We are looking for an experienced Senior IT Analyst to join a project within a large financial organization. This role combines IT Risk & Audit, Compliance, IT Security, Infrastructure, and Project Management.
We are looking for someone who is comfortable working across both technical and regulatory areas and can effectively collaborate with senior leadership, technical teams, Audit, and Risk & Control functions.
Location & Working Model
Warsaw / Łódź / Gdynia / Gdańsk
Hybrid model: currently 2 days per week from the office, increasing to 3 days per week from Q4.
Start: ASAP / up to 1 month
Key Responsibilities
Conduct IT risk assessments, from risk identification and action planning through to risk monitoring and remediation.
Design and coordinate audit remediation plans and audit closure strategies.
Collect, prepare, and document evidence and technical artefacts required for audit purposes.
Support the closure of complex internal and regulatory audit findings.
Communicate risks, priorities, remediation plans, required effort, and outcomes to senior leadership and Risk & Control functions.
Work with regulatory and compliance requirements, including NIS2, DORA, FSA guidelines, and ECB requirements.
Identify process and control weaknesses and recommend appropriate remediation actions.
Assess and address topics related to network security, database security, vulnerability management, and threat management.
Establish project plans, communication structures, and governance in line with industry-standard project management practices.
Manage stakeholders, dependencies, risks, timelines, and expectations.
Provide weekly reporting on progress, impediments, and identified risks.
Proactively drive actions required to deliver agreed results on time.
Requirements
IT Risk, Audit & Compliance
Strong experience in IT Risk Management and end-to-end risk assessment processes.
Expert knowledge of risk frameworks.
Extensive experience in IT Audit, including designing and executing remediation plans.
Experience collecting and documenting audit evidence and technical artefacts.
Knowledge of regulatory and compliance requirements such as NIS2, DORA, FSA guidelines, and ECB requirements.
Experience working on large-scale, cross-organizational initiatives.
Experience communicating risk and audit topics to senior management.
Experience with the closure of regulatory and internal audit findings is highly desirable.
IT Security & Infrastructure
Expert knowledge of DNS, TCP/IP, and network architecture, including cloud environments and internet-facing assets.
Senior/expert knowledge of database security, including backup strategies, user management, authentication, version management, and patch management.
Strong knowledge of vulnerability management, security testing, and vulnerability scanning tools and techniques.
Knowledge of security threat management, web-based threats, and appropriate mitigation strategies.
Understanding of incident management, problem management, and CMDB systems.
Knowledge of security risk management and governance is an advantage.
Technical Skills
Senior-level knowledge of database technologies, including Oracle, DB2, MSSQL, and PostgreSQL, covering architecture, security, compliance, and user management.
Expert knowledge of IP/DNS systems, network architecture, cloud networking, and internet-based assets.
Expert knowledge of SharePoint administration and development, including the design, development, and maintenance of SharePoint Lists.
Strong experience with Power Apps and Power Automate.
Python at mid/senior level, particularly for data management and analytics.
Banking
Experience within the banking or financial services sector.
Knowledge of banking applications and technologies across areas such as transactions, corporate banking, asset management, and trading.
Understanding of Business Continuity, Business Impact Analysis, and Business Analysis.
Project Management
Experience setting up and managing project plans according to industry-standard project management approaches.
Strong stakeholder management skills, including stakeholder onboarding and establishing effective ways of working.
Ability to monitor and control timelines, risks, dependencies, and resources.
Experience reporting project progress, impediments, and risks.
Excellent organizational and planning skills.
Strong communication and negotiation skills.
Ability to manage expectations and proactively drive delivery.
Soft Skills
We are looking for someone who can operate effectively in a complex and politically sensitive organizational environment. The ideal candidate demonstrates:
Strong organizational awareness and political sensitivity.
A collaborative and proactive mindset.
Ability to coach and upskill less experienced Risk/Audit professionals.
Persuasiveness and strong negotiation skills.
Trustworthiness and accountability.
Ability to recognize and advise on the remediation of ineffective controls.
Ability to clearly identify and articulate risks, process weaknesses, and control gaps.
Strong analytical skills and the ability to proactively propose alternative solutions.
Openness to acknowledging when a decision needs to be reconsidered and adapting accordingly.

