Job offer
Information Security Risk Manager
The Information Security Risk Manager at Sygnurn in Zurich is responsible for managing the company-wide control catalog, conducting risk assessments, and collaborating with regulatory authorities and auditors. The position requires at least five years of experience in information risk management, knowledge of frameworks such as NIST CSF or ISO 27001, and, ideally, certifications such as CISSP or CISM.
Tasks
- Responsibility for the catalog of information security controls, including assigning control responsibilities, evaluating effectiveness, measuring KPIs, and addressing deficiencies.
- Management and implementation of the top-down and bottom-up processes for assessing information security risks.
- Providing expertise on all aspects, including IT risks, security requirements, controls, and corrective actions.
- Promoting the automation of security reporting processes by integrating information from multiple sources (cloud, endpoint, and network) into unified reporting dashboards.
- Providing expertise and assessments on information risks and security to IT and business teams to support their risk management activities.
- Review of information security audit programs, whether conducted by the bank or by third parties.
- Supporting the promotion of a culture of information and security risk awareness through regular communication, awareness-raising, and training.
Requirements
- At least 5 years of professional experience in information risk frameworks and management, as well as IT audits, preferably at medium-sized to large fintech consulting or audit firms.
- In-depth knowledge of recognized frameworks such as NIST CSF, ISO 27001, or CSA CCM, as well as experience applying them in cloud and distributed environments.
- Professional certifications such as CISSP, CISM, or CRISC (or active efforts to obtain one).
- Familiarity with security tools and data sources in cloud and endpoint environments, as well as an interest in automating nightly processes and reporting.
- Proven communication and interpersonal skills, including the ability to manage multiple stakeholders.
- Strong communication skills, both written and oral, in English.
- Understanding and knowledge of digital assets; experience working with agile or DevSecOps models is a plus.
- Experience with cloud security in AWS and Microsoft Azure, as well as with Cloud Security Posture Management (CSPM) tools such as Wiz, is a plus.
We offer
- An attractive combination of market-rate wages and an incentive-based compensation system.
- Flexible Work Schedule Models / Work-from-Home Policies.
- Professional development through mentoring and buddy programs.
- One month of fully paid leave (sabbatical) after five years of continuous employment.
Job details