IT Risk Manager


Amsterdam
Permanent
Negotiable
Risk Management
PR/602094_1786374656
IT Risk Manager

We are representing a newly launched trading platform building critical infrastructure for the European fixed-income market.

You will be responsible for evaluating their technology infrastructure, monitoring and auditing critical technology providers, ensuring full compliance with the Digital Operational Resilience Act (DORA), and acting as a constructive, independent partner to the First Line (1LoD) operations team. Over time, this role is explicitly designed to evolve into a whole-of-business Enterprise Risk Management (ERM) mandate.

They operate in a heavily regulated, high-stakes environment. You must bring exceptional flexibility and a proactive, self-starter approach. The team steps in and steps up to solve critical issues, even when they fall outside a formal remit. A "no job too big, no job too small" work ethic is essential. You should be equally comfortable presenting risk strategy to the Senior Management Team as you are diving into the technical detail of a penetration testing report or a vendor SOC audit.

Key Responsibilities

  • Frameworks & Strategy: Review, implement, and monitor the firm's enterprise and IT risk management frameworks, ensuring strict alignment with DORA, ISO 27001, and relevant regulatory standards.
  • 2LoD Vendor & Operational Oversight: Act as the independent 2LoD partner to the Operations & Outsourcing Manager (1LoD), providing constructive challenge, risk reviews, and oversight of critical third-party technology providers.
  • Audits & Risk Assessments: Conduct independent risk assessments, gap analyses, and controls assurance across internal systems, critical IT vendors, and broader business operations.
  • Information Security & Resilience: Oversee information security controls, GDPR compliance, and Identity & Access Management (IAM) frameworks, while evaluating BCP and Disaster Recovery (DR) test outcomes.
  • Reporting & Incident Governance: Track enterprise risk metrics, manage IT incident escalation pathways, and present clear risk reporting directly to the CCO, COO, and CEO.

What We Are Looking For

  • Flexible Experience Profile: We welcome applications across a broad range of experience levels, from high-potential rising specialists to seasoned senior experts. Technical capability, execution mindset, and operational fit are prioritised over rigid tenure thresholds.
  • Risk & Assurance Background: Proven background in IT risk management, information security compliance, IT audit, or technology controls assurance (ideally within financial services, fintech, or critical infrastructure).
  • Regulatory & Framework Mastery: Strong familiarity with European technology regulations (DORA, NIS2) and major security/control frameworks (ISO 27001, NIST, SOC 2).
  • Domain Knowledge: General knowledge of capital markets, market infrastructure, or fixed-income trading is considered a strong plus.
  • AI-Forward Workflow: Practical experience with, or affinity for, using AI tools in a risk/IT context (e.g. threat modelling, control testing automation, or log/policy analysis) to scale lean operations.
  • Communication & Languages: Excellent ability to translate complex technical risks into clear, actionable business insights for leadership. Fluency in English is required.

FAQs

Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your CV and details on file so when we see similar roles or see skillsets that drive growth in organisations, we will always reach out to discuss opportunities.

Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.

We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business. 

That's why we recommend registering your CV so you can be considered for roles that have yet to be created. 

Yes, we help with CV and interview preparation. From customised support on how to optimise your CV to interview preparation and compensation negotiations, we advocate for you throughout your next career move.

Handpicked roles for you