Job
- Level
- Senior
- Job Field
- IT, System, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- from 80.250 € gross/year
- Location
- Vienna
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will oversee the Bank's ICT risks, develop mitigation measures, create oversight strategies, and lead DORA compliance testing to ensure operational resilience.
Job Technologies
Your role in the team
- In this high impact role, you will provide dedicated ICT Risk leadership with the Western Union International Bank's independent Second Line of Defence (2LoD).
- You will oversee and challenge how First Line teams identify, assess, manage and remediate ICT risk.
- You will have regular access to the Management Board and engage with auditors and supervisor authorities with regards to ICT Risks, through the Bank's established governance arrangements.
- This is an opportunity to shape a dedicated ICT risk oversight capability for an Austrian bank operating within a global leader in cross-border money movement.
- You will combine local regulatory influence with access to international technology, cyber, payments and risk specialists, helping protect the resilience of services used by customers around the world.
- The role offers substantial autonomy, Board-level visibility and the chance to build a lasting control framework rather than simply maintain an established program.
- Your impact will include strengthening the Bank's independent ICT risk oversight model, establishing a clear annual oversight and assurance plan, enhancing risk appetite and Management Board reporting, challenging priority ICT and third-party risk exposures, and embedding a sustainable review cycle for the ICT Risk Management Framework.
- You will be supported by established Risk Management and Internal Control capabilities, specialist external expertise during transition, and access to global Western Union stakeholders.
- Own and continuously enhance the ICT Risk Management Framework, including policies, standards, governance, controls, and reporting.
- Act as the independent Second Line of Defence (2LoD), providing oversight and challenge of ICT risk management activities across the Bank.
- Define, monitor, and report on ICT risk appetite, Key Risk Indicators (KRIs), thresholds, and escalation protocols.
- Leiten und Überwachen der DORA-Compliance-Aktivitäten, um die Einhaltung der geltenden europäischen regulatorischen Anforderungen und bewährten Branchenpraktiken sicherzustellen.
- Develop and oversee the Digital Operational Resilience Testing Programme, including scenario-based testing, resilience exercises, and vulnerability assessments.
- Provide oversight of ICT incident management, regulatory reporting, post-incident reviews, and remediation activities.
- Ensure effective integration of ICT risk management with Business Continuity Management and Disaster Recovery frameworks.
- Überwachen Sie die ICT-Drittanbieter- und Outsourcing-Risikogovernance, einschließlich Kritikalitätsbewertungen, Konzentrationsrisiken, vertraglicher Anforderungen und Exit-Planung.
- Coordinate regulatory engagements, audits, and supervisory reviews, serving as the primary contact for ICT risk and operational resilience matters.
- Monitor control effectiveness, oversee assurance activities, and ensure timely remediation of audit findings and regulatory actions.
- Prepare and deliver reporting on ICT risk posture, resilience, and emerging risks to senior management, committees, and the Management Board.
- Act as a trusted advisor to senior stakeholders on ICT risk, operational resilience, and regulatory developments.
This text has been machine translated. Show original
Our expectations of you
Education
- University degree or relevant professional qualification.
Qualifications
- Starkes Wissen über ICT-Risiko- und Governance-Rahmenwerke, einschließlich DORA, PSD2, ISO 27001, NIST und COBIT.
- A relevant professional certification such as CRISC, CISM, CISSP, CISA or an equivalent risk, security or audit qualification is desirable.
- Strong analytical, communication, stakeholder management, and problem-solving skills.
- Fluent English language skills, both written and verbal.
- Fluency in German.
- Additional risk management certifications are advantageous.
Experience
- At least seven years of relevant experience in ICT risk management, technology risk, information security, IT audit or operational resilience, including experience exercising independent oversight or challenge within a regulated financial services environment.
- Proven experience implementing or managing DORA, EBA ICT Guidelines, or comparable ICT risk and regulatory frameworks, with the ability to translate regulatory requirements into proportionate governance, oversight and reporting.
- Experience managing regulatory inspections, supervisory engagements, audits, or regulatory reviews.
- Experience overseeing third-party risk and outsourced ICT services.
- Experience preparing and presenting risk assessments, regulatory updates, and recommendations to senior leadership, committees, or board-level stakeholders.
- Experience within banking, payments, fintech, or other regulated financial services environments.
- Experience operating within multinational and matrix organisations.
This text has been machine translated. Show original
What we offer
- The minimum gross annual salary for this position is EUR 80,250.
- The actual offer will reflect the successful candidate's experience, qualifications, and market positioning and may be significantly above this minimum.
- The overall package also includes short-term incentive eligibility and Austria-specific benefits.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
Western Union International Bank GmbH
Wien
The Western Union International Bank was founded in 2004. Its headquarters are located in Vienna, Austria. The bank has a European license and is therefore authorized to open branches throughout the member states of the European Union.
Description
- Founding Year
- 2004
- Language
- English
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance