02 Aug
|
Ergo Technology & Services
|
Maharashtra
02 Aug
Ergo Technology & Services
Maharashtra
Role & responsibilities
This role sits within the second line of defense, ensuring that ICT risks are properly identified, assessed, and managed, while providing challenge and assurance to first-line activities. It directly supports compliance with DORA, Solvency II, and broader enterprise risk management standards.
Key Competencies & Skills required:
- Provide 2nd line oversight and challenges of the ICT risk management framework in line with DORA and Solvency II governance expectations.
- Support the Risk Management Function in maintaining ICT risk frameworks, standards, control requirements, and KPI/KRI metrics
- Oversee and challenge 1st line assessments for ICT incidents, resilience testing, and ICT risk (including registers, ongoing monitoring and the information domain)
- Contribute to DORA and ICT risk reporting.
- Experience from 2nd line Risk Management within financial services with a strong understanding of Solvency II governance, risk framework, and reporting expectations.
- Strong working knowledge of DORA (ICT risk management, incident management, resilience testing) and ability to translate requirements into practical tasks.
- Ability to deliver independent challenges while building trusted relationships; comfortable influencing senior stakeholders and explaining complex topics in business language.
- Strong documentation skills; experienced in producing risk assessments, and audit/regulatory evidence packs.
- Strong execution skills with multiple stakeholders and parallel deliverables; structured, pragmatic, and able to prioritize based on materiality and risk.
- Experience with GRC tooling and control libraries (RSA Archer) and maintaining risk/control registers and KPI/KRI reporting.
- Experience with information domain oversight and tooling (ServiceNow)
- ICT risk and security control frameworks (e.g., ISO 27001/27002, NIST CSF) and ability to map to DORA requirements.
- Operational resilience concepts: important business services/critical functions, impact tolerances, resilience testing approaches, and remediation tracking.
- Risk assessment methods and reporting (KRIs, dashboards), and producing audit-ready documentation and evidence.
Technical:
- Strong working knowledge of DORA (ICT risk management, incident management, resilience testing)
- Experience with GRC tooling and control libraries (e.g., RSA Archer)
- Experience with information domain oversight and tooling (e.g., ServiceNow)
- Familiarity with ICT risk and security control frameworks (ISO 27001/27002, NIST CSF) and ability to map to DORA requirements
- Operational resilience concepts: key business services/critical functions, impact tolerances, resilience testing approaches, remediation tracking
- Risk assessment methods and reporting (KRIs, dashboards)
- Producing audit-ready documentation and evidence
📌 Risk Specialist (Maharashtra)
🏢 Ergo Technology & Services
📍 Maharashtra