
gwp group · Zürich
DEINE AUFGABEN * Du engagierst Dich aktiv im Business Development und erhältst die Chance, das Beratungsangebot im Bereich ICT und Cyber Security neu aufzu...
Security neu aufzubauen.
Anforderungen und operationeller Resilienz: von der Reifegradbewertung bis zur Umsetzungsbegleitung
Stellungnahmen und Management-Reportings
und gestaltest den Governance-Rahmen mit
Projektbudget.
Auditor
(Beratung, Big4 oder Inhouse-Funktion)
hast sehr gute Deutsch- sowie Englischkenntnisse.
Hinweis: Diese Stelle ist für Direktbewerbungen ausgeschrieben – wir freuen uns auf deine persönliche Bewerbung!
DEINE AUFGABEN * Du berätst Finanzdienstleister bei aufsichtsrechtlichen Fragen und der Einhaltung sowie Umsetzung von Compliance-Vorschriften und bei weiteren finanzmarktrechtlichen Themen, u.a. im Bereich FIDLEG, GwG, Corporate Governance, Marktverhalten, Cross-Border, Bewilligungsverfahren. * Du überprüfst die Einhaltung der aufsichtsrechtlichen Vorgaben zur Bekämpfung der Geldwäscherei und Terrorismusfinanzierung sowie weiteren Compliance Themen bei Finanzdienstleistern in der Schweiz. * Du führst regulatorisch getriebene Gap- / Impactanalysen durch und leitest daraus Handlungsempfehlungen ab. * Du entwickelst dein technisches Know-how und deine Soft Skills stetig weiter durch on- und off-the-job-Trainings. DEIN PROFIL * Du hast einen Bachelor- / Masterabschluss in Wirtschaft, Recht oder einem verwandten Fachgebiet, oder vergleichbare Berufsausbildung mit Bezug zum Finanzsektor. Du hast bereits min. zwei Jahre relevante Arbeitserfahrung im Compliance- oder Big4-Umfeld gesammelt. * Du bist an juristischen und / oder regulatorischen Fragestellungen sowie betriebswirtschaftlichen Zusammenhängen interessiert und arbeitest gerne selbständig sowie kundenorientiert in einem spezialisierten Team. * Du hast eine schnelle Auffassungsgabe und bereits erste Erfahrung im Umgang mit Kunden, ebenfalls bist du motiviert, dich on- und off-the-job weiterzubilden. * Du bist engagiert und dienstleistungsorientiert, verfügst über einen lösungsorientierten sowie analytischen Arbeitsstil und hast sehr gute Deutsch- sowie Englischkenntnisse. Hinweis: Diese Stelle ist für Direktbewerbungen ausgeschrieben – wir freuen uns auf deine persönliche Bewerbung!
At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business. We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in 2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent - serves as a massive catalyst for our growth, allowing us to offer premier investment experience. ABOUT THE ROLE: As the Lead IT Risk Manager, you will play a pivotal role in owning and evolving our IT Risk Framework within the second-line risk function. Operating in a highly growth-oriented and regulated financial services environment, this role demands an exceptional blend of technical governance expertise, independent challenge capabilities, and strategic stakeholder management. You will serve as the primary second-line authority for IT risk matters, providing oversight to the first-line IT GRC team, leading comprehensive risk assessments, and ensuring strict alignment with Upvest's overarching Risk Appetite Framework. WHAT YOU’LL DO: Risk Framework Ownership & Oversight * Own and evolve the IT Risk and Business Continuity Management Framework within the second line, keeping it scalable as the business grows. * Provide independent second-line oversight and challenge to the first-line IT GRC team on the design and effectiveness of IT controls. * Lead IT risk identification, assessment, and mitigation across cyber, technology resilience, third-party, and data security, linking back to the Risk Appetite Framework. IT Governance & Compliance Management * Mature the ISMS by guiding policies, standards, and procedures with the relevant process owners. * Define baseline controls and run continuous ISMS maturity assessments against ISO/IEC 27001:2022 and related standards. * Oversee third-party IT risk, internal technology exposures, and business continuity assessments. IT Audit & 2nd Line Assurance * Drive second-line assurance reviews and deep-dives across critical IT risk domains, reporting findings and tracking remediation to closure. * Support internal and external audits, including IT General Controls (ITGC) and Application Controls. * Run preliminary internal IT audits to prepare engineering, product, and business teams for official engagements. Regulatory Alignment & Stakeholder Management * Lead Upvest's DORA obligations, including ICT risk management, incident classification, and third-party ICT risk oversight. * Track the regulatory landscape (BaFin, EBA, ESMA, ECB) and translate requirements into actionable risk guidance. * Act as the primary second-line contact for IT risk, reporting posture and material risk events to senior stakeholders, the C-suite, and the Risk Committee WHAT YOU BRING: * Education: University degree in Computer Science, Information Technology, Information Security, or an equivalent academic/professional background. * Experience: Minimum of 5+ years of progressive professional experience in IT Governance, Risk, Compliance, and Security (IT GRC / IT Security) within a regulated financial institution, bank, fintech, or fast-scaling B2B platform environment. * Technical Depth: Deep operational