- Company Name
- GEC _ Global Experts Consulting
- Job Title
- IT RIsk Officer
- Job Description
-
**Job Title:** IT Risk Officer
**Role Summary:**
The IT Risk Officer designs, implements, and monitors a comprehensive information‑technology risk management framework for a regulated insurance environment. The role ensures compliance with prudential regulations, oversees internal controls over IT systems and applications, and collaborates with internal and external stakeholders, including vendors, auditors, and regulatory authorities.
**Expectations:**
- Deploy and maintain robust internal IT control frameworks.
- Conduct risk assessments and classify IT assets by criticality.
- Ensure vendor controls meet regulatory and internal standards.
- Deliver timely remediation and reporting on risk findings.
- Communicate findings and recommendations to senior management and regulatory bodies.
**Key Responsibilities:**
- Develop and enforce IT risk management processes based on recognized frameworks.
- Coordinate with risk teams, internal audit, external auditors, regulators, and IT vendors.
- Perform fit‑gap analysis of IT controls and evaluate vendor evidence.
- Manage risk control processes: asset classification, confidentiality, integrity, availability controls, change, incident, configuration, backup, and infrastructure management.
- Oversee governance, architecture, regulatory compliance, budgeting, vendor management, and application solutions.
- Monitor and verify remediation of control deficiencies, including follow‑up on risk acceptance.
- Produce regulatory reporting and executive summaries on IT risk and control status.
- Provide operational support and manage documentation tools related to IT governance.
**Required Skills:**
- In‑depth knowledge of IT risk frameworks (e.g., ISO 27001, NIST, COBIT).
- Experience with IT control domains: asset, change, incident, configuration, backup, infrastructure, and application management.
- Strong analytical skills for risk assessment, gap analysis, and control evaluation.
- Ability to communicate complex risk findings to technical and non‑technical audiences.
- Familiarity with regulatory requirements for the insurance sector (e.g., prudential frameworks).
- Project management and stakeholder coordination skills.
- Proficiency in documentation and reporting tools.
**Required Education & Certifications:**
- Bachelor’s degree in Information Technology, Computer Science, Risk Management, Finance, or a related discipline.
- Professional certifications such as CISA, CISSP, CRISC, or equivalent are preferred.