First Line Risk & Security Engineer
Your working environment:
TouchPoint Platform is part-of ING’s “Think Forward” strategy to become one truly global bank, and is a key success factor on our path to become a financial services platform that extends beyond banking. Through our platform we provide a scalable foundation for platform business models and so position ING successfully in the new banking ecosystem.
A pragmatic approach for convergence is defined, moving ING towards a globally scalable banking platform. Key in converging towards this new model is developing harmonized business models and shared operating models. The globally scalable banking platform will create a differentiating customer experience and cater for growth by leveraging the innovation and development power within ING.
Foundational elements for the convergence towards the globally scalable banking platform are, among others, Global Data Management, Global Process Management and a Modular Architecture. The TouchPoint Open Banking platform will deliver the Modular Architecture.
The TPA Central Support team has recently been formed. It takes care of consistency and quality of the end to end Operations of the TPA services which consists of multiple components managed by several squads in different countries. Joining this team as First Line Risk & Security Engineer gives you the chance to make a large contribution to the further professionalization of the TPA organization.
Activities done by the TPA First Line Risk & Security Engineer:
- Establish and maintain TPA wide Risk & Security awareness in the context of ING’s Policy House, Minimum Standards and Security Controls in order to comply to global, regional and local laws and regulations.
- Coach, Train, Assist, Challenge TPA squads in their efforts to develop and maintain proven secure IT services through Business Impact Analysis, Risk Assessments, Operational Control Dashboards, OSGs, etc
- Establish (automated) reporting and dashboards on TPA Risk and Security Compliance status
- Establish and maintain close collaboration with TPA relevant Risk and Security departments (e.g. Global and local CISO, IRM, ORM)
- Stay up to date on all Risk and Security related subjects and provide relevant insight and guidance to TPA leadership
- Coordinate and work together with TPA squads on up to date, correct and timely risk identification and mitigation in iRisk (MIA’s and CAS audit findings)
- Set-up and facilitate Root Cause Analysis on risk and security related incidents, ensure follow-up actions and share lessons learned across TPA
- Drive efficiencies in risk management and processes in alignment with second line IRM and ORM
- Keep an overview of the overall TPA risk profile by reporting on Non Financial Risk Control scores, monitor and drive risk mitigation and facilitate internal and external audits being performed within the TPA domain.
- Prepare status reporting, requests for risk acceptance and advice TPA leadership towards regular Non Financial Risk Committee Tech and Bank
- Organize workshops and hackatons on specific risk and security subjects in the TPA domain
- Represent TPA Risk and Security in partner programs like Unite, PSD2 and ModelBank.
Your new job!
You are an enthusiastic Risk and Security Engineer with a Can-Do mentality and a focus on establishing a secure, resilient environment and services.
You recognize yourself in this profile
Competencies - Skills
- Experience working in a Dev/Ops team with Agile and ITIL practises
- Knowledge of ING’s Policy House, Minimum Standards, Non Financial Risk Control, Operation Control Dashboard (OCD) and understanding of required controls
- Content management: Confluence / OrangeSharing / SharePoint
- Agile planning and management : SNOW
- foundation in Linux and Apache Tomcat administration and troubleshooting;
- Foundational experience with automation;
- Be able to understand and formulate meaningful risk and security related metrics, reports and advice to all levels of the organisation (engineering, business and Sr Management);
- Experience taking a leading role in managing continuous improvements in a complex international context;
Your education and background
- Bachelor's Degree in Computer Science or related field
- Certifications of at least one of: CISSP, CISA, CISM
- Computer Science fundamentals in data structures
- Computer Science fundamentals in algorithm design, problem solving, and complexity analysis
- Good command of spoken and written English
- 36 - 40 uur