BW

Senior IT Risk Specialist

Hiring from
United Arab Emirates
Work type
Remote
Posted
Is this job info correct?

508,921 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description
We're Hiring: Senior IT Risk Specialist

Location: United Arab Emirates (Remote)

Employment Type: Full-Time

Experience Level: Senior

Work Arrangement: Fully Remote

About Us

We are a globally focused organization committed to strengthening technology resilience, information security, enterprise risk management, and operational performance across diverse digital environments. Our teams collaborate across Information Technology, Cybersecurity, Enterprise Risk, Compliance, Internal Audit, Engineering, Infrastructure, Data, and business functions to identify technology risks and maintain a resilient operating environment.

Our risk teams combine structured risk assessment, control evaluation, quantitative and qualitative analysis, governance, and continuous monitoring to help the organization understand technology exposure and make informed decisions about risk treatment and investment.

The Role

We are seeking an experienced Senior IT Risk Specialist to lead information-technology risk identification, assessment, monitoring, reporting, control evaluation, remediation, and governance activities across the organization's technology environment.

The ideal candidate will provide independent and risk-based oversight of IT risks covering infrastructure, applications, cloud, cybersecurity, data, third parties, technology operations, resilience, and transformation initiatives, while working closely with technology and business leaders to strengthen controls and reduce material risk exposure.

