Job offer
Head of Non-Financial Risk Control, Europe
The Head of Non-Financial Risk Control Europe at Julius Baer oversees the monitoring of non-financial risks and operational resilience for all European entities in compliance with the DORA Directive. The position requires over 10 years of experience in risk management, a degree in computer science or a related field, and fluency in English.
Tasks
- Serve as Head of Non-Financial Risk Control for Europe, based in Luxembourg, and assume full management responsibility for all non-financial risks across all regions.
- Are responsible for developing and implementing controls and policies for non-financial risks in all regions, including Europe and non-EU countries.
- Coordinate with local managers on how to implement our risk control policies and ensure that all risks are identified, assessed, and managed in accordance with the Digital Operational Resilience for Financial Institutions (DORA) policy.
- Are responsible for implementing the global frameworks defined by the Internal Group Framework (IGF), the Operational Risk Framework (ORF), and the Group ICT Risk Framework (GIRF).
- Manage the Risk Management Framework and the Incident Management Framework.
- Ensure that the Risk Management Framework (RMF) is maintained and updated in accordance with the requirements of the CRO Framework.
- Ensure that European entities have robust policies and procedures for operational resilience and facilitate efficient and transparent cooperation with regulatory authorities worldwide.
- Provide clear and timely reporting to regulatory authorities, including material incidents, access data, vulnerabilities, and alignment with the Group’s risk profile and tolerance.
- Coordinate with Group Internal Audit on issues relevant to enterprise risk and ensure the timely identification of problems, including operational resilience (BCP/DRP), compliance risks, and incident management.
- Exercise full authority and control over the European Division, adhere to the DORA guidelines, and coordinate effectively with Group Risk and Compliance.
- Ensure effective monitoring of business continuity, resilience, incident testing, control verification, and incident management.
- We conduct ongoing monitoring and regular testing to ensure that our incident management capabilities align with industry best practices and the regulatory requirements of the Digital Operational Resilience Act (DORA) in Europe, including scenarios for on-site and remote work.
- Ensure compliance with legal and regulatory guidelines regarding third-party risks, network and security monitoring, verification monitoring, and vulnerability assessments within our ICT risk framework.
- We conduct comprehensive audits and perform tests and assessments of our ICT systems and processes to identify and mitigate risks.
- Understand and proactively manage risks posed by third parties, including suppliers and contractors, and clearly communicate regulatory changes.
- We expect regular and documented reporting, including periodic updates on significant changes in the scope and impact of our ICT risk management activities.
- Building and transforming a competent NFR workforce through collaborative risk management, knowledge transfer, and innovation; establishing a culture of excellence and ethical leadership.
- Development and delivery of training programs at regular intervals throughout Europe for an organization committed to fostering a strong incident management culture and ensuring compliance.
- Fostering a culture of responsibility, risk awareness, and transparency in Europe, with a strong focus on the priorities of the DORA Directive and the evolving risks of the digital age.
- Develop and implement a framework that monitors, assesses, and manages risks across all operations.
Requirements
- A completed bachelor's or master's degree in computer science, IT, or a related field.
- Formal training in risk management methodologies and frameworks.
- Experience in implementing and operating risk management frameworks.
- Familiarity with regulatory frameworks and standards for ICT risk management practices.
Job details