Overview
As the ETRM advisor for the EMEA region, you drive technology and cyber risk oversight to align IT and business objectives with regulatory expectations. You’ll partner with risk professionals to embed risk frameworks across global and local entities, communicating complex risks to non‑technical audiences. This role supports risk reduction initiatives and transforms how EMEA risk is managed within a growing environment. You will influence governance, policy execution, and stakeholder engagement to sustain a world‑class risk management program.
Pay / Benefits
- flexible work-life support
- paid volunteer days
- vibrant employee networks
- inclusive development opportunities
Responsibilities
- Lead real-time risk oversight within the ETRM Service Catalogue
- Conduct technology risk assessments and material risk identification
- Support regulatory audits and client engagements related to technology risk
- Collaborate with global ETRM and ERM teams to align regional and global programs
- Develop and maintain EMEA stakeholder relationships in IT and business units
- Communicate risk exposure and escalation channels effectively
- Oversee governance, policy, and framework execution for EMEA
- Manage due diligence for new clients, vendors, and M&A activities
- Monitor emerging technology risks and trends in financial services
- Deliver projects independently and prepare risk/board presentations
Key requirements
- EMEA regulatory knowledge (FCA, PRA, ECB)
- Experience with DORA, BCBS 239, EU AI Act
- IT audits or risk assessments, ITGC, cybersecurity controls
- Knowledge of Information Security Frameworks (NIST, ISO 27000, CSA CCM) and ITIL
- Experience with AI adoption and AI risk management
- Ability to translate technical issues for non‑IT stakeholders
- Strong communication, negotiation, and cross‑cultural skills
- Minimum 10 years in financial/technology sectors
- Project management, critical thinking, problem‑solving, decision-making
- Exceptional communication and interpersonal skills
- Ability to influence and implement decisions
- Multitasking and prioritization
- Regulatory IT risk knowledge (EMEA)
- IT risk management and control frameworks
- IT risk assessments and ITGCs
…
