What You'll Do
- ICT Risk Management & DORA: Hold the ICT Risk Management Function under DORA Art. 6(4), maintain the ICT risk framework and the information register, and classify ICT-related incidents including timely reporting.
- ISMS & ISO 27001: Develop our ISMS in line with ISO 27001 Annex A, define baseline controls and run continuous maturity assessments – including preparing and steering certification and surveillance audits.
- Audit Management: Own audit evidence for DORA and ISO 27001 topics, run internal self-audits, and coordinate with external audit partners and internal audit.
- Engineering & Platform: Work closely with Software Engineering, Platform and DevOps to embed security and compliance requirements into development processes in a practical way, so security supports delivery rather than slowing it down.
- Business Continuity: Support business continuity and disaster recovery planning together with Platform and Engineering, including annual continuity testing for our time-critical processes.
- Third-Party & Vendor Risk: Assess and classify new ICT services under DORA Art. 28–30, review contractual requirements, and oversee the risk posed by our ICT third parties.
- Security Operations: Initiate penetration tests, run security incident response from triage through post-incident review, and strengthen security awareness across the company through training and workshops.
