IT Risk Manager

Selby Jennings
Amsterdam, Netherlands
2 days ago
Apply on www.efinancialcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Artificial Intelligence Software System Penetration Testing Cyber Security Disaster Recovery Identity and Access Management Information Technology Audit Software Tools

Requirements

We are representing a newly launched trading platform building critical infrastructure for the European fixed-income market. You will be responsible for evaluating their technology infrastructure, monitoring and auditing critical technology providers, ensuring full compliance with the Digital Operational Resilience Act (DORA), and acting as a constructive, independent partner to the First Line (1LoD) operations team. Over time, this role is explicitly designed to evolve into a whole-of-business Enterprise Risk Management (ERM) mandate. They operate in a heavily regulated, high-stakes environment. You must bring exceptional flexibility and a proactive, self-starter approach. The team steps in and steps up to solve critical issues, even when they fall outside a formal remit. A “no job too big, no job too small” work ethic is essential. You should be equally comfortable presenting risk strategy to the Senior Management Team as you are diving into the technical detail of a penetration testing report or a vendor SOC audit. Key Responsibilities Frameworks & Strategy: Review, implement, and monitor the firm’s enterprise and IT risk management frameworks, ensuring strict alignment with DORA, ISO 27001, and relevant regulatory standards. 2LoD Vendor & Operational Oversight: Act as the independent 2LoD partner to the Operations & Outsourcing Manager (1LoD), providing constructive challenge, risk reviews, and oversight of critical third-party technology providers. Audits & Risk Assessments: Conduct independent risk assessments, gap analyses, and controls assurance across internal systems, critical IT vendors, and broader business operations. Information Security & Resilience: Oversee information security controls, GDPR compliance, and Identity & Access Management (IAM) frameworks, while evaluating BCP and Disaster Recovery (DR) test outcomes. Reporting & Incident Governance: Track enterprise risk metrics, manage IT incident escalation pathways, and present clear risk reporting directly to the CCO, COO, and CEO. What We Are Looking For Flexible Experience Profile: We welcome applications across a broad range of experience levels, from high-potential rising specialists to seasoned senior experts. Technical capability, execution mindset, and operational fit are prioritised over rigid tenure thresholds. Risk & Assurance Background: Proven background in IT risk management, information security compliance, IT audit, or technology controls assurance (ideally within financial services, fintech, or critical infrastructure). Regulatory & Framework Mastery: Strong familiarity with European technology regulations (DORA, NIS2) and major security/control frameworks (ISO 27001, NIST, SOC 2). Domain Knowledge: General knowledge of capital markets, market infrastructure, or fixed-income trading is considered a strong plus. AI-Forward Workflow: Practical experience with, or affinity for, using AI tools in a risk/IT context (e.g. threat modelling, control testing automation, or log/policy analysis) to scale lean operations. Communication & Languages: Excellent ability to translate complex technical risks into clear, actionable business insights for leadership. Fluency in English is required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.efinancialcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:50 min

Electronic diagnostic software tools and factory production flashing

Denis Grahovac · World Congress 2021

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

4:21 min

Navigating compliance and risk in highly regulated environments

Alexandra Wudel Alexandra Wudel +3 · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all