Information Security Risk Manager — Sygnum Bank
- Location
- Zurich
- Contract
- full-time
- Posted
- Yesterday
Role overview
This is a unique opportunity to work at the intersection of a digital-native and FINMA-regulated bank with an international footprint, combining the pace and technology stack of a digital-first organization with the rigor of a regulated financial institution.
We are looking for an experienced Information Security Risk Manager to join our Information Security function in Zurich.
Reporting to the CISO, you will own the security control catalogue end to end, drive the enterprise information security risk assessment process, and act as the primary liaison for regulatory and audit engagements.
You will also help modernize how we monitor and report on control performance by automating oversight across cloud, endpoint, and other data sources, and you will keep the organization security-aware through an engaging awareness program.
Key responsibilities
· Own the information security control catalogue, including control oversight, effectiveness rating, KPI measurement, and deficiency remediation.
· Manage and perform the top-down and bottom-up information security risk assessment processes · Provide subject matter expert input relating to all aspects including IT risks, security measures, controls, and remedial actions.
· Drive automation of security oversight processes, integrating information from multiple sources (cloud, endpoint, and others) into unified reporting dashboards.
· Provide information risk and security subject matter expertise inputs and assessments to our IT and business teams in support of their risk management activities.
· Oversee information security audits, whether performed by the Bank or third- parties.
· Support our culture development of information and security risk awareness, hence, good conduct through supporting regular communications, awareness, and training.
- Key responsibilities:
- Own the information security control catalogue, including control oversight, effectiveness rating, KPI measurement, and deficiency remediation.
Main responsibilities
- Key responsibilities:
- Own the information security control catalogue, including control oversight, effectiveness rating, KPI measurement, and deficiency remediation.
- Manage and perform the top-down and bottom-up information security risk assessment processes
- Provide subject matter expert input relating to all aspects including IT risks, security measures, controls, and remedial actions.
- Drive automation of security oversight processes, integrating information from multiple sources (cloud, endpoint, and others) into unified reporting dashboards.
- Provide information risk and security subject matter expertise inputs and assessments to our IT and business teams in support of their risk management activities.
- Oversee information security audits, whether performed by the Bank or third- parties.
- Support our culture development of information and security risk awareness, hence, good conduct through supporting regular communications, awareness, and training.
- 5+ years of professional experience in information risk frameworks and management and IT audit, preferably in a mid/large-sized financial institution or audit company.
- Solid working knowledge of recognized frameworks such as NIST CSF, ISO 27001, or CSA CCM, and experience applying them to real-world control environments.
Company and context
- This is a unique opportunity to work at the intersection of a digital-native and FINMA-regulated bank with an international footprint, combining the pace and technology stack of a digital-first organization with the rigor of a regulated financial institution.
- We are looking for an experienced Information Security Risk Manager to join our Information Security function in Zurich.
- Reporting to the CISO, you will own the security control catalogue end to end, drive the enterprise information security risk assessment process, and act as the primary liaison for regulatory and audit engagements.
- You will also help modernize how we monitor and report on control performance by automating oversight across cloud, endpoint, and other data sources, and you will keep the organization security-aware through an engaging awareness program.
Additional details
- Sygnum offers a comprehensive package of benefits for all team members.
- Attractive combination of market salaries and entrepreneurial incentive scheme Flexible/Work at home policies
Notes and original content
- They include:
- Attractive combination of market salaries and entrepreneurial incentive scheme
- Flexible/Work at home policies
Questions about this listing
What salary does Sygnum Bank offer for this role?
Sygnum Bank lists CHF 121'500 - 206'500 gross per year for this position in Zurich. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.
Is this a full-time role, and what type of contract does Sygnum Bank offer?
This listing is a full-time position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with Sygnum Bank during the application process, since these details can vary by role even within the same contract category.
Do I need a cross-border work permit for a role in Zürich?
EU/EFTA residents living in the border zone of the country adjoining Canton Zürich can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Zürich's cantonal migration office or with HR during the application.
How do I apply for this position at Sygnum Bank?
Use the "Apply now" button on this page — it links directly to Sygnum Bank's original listing at sygnumpeopleportal.my.salesforce-sites.com, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.