We are looking for

IT Risk Officer

Back to offers list
Retour

IT Risk Officer

  • Permanent
  • Full time
  • Mumbai, Tamil Nadu, India
Apply
Job type
Permanent
Brand
BNP Paribas India Solutions
Schedule
Full time
Reference
1234567890100119361
Last update 10.09.2026

Job Title: IT Risk Officer

Department: ISPL Cardif IT

About Business line/Function: 

BNP Paribas Cardif is a world leader in bancassurance partnerships, providing its customers with products and services that let them realise their goals while protecting themselves from unforeseen events. BNP Paribas Cardif is committed to having a positive impact on society and to making insurance more accessible. A subsidiary of BNP Paribas, the insurer has a unique business model anchored in partnerships. It creates solutions for more than 500 partner distributors in a variety of sectors – including banks and financial institutions, automotive sector companies, retailers and telecommunications companies – as well as for financial advisors and brokers who market the products to their customers. With a presence in 30 countries and strong positions in Europe, Asia and Latin America, BNP Paribas Cardif is a global specialist in personal insurance, the world leader in creditor insurance and a major contributor to financing for the real economy. With 9,000 employees worldwide, BNP Paribas Cardif had gross written premiums of €40.5 billion in 2025.

BNP Paribas Cardif IT is a global organization with about 3000 IT staff across Europe, Latin America and Asia. Its mission is to drive and support our business strategy across all regions by leading digital transformation and delivering secure, resilient, and scalable industrial technology solutions. It is committed to enabling innovation, strengthening cyber resilience, and fostering collaboration and diversity across markets and teams to create exceptional value for our customers and partners, and ensure sustainable growth for BNP Paribas Cardif at the global scale.

Position Purpose: The IT Risk Officer (ITRO) is responsible for identifying, assessing, monitoring, and supporting the mitigation of IT and Cyber risks across the regional scope. Acting as the regional point of contact for Corporate IT Risk, second-line control functions, operational permanent control stakeholders, and local entities, the ITRO deploys the IT Risk Management (ITRM) framework and ensures that risk management and permanent-control requirements are embedded in day-to-day IT operations. The role consolidates local risk and control information, challenges material exposures, coordinates governance and remediation, and provides the CIO and senior leadership with clear, actionable insight into the risk profile, control effectiveness, and resilience of technology services.

Responsibilities

Direct Responsibilities

A. IT Risk Management (ITRM) Implementation

· Regional ITRM Execution: Run the regional branch of the IT Risk Management framework in alignment with Group and Cardif methodologies, policies, and risk-appetite principles.

· Framework Roll-out: Lead the implementation of IT risk management practices, tools, and guidance across regional IT entities and business lines, supporting local ITROs through awareness, training, and assistance.

· GKSP Validation Governance: Ensure the quality of GKSP control results through a documented regional validation and check-and-challenge process performed in accordance with Cardif Global ITRO guidelines. Ensure that justifications and supporting evidence substantiate assigned ratings and that any exception or reduction in the validation scope is formally documented and approved by the Global Cardif ITRO.

· Risk Portfolio Management: Manage and consolidate the portfolio of IT and Cyber risk remediation actions, monitor delivery, identify delays or dependencies, and escalate material deviations.

· Corporate and Local Coordination: Act as the regional point of contact between Corporate IT Risk, control functions, and local IT entities for matters within the role’s scope.

B. Risk Identification & Analysis

· Risk Identification: Proactively identify IT and Cyber risks arising from regional activities, infrastructure, third parties, and evolving digital services.

· Impact and Root-Cause Analysis: Perform and challenge analyses of root causes, business impacts, likelihood, existing controls, and residual exposure.

· Risk Cartography and RCSA: Ensure that material IT and Cyber risks are adequately reflected in relevant RCSA assessments; analyse whether mandatory assessments or additions to the risk baseline are required and coordinate the corresponding requests.

· Heatmap-based RCSA Evidence: Ensure that local first-line teams integrate the IT and Cyber Risk Heatmap presented to the IT & Cyber Risks Committee into each relevant RCSA exercise, using it as documented evidence to support risk ratings. Share the latest Heatmap with the second line of defence in due time to facilitate its RCSA check-and-challenge.

