IT Risks Specialist | French Speaker
Decskill · Porto, Portugal
Apply & track with Apply EdgeWe are growing. And we are looking for talented people.At Decskill, we believe that technological excellence is driven by human talent.We are an IT consulting company with more than 10 years of consolidated experience in the market, focused on building long-term relationships with both our clients and our people. Today, we are a community of over 800 professionals, working from Lisbon, Porto, and Madrid, contributing to impactful technology initiatives.As part of the Astek Group, we combine a strong local culture with a global presence, being active in around 23 countries across 4 continents. This allows us to offer an international context, diverse challenges, and long-term career opportunities, while staying close to our teams.We are looking for an IT Risks Specialist fluent in French!
Responsibilities
IT GovernanceEnsure the implementation of IT Governance in alignment with BNP Paribas Group policies, procedures, rules, requirements and controls.Support IT managers and technical teams in implementing IT Governance requirements, adapting them to the local context and formalizing the relevant controls and procedures.Monitor IT Governance compliance, track remediation plans and contribute to the establishment of the IT management system.Review and update procedures to ensure alignment with Group governance requirements, working with the relevant process owners.IT Risk ManagementEnsure the regular review of IT risks and maintain the IT risk register, including risk identification, assessment, treatment and reporting.Complete and update IT risk records in ServiceNow.Contribute to IT risk mappings, including ORSA and RCSA, and identify local controls and Key Risk Indicators (KRIs), where required.Monitor IT operational incidents, IT audits and the implementation of audit recommendations.Lead IT control plan campaigns, including organization, methodology support, review of results, evidence collection, action plans and reporting.Ensure the annual GKSP BI control campaign and record the results in ServiceNow.Monitor GKSP action plans and provide regular progress updates using Excel.Establish and maintain an inventory of Shadow IT.Promote IT risk awareness and a strong risk management culture.IT Governance & Risk ReportingPrepare IT risk and governance reports for local management, Cardif and BNP Paribas Group stakeholders.Consolidate and manage remediation plans relating to IT risks and non-compliance.Organize and present the quarterly IT Risk and Cyber Committee, covering Risk KPIs, IG recommendations, obsolescence, Shadow IT, historical incidents, CLV maturity in relation to Group governance and outsourcing, in collaboration with corporate teams.Support the CIO in preparing and organizing the quarterly IT Steering Committee.Liaise with Cardif headquarters teams on IT governance, risk reporting and specific information requests.Contribute to local and headquarters-level IT and Cyber Risk Committees and other governance bodies, including cybersecurity, obsolescence and asset committees.DORA GovernanceMonitor and support the deployment of DORA governance requirements at the local level.Prepare reports relating to DORA governance.Review intragroup contracts with subcontractors and ensure compliance with DORA contractual clauses.Support the implementation of governance requirements, including the deployment of relevant services and specific due diligence activities.Organize and monitor DORA steering committees with the relevant entities and subcontractors.Participate in the contractual review of suppliers.
Requirements
Education & ExperienceExperience in IT Governance, IT Risk Management, IT Security or a related field.Knowledge of the Finance and Insurance sectors is required.Experience with IT risk assessments, governance frameworks, internal controls, compliance monitoring and remediation plans.Familiarity with regulatory requirements and third-party risk management, particularly DORA.Technical SkillsKnowledge of IT governance and risk management standards and frameworks, such as COBIT, COSO, ISO 31000, ITIL, NIST and DORA.Expertise in IT and IT Security.Experience using Microsoft Office applications, particularly Excel, and ServiceNow.Ability to prepare risk reports, monitor KPIs and track remediation actions.Understanding of IT controls, risk registers, operational incidents, audit recommendations and compliance monitoring.Language SkillsFrench: C1 level — mandatory.English: C1 level — valuable.Soft SkillsStrong analytical and problem-solving skills.Excellent organizational skills and attention to detail.Ability to coordinate multiple stakeholders and follow up on remediation actions.Strong communication and reporting skills, including the ability to present risk-related information to committees and senior stakeholders.Ability to collaborate with IT teams, Security teams, process owners and corporate stakeholders.Proactive approach to risk identification, governance implementation and continuous improvement.Are you looking for an environment that values curiosity and commitment? Here, your contribution has real impact and individual growth is taken seriously.Find with us the right opportunity to grow!What you can expect from us:Long-term projects with national and international context (if applicable).Opportunities to grow technically and professionally.A people-first culture, focused on transparency and trust.Teams that value ownership, collaboration and stability.If you’re interested in this job, please send your CV to cesaltina.abreu@decskill.com, with the reference “CA/ITRisksSpecialist ”.Thank you! :)Decskill is committed to equality and non-discrimination with all our talents. We recruit and promote talent based on diversity and inclusion, regardless of age, gender, ethnicity, race, nationality or any other form of discrimination incompatible with the dignity of the human being.