About the job
Key Responsibilities
- Operational Risk Framework: Develop and maintain operational risk policies and standards, conduct risk and control assessments (RCSAs), establish Key Risk Indicators (KRIs), and manage incident taxonomy and issue tracking.
- Outsourcing & Third-Party Oversight: Ensure the completeness of the outsourcing register, conduct thorough risk assessments, review contracts and SLAs, and monitor ongoing performance alongside exit and contingency planning.
- DORA & ICT Risk Oversight: Lead the second-line oversight aligned with DORA governance, including incident classification, testing expectations, and managing ICT third-party risks.
- Operational Resilience: Facilitate the mapping of critical services, scenario testing, and tracking of lessons learned and remediation efforts.
- Reporting & Assurance: Generate management and Board-quality Management Information (MI) related to incidents, KRIs, outsourcing performance, and resilience testing, while supporting audits and regulatory engagements.
Key Deliverables
- Comprehensive outsourcing and third-party MI along with register assurance; incident and issues MI
- DORA and resilience oversight plan with a supporting evidence library; quarterly reporting cadence
- Insights into control effectiveness and follow-through on remediation actions