· Risk Consolidation and Challenge: Consolidate major risks reported by local ITROs, check and challenge their assessment, identify alerts, and request proportionate remediation actions where necessary.

· Regional Risk-Card Quality Review: Develop, maintain, and apply a regional IT risk-card management and oversight procedure approved by the Regional COO and Global Cardif ITRO. Perform periodic quality reviews of active risk cards to ensure that cards are well structured, reviewed on time, limited to coherent risk events and asset scopes, and that inherent and residual assessments are supported by complete justification and evidence.

· Taxonomy: Propose and support updates to IT process, risk-event, and control taxonomies when regional experience indicates that clarification or enhancement is needed.

· Assessment Exercises: Lead or contribute to periodic reviews, self-assessments, scenario analyses, and control exercises designed to evaluate the effectiveness of IT and Cyber risk management.

C. Reporting & Governance

· Governance: Organize regional IT risk committees and maintain governance that enables management to periodically review consolidated risk exposure, control results, incidents, and remediation progress.

· Committee Coverage of Local Oversight: Ensure that Local Key Surveillance Points and outstanding local ICT audit recommendations across regional entities are integrated into both local and regional IT & Cyber Risk Committees, with dedicated reporting on status, ageing, accountable owners, due dates, remediation progress, overdue items, decisions, and escalations.

· Recommendation Monitoring: Maintain committee-level oversight of remediation actions arising from IT risk reviews and audit recommendations, including progress against agreed milestones and the evidence required for sustainable closure.

· Executive Reporting: Prepare and present clear reports on IT and Cyber risk management to the regional CIO, Corporate IT Risk, and relevant governance committees.

· Continuous Monitoring: Monitor the effectiveness of mitigation measures, the quality and timeliness of remediation plans, and closure evidence; escalate overdue or insufficient actions.

· Control Framework Coordination: Coordinate the regional deployment of applicable Group and Cardif control plans, provide execution guidance and scoring criteria, assess their adequacy in the regional context, analyse local results, and initiate transversal action plans when required.

· Audit and Compliance Liaison: Act as a key point of contact for internal control, Internal Audit, second-line functions, and regulatory stakeholders regarding IT risk and control effectiveness.

Technical & Behavioral Competencies

Specific Qualifications:

  • Risk Analysis & Anticipation: Proven ability to identify emerging threats and perform sophisticated risk assessments.
  • IT Knowledge: Strong understanding of IT infrastructure, services, and the technical landscape of a modern insurance organization.
  • Consulting & Influence: Ability to act as an internal consultant, advising technical teams on how to integrate risk management into their workflows.
  • Resilience & Continuity: Knowledge of IT continuity and resilience strategies to ensure business stability.

Skills Referential (Required knowledge, skills and abilities)

Technical Skills:

· IT Security & Cybersecurity: Strong understanding of cybersecurity principles, threat landscapes, and security controls.

· Internal Audit Knowledge: Familiarity with audit methodologies and the ability to assess the effectiveness of internal controls.

· Risk Management Frameworks: Knowledge of IT Risk Management (ITRM) processes and regulatory compliance requirements.

· Safety & Security: Awareness of physical and digital safety/security protocols within an IT environment.

Behavioral Skills: 

· Analytical Rigor: Ability to identify, analyze, and prioritize complex risks and their potential impacts.

· Communication & Influence: Ability to report technical risks to senior leadership (CIO) and influence technical teams to implement remediation actions.

· Organization & Autonomy: Proven ability to manage a portfolio of projects and organize local risk activities independently.

· Collaboration: Ability to work cross-functionally with IT, Security, and Audit teams.

Education Level: Bachelor’s or Master’s degree in IT

Experience level: Minimum 5 years of experience in IT Risk Management, IT Audit, or Cybersecurity within a large-scale, regulated corporate environment.

Location: Chennai

About BNP Paribas Group:

BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.

About BNP Paribas India Solutions:

Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.

Commitment to Diversity and Inclusion

At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.