CyberSecurity Gestionnaire de risque et de contrôle de première ligne — Union Bancaire Privée
- Lieu
- Geneva, Switzerland
- Contrat
- full-time
- Publié
- il y a 43 jours
Vue d’ensemble du poste
Mission Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore).
Partner with Technology, Business, Risk, and Compliance stakeholders to proactively manage cyber risks, ensure regulatory adherence, and safeguard UBP’s clients and assets.
- Mission Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management.
- Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore).
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
Responsabilités principales
- Main responsibilities Governance & Risk Management
- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Drive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales.
- Maintain risk registers and key risk indicators (KRIs).
- Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap.
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
Exigences principales
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
- Strategic thinker with hands-on rigor—able to sustain current frameworks while maturing them for scalability and transparency.
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff. Education
- Bachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Designing and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing).
- Leading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance).
- Regulatory engagement, audit response, and evidence management.
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Frameworks/standards: NIST CSF, NIST 800-53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATT .
Processus de candidature
- Lead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties).
- Oversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs.
- Partner with Infrastructure, DevSecOps, and application owners to embed secure-by-design principles and shift-left controls.
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support
- Interpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS).
- Prepare evidence and responses for internal/external audits, regulatory exams, and board-level reporting.
- Maintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings.
- Manage and mentor a small team; build capabilities and career growth for junior staff.
Détails supplémentaires
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005). Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees. Regulatory Compliance & Audit Support Leadership & Stakeholder Management
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff.
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent. Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank. Proven track record in:
- Cross-border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS). Practical familiarity with:
- Reporting and metrics for executive forums and risk committees.
- French - strong advantage.
- Integrity: high professional ethics and commitment to client and bank protection.
Notes et contenu original
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005).
- Vulnerability Management
- Report on exposure, trends, and risk posture to senior management and risk committees.
- Regulatory Compliance & Audit Support
- Leadership & Stakeholder Management
- Your Profile
- Relevant certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent.
- Experience Technical skills
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank.
- Proven track record in:
Questions sur cette offre
Quel salaire propose Union Bancaire Privée pour ce poste ?
Union Bancaire Privée indique CHF 83 500 - 126 500 bruts par an pour ce poste à Geneva, Switzerland. Il s'agit du salaire publié dans l'annonce d'origine (ou, si l'employeur ne précise pas de montant, d'une estimation réaliste pour le rôle et le secteur) — le calculateur de ce site le convertit en net réel une fois l'impôt frontalier et les cotisations sociales appliqués.
Est-ce un poste à temps plein, et quel type de contrat propose Union Bancaire Privée ?
Cette offre est un poste en temps plein. Le type de contrat affiché ici provient directement de l'annonce originale de l'employeur ; confirmez toujours les horaires exacts, le préavis et la durée d'essai avec Union Bancaire Privée pendant le processus de candidature, ces détails pouvant varier même au sein de la même catégorie de contrat.
Ai-je besoin d'un permis de frontalier pour un poste dans le canton de Genève ?
Les résidents UE/AELE domiciliés dans la zone frontalière du pays voisin du canton de Genève peuvent demander un permis G ; l'employeur suisse le dépose auprès de l'office cantonal des migrations après signature du contrat. Les règles de zone frontalière et les délais varient selon le pays voisin et le canton — confirmez les détails auprès de l'office des migrations du canton de Genève ou avec les RH pendant la candidature.
Comment postuler à ce poste chez Union Bancaire Privée ?
Utilisez le bouton « Postuler maintenant » sur cette page — il renvoie directement à l'annonce originale de Union Bancaire Privée sur iaadtu.fa.ocs.oraclecloud.eu, votre candidature arrive donc directement dans le système de suivi des candidatures de l'employeur. Frontaliere Ticino ne collecte ni ne transmet lui-même les candidatures.