About the job
- RISK ORM (RISK Operational Risk Management) is part of the Group BNP Paribas second line of defence (2LoD). It belongs to the Risk Function (RISK) of BNP Paribas and is under the responsibility of the Group Chief Operational Risk Officer.
- The department has responsibility for independently challenging and supervising the Operational Risk Management (ORM) of Group BNP Paribas activities on a worldwide scope. This is achieved by framing operational risk methodology for Group BNP Paribas, disseminating of a risk management culture across the Group, assessing the adequacy of the ORM set-up, controlling effectiveness of the Group Entities control environment, contributing to the detection, anticipation and response to risks, alerting BNP Paribas Management and RISK stakeholders on any significant risk issue and providing a consolidated view on Group Entities operational risk profile.
- As the second line of defence (2LoD) for Information and Communications Technology (ICT) risks (which are operational risks), RISK ORM has the responsibility to identify the key technology risks of the Bank and to influence Businesses, Functions and technology partners to make sound risk management decisions, working with the main Businesses and Functions teams such IT Operations, Cloud, Cybersecurity, Data, Finance, etc.
Your Main Activities Are
- Integrated in the Global Iberian Centre of Excellence, the candidate will be responsible for supporting RISK ORM management in the development and implementation of the ICT risk management framework
- As ICT Operational Risk Officer, the candidate will be responsible to perform the following main missions, assessing IT risks and providing advice to the BNP Paribas business lines (BL)
- Framework: to assist in the review, analysis and challenge of the ICT risk management framework and in particular the norms & standards, consistently with RISK ORM guidelines, and validate any exemption to these norms & standards, namely the ICT Risk and Control plans definition
- Risk Identification & Assessment: to challenge and verify on the first line of defence (1LoD) risk identification, ensure the consistency of potential incidents quantification, conduct independent ICT risk assessment (incident review, post mortem analysis), and validate closure of permanent control actions (controls implemented by 1LoD)
- Risk Treatment & Decision: to assist in overseeing the risk treatment process (risk acceptance, risk transfer, risk remediation) performed by the BNP Paribas Entities and their Departments, jointly participate to co-decision Committees (e.g. Change Management, New Activity, New Process, Vendor, Emergent Technologies) and/or share opinion on the ICT risks exposure with RISK ORM and 1LoD Management. Oversight the action plans defined to mitigate risk and to implement the Internal Audit, Regulators and other IT/Security authorities conclusions and recommendations
- Testing: to conduct independent testing and challenge on 1LoD (IT and operations) controls and oversight/perform 2LOD tests/vulnerability scans when required
- Plan: to assist to identify the main ICT risks priorities, clarify/ define the approach to perform the work aligned with BNP Paribas framework, manage relationship with stakeholders, and ensure deliverables agreed
- Risk Reporting, Monitoring & Alert: to support BNP Paribas Management and the RISK stakeholders on incidents and crisis management (e.g. security events, data leakage); to alert on critical points for attention to be raised to RISK Management
- Awareness / Training / Animation: to assist in promoting and driving awareness on ICT risks; to assist in organising risk meetings, forums and committees with community members
Profile and Skills to Success
- The successful candidate will have exposure to implementing risk management programs and/or working in an internal/external ICT assessment function within a reputed consultancy/global organisation, with robust knowledge of technology, risks, architectures and related tools. Prior ICT risk experience (IT, Cyber, Vendor management etc.), exposure to the Financial Services industry, experience with GRC tools and other risk management information systems is preferred
- Negotiation, Conflict Management and Presentation skills are necessary. The individual will assist in the preparation/contribution to the development of BNP Paribas RISK ORO IT independent testing controls and conduct Risk and Control Self-Assessment independent re-testing and validation on 1LoD set up and performed controls. Experience interacting with regulatory agencies is a plus
- 4+ experience specifically in technology risk assessments
- Bachelor degree in Information Technology, Information Security, Business or Risk Management (or equivalent professional qualification)
- Team player – focus on the success of the whole team. Working well both with others, as well as individually
- Excellent stakeholder management skills
- Experience in a Technology Risk, Information Security or an ICT Assessment and audit role
- Good listening and analytical skills – being able to come to a thoughtful and business focused conclusion quickly
- Motivated to pro-actively collaborate, challenge and contribute to promote a high qualified team of experts in several domains and with relevant previous experience in BNP Paribas, Finance Sector, or Consulting firms
- Flexibility to travel and to work in a global context
- Ability to co-operate and work well with others adopting an approachable style – Important as we work closely with a large and diverse set of stakeholders, cultures, and contexts
- Ability to see the stakeholder perspective, i.e. from a business and operational point of view, the most secure solution is not always workable or realistic considering costs and benefits
