CyberSecurity Frontline Risk and Control Manager — Union Bancaire Privée
- Location
- Geneva, Switzerland
- Contract
- full-time
- Posted
- 43 days ago
Role overview
Mission
Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore).
- Mission
- Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
Main responsibilities
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Drive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales.
- Maintain risk registers and key risk indicators (KRIs).
- Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap.
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
Key requirements
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
- Strategic thinker with hands-on rigor—able to sustain current frameworks while maturing them for scalability and transparency.
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff. Education
- Bachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Designing and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing).
- Leading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance).
- Regulatory engagement, audit response, and evidence management.
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Frameworks/standards: NIST CSF, NIST 800-53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATT .
Application process
- Lead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties).
- Oversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs.
- Partner with Infrastructure, DevSecOps, and application owners to embed secure-by-design principles and shift-left controls.
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support
- Interpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS).
- Prepare evidence and responses for internal/external audits, regulatory exams, and board-level reporting.
- Maintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings.
- Manage and mentor a small team; build capabilities and career growth for junior staff.
Additional details
- Main responsibilities Governance & Risk Management
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support Leadership & Stakeholder Management
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Reporting and metrics for executive forums and risk committees.
- French - strong advantage.
- Integrity: high professional ethics and commitment to client and bank protection.
Notes and original content
- Main responsibilities
- Governance & Risk Management
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005).
- Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees.
- Regulatory Compliance & Audit Support
- Leadership & Stakeholder Management
- Your Profile
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent.
- Experience Technical skills
Questions about this listing
What salary does Union Bancaire Privée offer for this role?
Union Bancaire Privée lists CHF 83'500 - 126'500 gross per year for this position in Geneva, Switzerland. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.
Is this a full-time role, and what type of contract does Union Bancaire Privée offer?
This listing is a full-time position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with Union Bancaire Privée during the application process, since these details can vary by role even within the same contract category.
Do I need a cross-border work permit for a role in Geneva?
EU/EFTA residents living in the border zone of the country adjoining Canton Geneva can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Geneva's cantonal migration office or with HR during the application.
How do I apply for this position at Union Bancaire Privée?
Use the "Apply now" button on this page — it links directly to Union Bancaire Privée's original listing at iaadtu.fa.ocs.oraclecloud.eu, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.