EU remote
CYBER & INFORMATION SECURITY AND ICT RISK OFFICER (DEPUTY) (f/m/d)
About this role
As Deputy Cyber & Information Security and ICT Risk, you support the oversight and further development of 360T’s Cyber & Information Security and ICT Risk framework. In this Second Line of Defense role, you provide independent oversight, challenge and advice while supporting operational and regulatory excellence across the 360T Group. You act as a deputy to the responsible function lead and provide support and coverage across key governance, risk and oversight activities.
Our approach is based on full compliance in both word and spirit, continuous assessment of regulatory, legal and technological developments, constructive engagement with regulators and market participants, and the conviction that operational and regulatory excellence is a key competitive advantage. Strategy & Governance Support the development and continuous enhancement of the Group’s Cyber & Information Security and ICT Risk strategy, policies and oversight framework in alignment with 360T’s business strategy.
Help ensure alignment with applicable legal and regulatory requirements, established standards and relevant industry best practices. Support the translation of regulatory requirements, business objectives and risk considerations into appropriate governance and oversight measures. Contribute to regular reporting to Management and relevant governance bodies on the risk profile, First Line roadmaps, control environment, testing activities and significant incidents.
Deputize for the responsible function lead in relevant committees, meetings and governance activities as required. Identify and assess emerging ICT and cyber risks and recommend appropriate mitigation, challenge or escalation. Organization & Risk Oversight Support the oversight of the Information Security Management System (ISMS), related policies and governance processes through which the First Line implements the security and ICT risk strategy.
Support the governance and ongoing operation of the Global ICT Risk and Security Committee. Perform independent Second Line monitoring and reviews of relevant processes, systems and controls to assess their adequacy and effectiveness, while operational ownership remains with the First Line. Act as an interface to the Group Risk Management framework and contribute to the consistent identification, assessment, monitoring and reporting of ICT and cyber risks.