Talent.com
UBP - Union Bancaire Privée
CyberSecurity Frontline Risk and Control ManagerUBP - Union Bancaire Privée • genf, Switzerland
CyberSecurity Frontline Risk and Control Manager

CyberSecurity Frontline Risk and Control Manager

UBP - Union Bancaire Privée • genf, Switzerland
Vor 27 Tagen
Stellenbeschreibung
p h3Mission /h3 pLead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk Governance and Vulnerability Management. Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore). Partner with Technology, Business, Risk, and Compliance stakeholders to proactively manage cyber risks, ensure regulatory adherence, and safeguard UBP’s clients and assets. /p h3Governance Risk Management /h3 ul liOwn and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence. /li liDrive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales. /li liMaintain risk registers and key risk indicators (KRIs). Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap. /li liEnsure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). /li /ul h3Vulnerability Management /h3 ul liLead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties). /li liOversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs. /li liPartner with Infrastructure, DevSecOps, and application owners to embed secure‑by‑design principles and shift‑left controls. /li liReport on exposure, trends, and risk posture to senior management and risk committees. /li /ul h3Regulatory Compliance Audit Support /h3 ul liInterpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS). /li liPrepare evidence and responses for internal/external audits, regulatory exams, and board‑level reporting. /li liMaintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings. /li liManage and mentor a small team; build capabilities and career growth for junior staff. /li liCommunicate complex cyber risk topics clearly to senior management and non‑technical stakeholders. /li liChampion a risk‑aware culture across technology and business functions. /li /ul h3Leadership Stakeholder Management /h3 ul liManage and mentor a small team; build capabilities and career growth for junior staff. /li liCommunicate complex cyber risk topics clearly to senior management and non‑technical stakeholders. /li liChampion a risk‑aware culture across technology and business functions. /li /ul h3Your Profile /h3 ul liExperienced cybersecurity risk leader with deep first line of defense experience in financial services. /li liStrong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements. /li liStrategic thinker with hands‑on rigor—able to sustain current frameworks while maturing them for scalability and transparency. /li liInfluential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff. /li /ul h3Education /h3 ul liBachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field. /li liRelevant certifications preferred: CISSP, BISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. /li /ul h3Experience Technical Skills /h3 ul li8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. /li liProven track record in: /li liDesigning and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing). /li liLeading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance). /li liRegulatory engagement, audit response, and evidence management. /li liCross‑border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). /li liPractical familiarity with: /li liFrameworks/standards: NIST CSF, NIST 800‑53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATTCK. /li liVM tooling ecosystems: Qualys/Tenable/Rapid7, SAST/DAST, SCA, container and cloud posture management (CSPM), EDR/XDR. /li liEnterprise environments: Windows/Unix, networks, databases, microservices, SaaS, public cloud (AWS/Azure/GCP). /li liSecure SDLC/DevSecOps and CI/CD integration of controls. /li liReporting and metrics for executive forums and risk committees. /li /ul h3Languages /h3 ul liEnglish: fluent (written and spoken). /li liFrench - strong advantage. /li /ul h3Personal skills /h3 ul liLeadership: coaching mindset, able to build high‑performing teams and upskill junior colleagues. /li liCommunication: clear, concise, and audience‑appropriate; strong presentation and writing skills. /li liDecision‑making: risk‑based prioritisation, data‑driven, and pragmatic under time pressure. /li liCollaboration: strong stakeholder management across IT, Risk, Compliance, and business lines. /li liAdaptability: navigates ambiguity; balances regulatory rigor with business practicality. /li liIntegrity: high professional ethics and commitment to client and bank protection. /li /ul h3Others /h3 ul liLocation: Geneva /li liSwiss Residence /li liHybrid working arrangements aligned with UBP policy. /li liCandidates must have the right to work in the relevant jurisdiction. /li liBackground checks required consistent with banking standards. /li /ul h3Core Competencies /h3 ul liAdherence to the company’s values: Dedication, Conviction, Agility, and Responsibility - Compliance with regulations and internal directives /li /ul /p #J-18808-Ljbffr
Jobalert für diese Suche erstellen

CyberSecurity Frontline Risk and Control Manager • genf, Switzerland

Ähnliche Stellen

Business Risk Manager - Technology & Operations (80-100%)

Lombard OdierGeneva

An innovative bank of choice for private and institutional clients, our independently owned Firm is one of the best-capitalised banking groups in the world, managing close to CHF 300 billion and op... Mehr anzeigen

 • Gesponsert

Risk Manager

Norman AlexGeneva, Switzerland
Quick Apply

Notre client est une societe de gestion en forte croissance sur Geneve et elle recherche un Risk Manager pour prendre en charge la fonction risque de la société, aujourd'hui assurée en interne.Post... Mehr anzeigen