• 4+ years of experience in information security or risk management, with a focus on second line functions.
• Experience in performing information security assessments or audits.
• Demonstrated experience in operational security risk management.
• Strong understanding of Information Security frameworks (ISO 27001, NIST, SOC) and their application in second line assurance activities.
• Strong understanding of the FS regulatory landscape (DORA, NBB, EBA, etc.).
• Proven ability to conduct risk oversight, challenge the first line’s risk management activities, and ensure compliance with internal and external standards.
• Experience working in financial services or large-scale enterprises, with an understanding of regulatory requirements in IT and cybersecurity.
• Security certifications such as CISSP, CISM, CCSK, or similar.
• Familiarity with vulnerability management, penetration testing, and reviewing IT and security clauses in contracts.
• Knowledge of control frameworks and audit methodologies within second line risk functions.
• Strong communication and influencing skills, capable of working with senior stakeholders and challenging the first line when necessary.
• Excellent analytical and problem-solving abilities, with a focus on providing independent assurance and actionable recommendations.
• Proactive, autonomous, teamplayer, collaborator and able to synthesize complex issues.