> Markdown version of [/jobs/ext/2106355-senior-ict-risk-manager-independent-second-line-vienna-austria](https://www.wearedevelopers.com/jobs/ext/2106355-senior-ict-risk-manager-independent-second-line-vienna-austria). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ICT Risk Manager - Independent Second Line - Vienna, Austria - **Company:** Western Union - **Location:** Wien, Austria - **Experience:** Expert - **Salary:** €80,250.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Disaster Recovery, Information Technology Audit, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://www.adzuna.at/details/5846903968 ## About the Role * University degree or relevant professional qualification. * At least seven years of relevant experience in ICT risk management, technology risk, information security, IT audit or operational resilience, including experience exercising independent oversight or challenge within a regulated financial services environment. * Proven experience implementing or managing DORA, EBA ICT Guidelines, or comparable ICT risk and regulatory frameworks, with the ability to translate regulatory requirements into proportionate governance, oversight and reporting. * Experience managing regulatory inspections, supervisory engagements, audits, or regulatory reviews. * Experience overseeing third-party risk and outsourced ICT services. * Experience preparing and presenting risk assessments, regulatory updates, and recommendations to senior leadership, committees, or board-level stakeholders. * Strong knowledge of ICT risk and governance frameworks, including DORA, PSD2, ISO 27001, NIST, and COBIT. * A relevant professional certification such as CRISC, CISM, CISSP, CISA or an equivalent risk, security or audit qualification is desirable. * Strong analytical, communication, stakeholder management, and problem-solving skills. * Fluent English language skills, both written and verbal., * Experience within banking, payments, fintech, or other regulated financial services environments. * Experience operating within multinational and matrix organisations. * Fluency in German. * Additional risk management certifications are advantageous. ## Description Vienna-Gertrude Vollzeit NEU In this high impact role, you will provide dedicated ICT Risk leadership with the Western Union International Bank's independent Second Line of Defence (2LoD). You will oversee and challenge how First Line teams identify, assess, manage and remediate ICT risk. You will have regular access to the Management Board and engage with auditors and supervisor authorities with regards to ICT Risks, through the Bank's established governance arrangements. This is an opportunity to shape a dedicated ICT risk oversight capability for an Austrian bank operating within a global leader in cross-border money movement. You will combine local regulatory influence with access to international technology, cyber, payments and risk specialists, helping protect the resilience of services used by customers around the world. The role offers substantial autonomy, Board-level visibility and the chance to build a lasting control framework rather than simply maintain an established program. Your impact will include strengthening the Bank's independent ICT risk oversight model, establishing a clear annual oversight and assurance plan, enhancing risk appetite and Management Board reporting, challenging priority ICT and third-party risk exposures, and embedding a sustainable review cycle for the ICT Risk Management Framework. You will be supported by established Risk Management and Internal Control capabilities, specialist external expertise during transition and access to global Western Union stakeholders. Role Responsibilities * Own and continuously enhance the ICT Risk Management Framework, including policies, standards, governance, controls, and reporting. * Act as the independent Second Line of Defence (2LoD), providing oversight and challenge of ICT risk management activities across the Bank. * Define, monitor, and report on ICT risk appetite, Key Risk Indicators (KRIs), thresholds, and escalation protocols. * Lead and oversee DORA compliance activities, ensuring alignment with applicable European regulatory requirements and industry best practices. * Develop and oversee the Digital Operational Resilience Testing Programme, including scenario-based testing, resilience exercises, and vulnerability assessments. * Provide oversight of ICT incident management, regulatory reporting, post-incident reviews, and remediation activities. * Ensure effective integration of ICT risk management with Business Continuity Management and Disaster Recovery frameworks. * Oversee ICT third-party and outsourcing risk governance, including criticality assessments, concentration risk, contractual requirements, and exit planning. * Coordinate regulatory engagements, audits, and supervisory reviews, serving as the primary contact for ICT risk and operational resilience matters. * Monitor control effectiveness, oversee assurance activities, and ensure timely remediation of audit findings and regulatory actions. * Prepare and deliver reporting on ICT risk posture, resilience, and emerging risks to senior management, committees, and the Management Board. * Act as a trusted advisor to senior stakeholders on ICT risk, operational resilience, and regulatory developments. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How to Find Tech Jobs in Vienna](https://www.wearedevelopers.com/magazine/292-how-to-find-tech-jobs-in-vienna) - [Best Companies to Work For in Austria: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/192-best-companies-to-work-for-in-austria-top-25-companies-in-2023) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria) - [Austria – the most livable place for software developers?](https://www.wearedevelopers.com/magazine/20-austria-the-most-livable-place-for-software-developers) - [Software Developer Salary in Austria [2023]](https://www.wearedevelopers.com/magazine/213-software-developer-salary-in-austria-2023) - [Data Analyst Salary Austria](https://www.wearedevelopers.com/magazine/275-data-analyst-salary-austria)