Hiring.Camp

ICT Risk Governance & Oversight - Assistant Vice President

Statestreet

·

Yesterday

Location
BIG - Zielinskiego Krakow, Poland · Gdansk, Poland
Type
Full-time
Seniority
VP
Experience
4+ years
Education
Master
Closing date
Today
Source
Workday

Description

Who we are looking for

We are looking for an ICT Risk Governance & Oversight Assistant Vice President (AVP) to support the SSBI ICT Risk Manager in the independent oversight, governance, challenge, monitoring and reporting of Information and Communication Technology (ICT) risks across State Street Bank International (SSBI). In this role, you will operate within the Second Line of Defense and contribute to the ongoing development and enhancement of the SSBI ICT Risk Management Framework, supporting compliance with the Digital Operational Resilience Act (DORA), related regulatory standards and applicable supervisory expectations.

You will work closely with Enterprise Technology Risk Management, Third Party Risk Management, Information Security, Operational Resilience, Technology, Outsourcing Governance and other control functions to ensure effective identification, assessment, monitoring and reporting of ICT risks across SSBI. The role does not own or operate ICT systems, ICT controls, information security operations or technology services. In addition to ICT risk responsibilities, you may also support broader Operational Risk Management activities across SSBI, including risk assessments, governance reporting, operational resilience, new business reviews, outsourcing oversight, regulatory engagement and other ORM initiatives, as required.

Why this role is important to us

The team you will be joining plays an important role in strengthening SSBI’s ICT risk governance, operational resilience and regulatory compliance. Across the globe, institutional investors rely on State Street to help them manage risk, respond to challenges and drive performance. Regulators rely on us to demonstrate that the bank operates in a resilient, well-controlled and compliant manner. In this role, you will help provide independent oversight and challenge of ICT risk management activities, support effective governance and reporting, and contribute to the firm’s ability to manage technology and operational resilience risks. Join us if making your mark in financial services from day one is a challenge you are up for.

What you will be responsible for

As an ICT Risk Governance & Oversight Assistant Vice President, you will:

Support the maintenance and continuous enhancement of the SSBI ICT Risk Management Framework, ensuring alignment with DORA, operational resilience requirements and enterprise risk management frameworks.

  • Prepare materials and analysis for ICT governance committees, management forums and senior management reporting.

  • Perform independent review and challenge of ICT risk assessments, control evaluations, risk acceptance decisions and supporting first-line evidence.

  • Escalate emerging ICT risk concerns, weaknesses and thematic observations to the ICT Risk Manager and ORM leadership, including proposed considerations where appropriate.

  • Support the development, maintenance, monitoring and reporting of ICT risk appetite metrics, thresholds and Key Risk Indicators.

  • Produce risk reporting, trend analysis and management information for senior stakeholders, including documentation supporting regulatory demonstrations of ICT risk governance effectiveness.

  • Support oversight and challenge of ICT control testing, resilience testing, scenario testing and threat-led testing outputs from a risk governance perspective.

  • Review management responses, remediation activities, root-cause analyses, lessons learned and corrective action plans arising from ICT incidents, testing exercises and technology-related operational events.

  • Support second-line oversight activities relating to ICT third-party and outsourcing risk, including review of related risk assessments, governance artefacts and reporting.

  • Assist in monitoring regulatory developments relating to DORA, ICT risk, cybersecurity and operational resilience, and support responses to regulatory reviews, audits and supervisory requests.

  • Contribute to broader SSBI Operational Risk Management activities, including LERA, RCSA, SAOR, TRA, new business reviews, outsourcing oversight, operational resilience initiatives, regulatory and audit engagements, policy development and risk committee reporting.

What we value

These skills will help you succeed in this role:

  • Strong analytical and risk assessment capabilities, with the ability to interpret regulatory requirements and translate them into practical oversight activities.

  • Good understanding of DORA, ICT risk management, cybersecurity risk, operational resilience and outsourcing or third-party ICT risk frameworks.

  • Understanding of risk management principles within the Three Lines of Defense model.

  • Ability to provide effective and constructive second-line challenge based on evidence and sound judgement.

  • Excellent written and verbal communication skills, with strong stakeholder management and influencing capabilities.

  • Strong attention to detail and the ability to manage multiple priorities across regulatory, operational and strategic initiatives.

  • Team-oriented approach with the ability to work effectively across international and cross-functional environments.

Education & Preferred Qualifications

  • 4-8 years of experience in ICT Risk Management, Operational Risk Management, Information Security Risk, Operational Resilience, Technology Controls, Internal or External Audit, or Regulatory Risk Management.

  • Experience within financial services or another highly regulated industry preferred.

  • Bachelor’s or Master’s degree in Risk Management, Information Technology, Information Security, Finance, Business Administration or a related discipline.

  • Good awareness of EBA ICT and security risk management guidelines and outsourcing expectations.

  • Professional certifications such as CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor or Lead Implementer, CIA, RIMS-CRMP, FRM or equivalent are preferred.

  • Demonstrated experience may be accepted in lieu of formal certification.

  • Good understanding of DORA and related ICT risk management requirements.

  • Familiarity with ICT governance, cybersecurity risk, operational resilience and outsourcing/ third-party ICT risk frameworks.

  • Understanding of risk management principles within the Three Lines of Defense model.

  • Awareness of EBA ICT and security risk management guidelines and outsourcing expectations.

  • Bachelor's or Master's degree in Risk Management, Information Technology, Information Security, Finance, Business Administration or a related discipline.

  • CRISC, CISA, CISM, CISSP or equivalent ICT Risk / Information Security certification.

  • ISO 27001 Lead Auditor or Lead Implementer certification desirable.

  • Operational Risk, Audit or Governance certifications (e.g., CIA, RIMS-CRMP, FRM, ORM-related qualifications) advantageous.

  • Demonstrated experience may be accepted in lieu of formal certification.

Note: The role requires a minimum of 3 days per week working from the office

Minimum Salary:

zł182 004 Annual

The minimum salary quoted above applies to the role in the primary location specified. If the candidate ultimately works outside of this primary location, the applicable minimum salary may differ.​

Salary will be determined based on factors such as the position, type of work performed, individual skills, job description, working hours, diligence, initiative, self-management, length of employment, availability, and the quantity and quality of work delivered, as well as other objective and non-discriminatory criteria relevant to State Street employees.​

In addition to salary, employees are eligible to be considered for discretionary annual performance-based awards.​

We Offer:

  • Permanent contract from day one​

  • Additional holidays (Birthday Day Off, 3rd and 5th year anniversary Day Off)​

  • Gold Medical Package for employees and their families (partner and children)​

  • Premium life insurance package and private pension plan​

  • Wide range of soft skills training, technical workshops, language classes and development programs​

  • Opportunities to volunteer your time to company-driven initiatives, employee networks or organizations of your choice​

  • Variety of well-being programs​

  • Additional benefits available depending on the seniority of the role

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

State Street's Speak Up Line

Załącznik do standardu Whistleblowing i Speak Up SSBI GmbH dla Oddziału w Polsce

Skills

CybersecurityRisk ManagementComplianceISO 27001CISSP