Hiring.Camp

DORA Implementataion and Oversight Analyst

Theapexgroup

·

Today

Location
Pune - Baner, India
Type
Full-time
Experience
5+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.

Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.

That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.

Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.

For our business, for clients, and for you

The DORA Implementation & Oversight Analyst the implementation, maintenance and continuous improvement of the DORA governance and control framework across the relevant Apex entities in scope. 

The role operates across all European entities of the Apex Group subject to DORA, ensuring a consistent, pragmatic, and well-governed approach to ICT governance, ICT risk management, ICT third-party oversight, incident governance, resilience documentation, and regulatory evidence. 

This role focuses on governance, stakeholder coordination, compliance monitoring, documentation management, and management reporting. The successful candidate will work closely with technology, risk, compliance, business, and support functions to help ensure that regulatory obligations, governance activities, and remediation actions are effectively tracked, documented, and reported. 

The Analyst reviews the completeness and consistency of DORA documentation, provides constructive challenge within the authority of the role, and escalates material gaps, delays or inconsistencies through the appropriate governance channels. 

This position is ideal for professionals with backgrounds in compliance, risk management, internal audit, operational risk, IT governance, regulatory reporting, or program coordination who are looking to develop expertise within a regulated financial services environment. 

Job Specification and key responsibilities 

DORA framework implementation and maintenance 

  • Support the implementation, maintenance and periodic review of the DORA governance and control framework across the in-scope Luxembourg entities. 

  • Coordinate DORA gap assessments, implementation plans, remediation roadmaps and supporting evidence. 

  • Maintain the consolidated DORA implementation roadmap, clearly identifying accountable owners, milestones, dependencies and target dates. 

  • Support the drafting and review of DORA-related policies, procedures, controls, methodologies, standards, templates and guidance. 

  • Coordinate the incorporation of entity-specific requirements into Group frameworks and identify where local adaptations or supplementary controls are required. 

  • Monitor relevant regulatory developments and prepare documented impact assessments and implementation recommendations. 

  • Promote consistent terminology, documentation standards, evidence requirements and control design across the in-scope entities. 

ICT Risk and Control governance 

  • Review the completeness and consistency of ICT risk assessments, control assessments, risk registers, risk-treatment plans and documented risk acceptances. 

  • Coordinate with first-line teams, second-line functions and other control functions to support consistent implementation and evidence standards. 

  • Escalate material gaps, high-risk exposures, recurring deficiencies and significant delays through the appropriate governance channels. 

Register of Information and ICT third-party governance 

  • Coordinate the preparation, maintenance, reconciliation and quality review of the DORA Register of Information across the in-scope Luxembourg entities. 

  • Monitor DORA-related requirements concerning ICT third-party arrangements supporting critical or important functions. 

Outsourcing and ICT third-party oversight 

  • Support oversight of ICT third-party arrangements and applicable DORA contractual and governance requirements. 

  • Monitor the availability and quality of due diligence, risk assessments, contractual assessments, approvals and supporting evidence. 

  • Monitor concentration risk, subcontracting arrangements, service continuity measures, exit strategies and termination plans. 

  • Support the identification and remediation of material contractual or governance gaps. 

  • Escalate material contractual deficiencies, overdue remediation and unsupported risk decisions. 

Digital operational Resilience Testing 

  • Support the planning, coordination and monitoring of the digital operational resilience testing program. 

  • Support a consolidated overview of planned and completed tests, scope, critical functions covered, findings, evidence, action owners and remediation dates. 

  • Monitor testing activities including business continuity exercises, disaster recovery tests, backup restoration tests, scenario-based testing, vulnerability assessments and penetration testing. 

  • Support the coordination and governance of threat-led penetration testing where applicable. 

  • Monitor whether material changes, incidents or identified weaknesses trigger additional testing or reassessment. 

Audit, evidence, and regulatory readiness 

  • Maintain an audit-ready evidence repository covering DORA implementation, governance, third-party oversight, and remediation status. 

  • Support preparing concise and high-quality documentation for supervisory interactions and internal governance reporting. 

Governance, management reporting and escalation 

  • Maintain the DORA action tracker, risk and issue log, decision log and escalation log. 

  • Report progress, dependencies, emerging risks, overdue actions and management decisions across the in-scope entities. 

  • Escalate high-risk control gaps, regulatory deadline risks, unresolved classification issues and persistent owner non-delivery. 

Key deliverables 

  • Consolidated DORA implementation and maintenance roadmap. 

  • DORA action tracker and remediation dashboard. 

  • Register of Information coordination, validation and quality-assurance records. 

  • Digital operational resilience testing overview and findings tracker. 

  • DORA policy and procedure review log. 

Required Qualifications 

  • Bachelor's degree in Business Administration, Risk Management, Information Systems, Law, Compliance, or a related field. 

Skills Required 

  • 5+ years of experience in one or more of the following areas:  

  • Compliance 

  • Risk Management 

  • Internal Audit 

  • Operational Risk 

  • IT Governance 

  • Regulatory Reporting 

  • Good knowledge of ICT risk management, ICT third-party / outsourcing governance, and control documentation 

  • Strong coordination, tracking, and stakeholder management skills 

  • Ability to interpret regulatory requirements and translate them into practical governance arrangements, controls, documentation and actions. 

  • Strong drafting and reporting skills, with the ability to prepare management-ready and audit-ready material 

  • Fluent English 

  • Experience coordinating cross-functional initiatives and managing action trackers. 

  • Strong written and verbal communication skills in English. 

  • Experience preparing reports, presentations, or management information. 

  • Strong organizational and stakeholder management skills. 

The role holder is expected to demonstrate: 

  • Regulatory awareness and curiosity. 

  • Analytical and structured thinking. 

  • Strong attention to detail. 

  • Clear and concise drafting. 

  • Evidence-based and risk-based judgement. 

  • Accountability for assigned deliverables. 

  • Strong stakeholder coordination. 

  • Ability to work across multiple functions and legal entities. 

Regulatory knowledge 

  • Good working knowledge of DORA and its application to ICT risk management, ICT incident reporting, digital operational resilience testing and ICT third-party risk. 

  • Familiarity with relevant DORA Regulatory Technical Standards, Implementing Technical Standards and ESA guidance. 

Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.

Skills

Penetration TestingRisk ManagementCompliance