Key Responsibilities
  • Develop and implement IT risk-management strategies, frameworks, policies, standards, and procedures.
  • Maintain a comprehensive IT risk-management framework aligned with enterprise risk-management objectives.
  • Identify and assess technology risks across applications, infrastructure, cloud, networks, data, cybersecurity, operations, and third-party services.
  • Conduct risk assessments for new technologies, systems, applications, projects, vendors, and business initiatives.
  • Evaluate inherent and residual technology risk using defined assessment methodologies.
  • Develop and maintain IT risk registers covering identified risks, owners, controls, ratings, treatment plans, and target dates.
  • Facilitate risk assessments with technology owners, business stakeholders, security teams, and control owners.
  • Analyze technology risks based on likelihood, impact, asset criticality, threat exposure, vulnerability, and control effectiveness.
  • Establish appropriate risk-rating criteria and escalation thresholds.
  • Monitor changes in IT risk exposure and identify emerging risks requiring management attention.
  • Evaluate the effectiveness of technology controls in mitigating identified risks.
  • Identify control gaps, weaknesses, exceptions, and areas of excessive risk exposure.
  • Coordinate development and implementation of risk-treatment and remediation plans.
  • Track technology-risk remediation activities through closure.
  • Validate remediation actions and assess whether residual risk has been appropriately reduced.
  • Monitor overdue risk treatments and escalate significant delays or unresolved exposures.
  • Review and challenge risk acceptance requests, compensating controls, and risk exceptions.
  • Maintain a structured technology-risk exception and waiver process.
  • Ensure risk acceptances have appropriate ownership, justification, duration, approval, and review requirements.
  • Assess IT risks associated with cloud migration, digital transformation, application modernization, and technology implementation programs.
  • Support risk assessments for artificial intelligence, automation, emerging technologies, and new digital services.
  • Evaluate risks associated with cybersecurity threats, vulnerabilities, security incidents, and technology weaknesses.
  • Coordinate with Information Security teams to understand cyber-risk exposure and control effectiveness.
  • Assess identity and access-management risks, including privileged access, authentication, authorization, and access lifecycle controls.
  • Evaluate infrastructure and network risks, including availability, capacity, configuration, resilience, and security.
  • Assess application risks covering software development, change management, architecture, interfaces, dependencies, and application security.
  • Evaluate data risks involving confidentiality, integrity, availability, classification, privacy, retention, and data loss.
  • Assess technology resilience, business continuity, disaster recovery, backup, and recovery capabilities.
  • Evaluate IT service-management risks involving incident, problem, change, configuration, release, and service-level management.
  • Assess risks associated with technology outsourcing, managed services, cloud providers, SaaS platforms, and other third parties.
  • Coordinate with Third-Party Risk Management teams to assess supplier technology and cybersecurity risks.
  • Review supplier security assessments, audit reports, certifications, penetration-testing reports, and remediation commitments.
  • Assess risks arising from technology dependencies, concentration, single points of failure, and critical service providers.
  • Support technology risk assessments for mergers, acquisitions, integrations, reorganizations, and major system changes.
  • Evaluate risks associated with legacy systems, unsupported technologies, technical debt, and aging infrastructure.
  • Monitor technology-risk indicators, key risk indicators, control metrics, incidents, vulnerabilities, audit findings, and other risk signals.
  • Develop and maintain IT Key Risk Indicators and Key Performance Indicators.
  • Establish thresholds and triggers for risk escalation and management intervention.
  • Analyze risk trends and identify recurring or systemic technology-risk issues.
  • Develop dashboards and management reports covering IT risk exposure, trends, remediation, exceptions, and emerging threats.
  • Prepare executive-level risk reporting for senior management and risk committees.
  • Provide clear recommendations to technology leadership on risk mitigation priorities and control improvements.
  • Support internal and external audits by providing IT risk registers, assessments, control documentation, and remediation evidence.
  • Coordinate responses to audit findings and regulatory observations related to technology risk.
  • Monitor remediation of audit findings and validate closure where appropriate.
  • Support regulatory examinations, customer assurance reviews, and technology due-diligence activities.
  • Maintain IT risk policies, methodologies, procedures, risk taxonomies, control libraries, and governance documentation.
  • Establish consistent IT risk assessment standards across technology functions and business units.
  • Develop risk-awareness and training materials for technology teams and control owners.
  • Promote risk ownership and accountability throughout the technology organization.
  • Facilitate risk workshops, control assessments, and management discussions on significant technology exposures.
  • Provide independent challenge to technology decisions where risk implications are significant.
  • Partner with Enterprise Risk, Compliance, Information Security, Internal Audit, Legal, Privacy, and business teams.
  • Evaluate opportunities to automate IT risk monitoring, assessment workflows, evidence collection, and reporting.
  • Support implementation and optimization of GRC and IT risk-management platforms.
Key Performance Indicators
  • IT risk assessment completion rate
  • IT risk-register completeness
  • Risk assessment turnaround time
  • Risk identification effectiveness
  • High-risk issue identification
  • Critical IT risk remediation rate
  • IT risk remediation completion rate
  • Average risk remediation time
  • Overdue risk-treatment rate
  • Risk acceptance review timeliness
  • Risk exception closure rate
  • Residual-risk reduction
  • Control effectiveness rate
  • IT control deficiency rate
  • Recurring risk reduction
  • Technology-risk exposure trend
  • Key Risk Indicator monitoring coverage
  • KRI threshold breach response time
  • Emerging-risk identification rate
  • Technology project risk assessment coverage
  • Cloud-risk assessment coverage
  • Application-risk assessment coverage
  • Infrastructure-risk assessment coverage
  • Third-party IT risk assessment coverage
  • Critical supplier risk coverage
  • Cyber-risk integration effectiveness
  • IT resilience risk coverage
  • Business-continuity risk assessment completion
  • Disaster-recovery risk assessment completion
  • Audit finding remediation rate
  • IT audit issue closure time
  • Regulatory finding remediation
  • Risk reporting timeliness
  • Risk reporting accuracy
  • Risk dashboard adoption
  • Risk-data quality
  • Risk-owner response rate
  • Risk-treatment effectiveness
  • Risk escalation timeliness
  • Technology risk-policy compliance
  • GRC workflow adoption
  • Risk automation rate
  • Manual risk-management reduction
  • Stakeholder satisfaction
  • Risk-awareness training completion
  • IT risk governance maturity
  • Overall technology-risk reduction
Ideal Candidate

The successful candidate should have strong experience in IT risk management, technology risk, information-security risk, IT governance, cybersecurity governance, technology controls, or enterprise risk management, preferably within complex enterprise, financial-services, technology, telecommunications, professional-services, or highly regulated environments.

The candidate should demonstrate:

  • Strong understanding of IT risk-management principles and frameworks.
  • Proven experience identifying, assessing, monitoring, and reporting technology risks.
  • Strong knowledge of risk and control assessment methodologies.
  • Experience developing and maintaining IT risk registers and risk taxonomies.
  • Strong understanding of inherent and residual risk concepts.
  • Experience evaluating technology controls and control effectiveness.
  • Strong knowledge of information-security and cybersecurity risk.

Similar jobs

Apply on LinkedIn