- Demonstrating a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate, and collaborate with many departments
- Adapting personal approach to suit situations, individuals, groups and cultures. Is flexible in relation to getting the job done
- Taking accountability for their actions and be open and honest when things have gone wrong, and celebrating successes when things have gone well
- Being rigorous and thorough, especially when logging and tracking issues through conclusion
- Ability to manage their workload as to meet the realistic targets and priorities set in conjunction with management
- Demonstrating a high-level of commitment and self-motivation, combined with enthusiasm and a genuine interest in the role of Risk Assessment in business
- Ability to express views clearly and fluently, both orally and in writing. Considers the audience, avoiding technical jargon wherever necessary and appropriate
- Ability to re-think, promote continuous improvement, presenting and implementing new solutions and approaches
- Good knowledge of ICT risks, IT Control, Information Security, Business Continuity, IT operations and IT Audit and assessment methodologies and concepts
- Experience working with ICT risks, business continuity, IT Management and operations, IT risk and IT audit teams
- Ability to articulate risk management concepts in business language
- Excellent written and verbal communication skills
- Proficient with Microsoft Office Suite
- Prior experience documenting tool requirements to support risk management
- Ability to travel to BNP Paribas and vendor sites, and perform assessments as necessary
- Proven ability to manage issues through to resolution; skilled at making judgment calls
- Ability to successfully multitask and complete difficult assignments within deadlines which may have short lead times
- Industry certifications (e.g. CISA, CRISK, COBIT) or willingness to obtain the same
- Works iteratively, delivering quickly and frequently to produce high quality documents and outputs which require little to no rework
- Multilingual capability (English is essential, French is preferred, other language is a plus)
- Be a role model, supporting and fostering a culture of good conduct
- Demonstrate proactivity, transparency and accountability for identifying and managing conduct risks
- Consider the implications of your actions on colleagues, partners and clients before making decisions, and escalate issues to your manager when unsure
- Be available to work in our Lisbon or Porto offices
Why joining BNP Paribas?
· Leading banking institution
BNP Paribas is a leader in the Eurozone, and a prominent international banking institution with strong roots in Europe's banking history. It has a presence in 65 countries, with around 190 000 Employees – including more than 145 000 in Europe.
· Our presence in Portugal
Since 1985, BNP Paribas was one of the first foreign banks to operate in the country. Today, the Group has around 7.100 employees across several entities operating directly in the territory, offering a wide range of integrated financial solutions to support its clients and their businesses.
· International reach
Thanks to its international presence and regular and close collaboration among its different entities, BNP Paribas has the resources to support all clients with financing, investment, savings and protection solutions that help make their projects a success. BNP Paribas holds key positions in its three core operating divisions:
- Retail Banking, a division that brings together all of the Group’s retail activities and specialised business lines;
- Investment & Protection Services that include specialised businesses offering a wide range of savings, investment and protection services;
- Corporate & Institutional Banking division that offers tailored financial solutions for corporate and institutional clients.
· Diversity and Inclusion commitment
BNP Paribas is an equal opportunity employer and proud to provide equal employment opportunity to all job seekers. We are actively committed to ensuring that no individual is discriminated against on the grounds of age, disability, gender reassignment, marriage or civil partnership status, pregnancy and maternity/paternity, race, religion or belief, sex or sexual orientation. Equity and diversity are at the core of our recruitment policy because we believe that they foster creativity and efficiency, which in turn increase performance and productivity. We strive to reflect the society we live in, while keeping with the image of our clients.
· Commitment towards work/life balance
At BNP Paribas we care about our employees wellbeing and promote a culture of good integration between work and rest. We believe our employees have rich personal lives outside of work, being fundamental to be disconnected from work to recharge both physically and mentally. Only through this balance we may all be at our best while working.
· Remote Working Conditions
At BNP Paribas, we embrace a Smart Working framework based on trust, autonomy and collaboration. Within this framework, eligible employees can benefit from flexible remote working modalities adapted to our hybrid working environment. To guarantee a comfortable and efficient working set-up, eligible employees are provided with both the office and home equipment, are entitled to an equipment allowance and can benefit from exclusive partnerships to purchase additional equipment at reduced prices.
To find out more on why you should join BNP Paribas visit https://bnpp.lk/why-BNP-Paribas-Portugal
* Please note that only applications submitted in English will be considered.
* In case you are selected for this role, further documentation will be requested to support your hiring process.