passions, and professional background to place you in a project that lets your talents shine. But we don't stop there: we provide continuous support throughout your career journey, collaborating and evolving together, constructing a brighter future one step at...

  • Biso, Profiles and Insights

    4 semanas atrás


    Porto, Portugal KANTAR Tempo inteiro

    Kantar is the world’s leading marketing data and analytics company. We have a complete, unique and rounded understanding of how people think, feel and act; globally and locally in over 90 markets. By combining the deep expertise of our people, our data resources and benchmarks and our innovative analytics and technology, we help our clients understand...


  • Porto, Portugal mgm security partners Tempo inteiro

    With our colleagues in Munich, Berlin, Dresden, Cologne and Đà Nẵng (Vietnam), we maintain a** family atmosphere **in which everyone contributes their** individual strengths and interests**. Our focus on security and the large number of customer inquiries constantly present us with new challenges. In order to master these together, we are looking for...

  • Security Data Analyst

    4 semanas atrás


    Porto, Portugal askblue Tempo inteiro

    We operate as a consulting service firm since 2013 and offer specialized consulting services to clients In the areas of finance and information technology. We are currently looking for **Security Data Analyst** to integrate one of our project teams in **Lisbon **or **Porto**. **Main Responsibilities**: - Contribute to produce the vulnerability remediation...