410,083open jobs
14,230companies
73,879added this week
Browse all
Location
In office (Bucharest, Cluj-Napoca)
Employment
Full-Time
Overview
Company
Impact
Profile match
ING is a Dutch banking group formed in 1991 by the merger of the postal bank NMB Postbank and the insurer Nationale-Nederlanden, and it was among the first large banks to build a direct, branch-light retail model. It serves retail customers in the Netherlands, Belgium, Germany, Poland, Spain and several other markets through mobile-first banking, and runs a substantial wholesale bank covering lending, transaction services and financial markets for corporate clients. Headquartered in Amsterdam and listed on Euronext, the group divested its insurance operations after the financial crisis to focus on banking.

Discover ING Hubs Romania

ING Hubs Romania offers 130 services in software development, data management, non-financial risk & compliance, audit, and retail operations to 24 ING units worldwide, with the help of - , , .

We started out in 2015 as ING’s software development hub, then steadily expanded our range to include more services and competencies. Now we provide borderless services with bank-wide capabilities and : -.

, with more than 1800 colleagues active in Data Management, Touchpoint Channels & Integration, Core Banking, and Global Products.

We enjoy a flexible way of working and a highly collaborative environment, where fair and constructive feedback is encouraged.

For us, impact isn't a perk. It's the driver of our work. We are guided and rewarded by a shared desire to make the world a better place, one innovative solution at a time. Our colleagues make it their job to do impactful things and they love doing it in good company. Do you?

Your mission

As an OpsRisk Engineerwill be part of the Financial Markets domain.

You will help on risk subjects like:

  • Act as a central SPOC for all incoming IT risk assessments and control evidencing requirements adhering the established control framework, SOx requirements and industry best practices.

  • Monitoring, tracking and managing deviations to established IT Risk controls.

  • Mediating between 1st LOD/2nd LOD and DevOps teams.

  • Conducting walkthroughs with auditors to review and validate IT Risk control processes.

  • Lead technical due diligence sessions with third party vendors.

You will work in an AGILE environment, following SCRUM methodology together with DevOps squads, helping to maintain a safe and secure application.

Your Day to Day

Your primary mission is to help the squads to implement IT Controls and to prove the controls are implemented effectively:

  • ensure we are in control of our risk appetite

  • define and document adequate risk processes and collect the evidences in regards; make sure that the different risk parties agree with the evidences

  • responsible for creating documents and project management requirements or specifications

  • provide documentation support to the technical team; interface with developers and operation engineers to define the specifications

  • liaison between the team and other IT Risk professionals

  • understand the need for security and apply it using the existing framework; constant communication about changes

  • participate in automation program for process and evidence for IT risk

  • show proactivity and flexibility, come up with plans of action and adapt approaches if necessary

  • understand the corporate climate and culture and act as an ambassador; IT custodianship/asset owner role.

What you’ll bring to the team

Experience:

  • Degree and/or experience in IT risk management, cybersecurity, or related field.

  • Understanding of fundamental IT risk and security concepts and ability to think critically across technical control domains.

  • Knowledge of IT control frameworks (eg. SOX, GDPR, CSA CCM) and industry standards (eg. ISO2700x, NIST).

  • Proven track record of conducting IT control evidencing, qualitative risk assessments and developing mitigation strategies.

Risk reporting and communication:

  • ability to communicate risk-related concepts to technical stakeholders.

  • experience in liaising with second line risk functions.

  • strong written and verbal communications skills in English.

  • Certifications such as CISSP, CISM, CRISC or equivalent are a plus.

Knowledge:

Mandatory:

  • Ability to understand the risk processes in an IT environment

  • Experience with IT risk standards

  • Ability to make clear and convincing statements related to risk procedures Proven planning and organizing experience

Nice to have:

  • Project management experience

  • Ability to track, plan and coordinate projects related to third party risk management, technical compliance, and/or IT risk automation

  • Experience in working with Dev(Sec)Ops teams across vulnerability management, threat hunting, security detection and response and developing, or contributing to information security policies and procedures

  • Knowledge of Agile methodology

Foreign languages: English (advanced)

Education: nice to have Bachelor’s Degree (or higher) in an IT related field.

If you want to deep dive into the processing of personal data conducted by ING Hubs Romania during the recruitment process and your rights related to it, read the privacy notices on our website (make sure to scroll until you reach the Data Protection section/ Candidates tab).

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
410,083 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bucharest
Remote/Hybrid • 10+ years exp • Austin
Cybersecurity
GDPR
HIPAA
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree • São Paulo
DevOps
GitHub
Cybersecurity
GDPR
Marketing
LinkedIn
Apply
$85k – $135k per year • Remote/Hybrid • 5+ years exp • Bachelor's Degree
Cybersecurity
GDPR
HIPAA
Apply
In office • 7+ years exp
Cybersecurity
GDPR
Apply
In office • 10+ years exp • Bachelor's Degree
Cybersecurity
GDPR
ISO 27001
SOC 2
Analytics
Power BI
Management
Jira
Notion
Apply
$38k – $77k per year (Estimated) • In office • Full-Time • Warsaw
SQL
Apply
In office • Full-Time • Frankfurt am Main
Apply
In office • Full-Time • Sydney
Apply
In office • Full-Time • Wyong
Apply
In office • Full-Time • Bachelor's Degree • Sydney
Apply
Remote/Hybrid • 2+ years exp • Bachelor's Degree • Bucharest
Marketing
LinkedIn
Salesforce
Apply
Remote/Hybrid • 2+ years exp • Bachelor's Degree • Bucharest
Marketing
LinkedIn
Salesforce
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree • Bucharest
DevOps
GitHub
Cybersecurity
GDPR
Marketing
LinkedIn
Apply
$30k – $37k per year (Estimated) • Remote/Hybrid • Full-Time • Bucharest
C#
JavaScript
SQL
TypeScript
C#
.NET
Databases
MS SQL
Frontend
Angular
DevOps
Azure
CI/CD
Docker
Kubernetes
Apply
In office • Full-Time • Bucharest
Apply
See all jobs
This is one of many
410,083 more open roles from verified company boards, updated every day.