understanding of IT governance standards (e.g., ISO 27001), regulatory risk requirements (BaFin BAIT/MaRisk), and modern resilience standards like DORA. * Communication Skills: Exceptional verbal and written articulation skills in English, with a proven ability to engage credibly with a multilingual international stakeholder base, technical engineering leads, and C-level executives. * Mindset: A strong product engineering and security-focused mindset, combined with commercial pragmatism and the ability to operate confidently under ambiguity. HOW WE UPVEST IN YOU: * Best-in-class AI tools: Every Upvenger has €20,000 per year to spend on the best AI tools available — so you're always working with the most powerful models and tooling on the market. * Impact-driven work: We’re building the infrastructure that will power the future of investing in Europe. It’s complex, ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no limits. * Wellbeing: Recharge with 30 days of annual leave and maintain a healthy lifestyle with sports benefits. Access confidential professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a one-month fully paid sabbatical after every 4 years of working at Upvest. * Development: Growth is in our DNA. Each Upvenger has access to a personal development budget and the freedom to decide how to use it. * Flexible work environment: Work from any of our hubs in Berlin, London or Tallinn hybrid or remotely across Europe, depending on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose. * Compensation and equity: We believe that all Upvengers contribute to our success and deserve a competitive, above-market salary and a participation in our employee equity program. * Team celebrations: Participate in company-wide events, such as UpFest, dinners, offsites and our Holiday party, to connect with colleagues and celebrate our achievements. * Inclusion: We’re committed to a culture where everyone belongs and thrives. Our Employee Resources Groups foster inclusion and connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies. OUR VALUES: * Make it easy for others. We simplify the complex and act with the best intentions * Own the outcome. We are proactive, fast and confident to get the job done, valuing progress over perfection. * Rise to the challenge. We aim high and push the boundaries. We stay curious, learn and celebrate our wins together. * Tell the story. We start with the Why to align on purpose. We are transparent and share knowledge to empower and inspire others. Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
🚀 We’re on a mission to make money work for everyone. We’re waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers! We’re not about selling products - we want to solve problems and change lives through Monzo ❤️ ---------------------------------------------------------------------------------------------------------------------------------- 📍Dublin, Ireland |💰 €68,00 - €83,000, Incentive Awards tied to your performance ➕ benefits | Hear from the team ⭐Our Risk and Compliance team Monzo Bank Europe (MBEU) is the Irish-based subsidiary of the Monzo Group and the strategic launchpad for our expansion across the European Union. We are looking for a seasoned Risk Assurance Manager to provide independent Second-Line of Defence (2LOD) assurance over the design and effectiveness of the bank’s risk management framework, controls and processes. You will ensure that key risks are managed in line with regulatory expectations, internal policies and our risk appetite, providing robust oversight and challenge across the full spectrum of the bank’s risk universe. In this role, you will ensure the bank complies with: * Irish Regulatory Obligations, including CBI, CPC, AML/CFT legislation, and the Companies Act. * EU Regulatory Requirements, including DORA, EBA Guidelines, ECB/SSM expectations, and GDPR. * Internal Governance, including adherence to risk frameworks, policies, and risk appetite. Reporting directly to the Director of Risk Assurance, MBEU, you will design, execute, and report on 2LOD assurance reviews covering conduct, financial crime, fraud, credit, and financial risks. Your remit will also include operational risk, ICT and information security, outsourcing, data protection and governance structures. This role is critical in fostering a sound risk culture and supporting senior management and the Board in their oversight responsibilities.You will be instrumental in providing stakeholders with the assurance needed to ensure our growth is safe, resilient and compliant. The role you are applying for is a Controlled Function (CF-2) within the meaning of the Central Bank Reform Act, 2010. For this role, appointment will be conditional on Monzo being fully satisfied that the appointee meets the requirements as set out in the Fitness and Probity Standards 2018 issued by the Central Bank of Ireland. As a CF, the role holder will be subject to Conduct Standards under the Central Bank of Ireland Individual Accountability Framework and will be required to take reasonable steps to ensure that the relevant conduct standards are met. 