Responsabile del Rischio e del Controllo di Prima Linea della Cybersecurity — Union Bancaire Privée
- Località
- Geneva, Switzerland
- Contratto
- full-time
- Pubblicato
- 43 giorni fa
Panoramica
Mission Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore).
Partner with Technology, Business, Risk, and Compliance stakeholders to proactively manage cyber risks, ensure regulatory adherence, and safeguard UBP’s clients and assets.
- Mission Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
- Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore).
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
Responsabilità principali
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Drive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales.
- Maintain risk registers and key risk indicators (KRIs).
- Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap.
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
Requisiti principali
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
- Strategic thinker with hands-on rigor—able to sustain current frameworks while maturing them for scalability and transparency.
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff. Education
- Bachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Designing and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing).
- Leading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance).
- Regulatory engagement, audit response, and evidence management.
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Frameworks/standards: NIST CSF, NIST 800-53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATT .
Processo di candidatura
- Lead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties).
- Oversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs.
- Partner with Infrastructure, DevSecOps, and application owners to embed secure-by-design principles and shift-left controls.
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support
- Interpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS).
- Prepare evidence and responses for internal/external audits, regulatory exams, and board-level reporting.
- Maintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings.
- Manage and mentor a small team; build capabilities and career growth for junior staff.
Dettagli ulteriori
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support Leadership & Stakeholder Management
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Reporting and metrics for executive forums and risk committees.
- French - strong advantage.
- Integrity: high professional ethics and commitment to client and bank protection.
Note e contenuto originale
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005).
- Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees.
- Regulatory Compliance & Audit Support
- Leadership & Stakeholder Management
- Your Profile
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent.
- Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank.
- Proven track record in:
Domande frequenti su questo annuncio
Che stipendio offre Union Bancaire Privée per questa posizione?
Union Bancaire Privée indica CHF 83'500 - 126'500 lordi annui per questo ruolo a Geneva, Switzerland. Questo è lo stipendio pubblicato nell'annuncio originale (o, quando il datore non specifica una cifra, una stima realistica per ruolo e settore) — il calcolatore di questo sito lo converte nel netto reale una volta applicate imposta da frontaliere e contributi sociali.
È un ruolo a tempo pieno, e che tipo di contratto offre Union Bancaire Privée?
Questo annuncio è una posizione a tempo pieno. Il tipo di contratto mostrato qui arriva direttamente dall'annuncio originale del datore di lavoro; conferma sempre orario esatto, preavviso e durata del periodo di prova con Union Bancaire Privée durante il colloquio, perché questi dettagli possono variare anche all'interno della stessa categoria contrattuale.
Serve un permesso da frontaliere per un ruolo nel canton Ginevra?
I residenti UE/AELS nella zona di frontiera del paese confinante con il canton Ginevra possono richiedere il Permesso G; il datore di lavoro svizzero lo presenta all'ufficio della migrazione di quel canton dopo la firma del contratto. Regole sulla zona di frontiera e tempi di lavorazione variano per paese confinante e canton — verifica i dettagli con l'ufficio della migrazione del canton Ginevra o con HR durante il colloquio.
Come mi candido a questa posizione presso Union Bancaire Privée?
Usa il pulsante "Candidati ora" in questa pagina — rimanda direttamente all'annuncio originale di Union Bancaire Privée su iaadtu.fa.ocs.oraclecloud.eu, quindi la tua candidatura arriva direttamente nel sistema di gestione candidature del datore di lavoro. Frontaliere Ticino non raccoglie né inoltra candidature in proprio.