🔑You’ll play a key role by... * Assurance Plan: Planning, coordinating and executing comprehensive risk assurance activities, including effectiveness reviews to ensure EU-wide adherence to the enterprise risk framework. * Thematic Reviews: Conducting targeted thematic reviews across specific risk areas (e.g., conduct, compliance, financial crime, IT, prudential and strategic risk) to provide in-depth assurance over design adequacy and operating effectiveness. * Remediation: Identifying areas for improvement within the risk management framework and control environment, recommending practical, impactful solutions and tracking remediation efforts to completion. * Stakeholder Engagement: Proactively engage with business and risk stakeholders to understand Monzo Europe’s products and risk profiles, fostering a collaborative and transparent risk culture. * Strategic Planning: Contributing to the annual risk assurance plan by providing insights gathered through continuous monitoring of regulatory trends and horizon scanning, market practices and upstream developments. * Framework Governance: Contribute to the continuous improvement of the 2LOD Risk Assurance Framework, Methodology and Terms of Reference to ensure they remain fit-for-purpose and market-leading. * Cross-Functional Collaboration: Partnering closely with First-Line of Defence (1LOD) control testing, Group 2LOD, and Internal Audit to ensure alignment while maintaining strict independent challenge. * Reporting & Governance: Contributing to risk governance by reporting thematic insights, trends and remediation progress to senior management committees. * Risk Culture: Promote a strong risk and compliance culture, awareness and training programs across the organisation. 🤩 We’d love to hear from you if… * You have a strong background in risk assurance, internal audit and/or risk management within banking or fintech in the European regulatory and financial services landscape. * You have a proven ability to plan and execute diverse assurance activities, from effectiveness reviews to thematic deep dives, with a clear focus on root cause analysis. * You’ve led reviews across a wide range of risk areas, including ICT and Information Security, Financial/Prudential (Liquidity, Treasury, Capital), Fraud and Financial Crime (AML/Sanctions), Operational and Conduct Risk (Consumer Protection/Vulnerability). * You possess a deep understanding of risk and control frameworks (e.g., COSO, ISO) and can practically apply this knowledge to 2LOD oversight. * You are skilled in the hands-on identification and testing of risks and controls, with a keen eye for detail and potential weaknesses. * You have a track record of identifying gaps within risk management processes and frameworks and recommending practical, high-impact solutions. * You combine sharp analytical skills with the ability to communicate findings clearly to diverse stakeholders, offering constructive challenge and influencing at all levels. * You have strong data analysis skills, you know how to extract, interrogate and present data in a way that makes complex issues easy for stakeholders to understand. * You’re proficient in Google Suite and can build high-quality decks for Committee and Board reporting. Experience with SQL or Python is a distinct advantage. Not ticking every box? That’s totally okay! Studies show that women and people of colour might hesitate to apply unless they meet every single requirement. At Monzo, we’re dedicated to creating a diverse and welcoming team. If you’re passionate about this role and keen to learn and grow with us, we encourage you to apply— even if you don’t have everything that's listed just yet. Drop us your application, we’d love to hear from you! 🙌What’s in it for you 💰A salary range of €68,000 - €83,000 and Incentive Awards tied to your performance 📍This role will have a hybrid working model, based in our Dublin office 2 - 3 days a week ⏰We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. 🏝 Annual Leave - 34 days including public holidays (24 holiday days + 10 public holidays) 📚€1,200 learning budget each year to use on books, training courses and conferences. 🏥Private healthcare scheme 💰Pension scheme: the minimum contribution is 4% and Monzo matches any additional contributions that you make up to a maximum of 6% 💛Wellbeing benefits: financial education, women’s and men’s health support, mental health benefits, including coaching and counselling 🌈 The application journey has 4 key steps * An introductory call with a member of our hiring team * An initial call with the hiring manager * A series of role specific and behavioural interviews * A final call with a member of our Executive team This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here. We’ll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don’t miss out. If you're successful in applying for this role, we'll work with you to find a start date. In some cases, there might be a delay in when you can be released from your current role so that we can make sure things continue to run smoothly. We’ll be sure to communicate this with you and keep you updated. #LI-ÉS1 ---------------------------------------------------------------------------------------------------------------------------------- Equal opportunities for everyone Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, 2026 Diversity and Inclusion Report and 2025 Gender Pay Gap Report. We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage 😊