Business Information Risk Officer – fixed-term assignment
📍 Geneva
Rolle und Verantwortlichkeiten
Identify, assess, and monitor non-financial risks across COO-owned functions, including IT, Operations, Central File, Client Reception and Procurement. Maintain and enhance risk and control assessments across the CSO perimeter, including key risk indicators and mitigation plans aligned with the bank’s risk appetite. Update and maintain Business Impact Analyses for critical banking functions and processes, ensuring documentation is clear, practical and actionable. Support the review, testing and improvement of Business Continuity and Disaster Recovery Plans with relevant business stakeholders, in coordination with the CSO. Support the bank’s operational resilience framework, ensuring continuity of critical services under severe but plausible scenarios in collaboration with the CSO. Monitor dependencies on people, processes, technology, premises, and third-party providers and adequately documented within the ERM tools (ie. OPCIS). Manage periodic access recertification campaigns for the core banking system and other relevant bank-managed applications, ensuring timely follow-up and clear stakeholder coordination. Partner with IT and Information Security to assess risks linked to system changes, migrations, and incidents. Assess and monitor risks related to outsourced services and critical suppliers, in coordination with procurement and IT. Assess operational, access, and resilience risks arising from new products, process changes, and system implementations. Act as the primary point of contact for internal and external auditors for all audits covering the COO perimeter; coordinate, supervise, and contribute to audit activities, including planning, walkthroughs, evidence collection, and management responses for all COO division-related audits. Liaise with second-line risk control and internal audit to ensure alignment with the bank’s control framework and regulatory expectations.
Team / Beschreibung
This short-term assignment offers a unique opportunity to contribute quickly and visibly to the bank’s operational resilience and risk management framework. Working closely with senior stakeholders across Information Security, IT, Operations and control functions, you will help strengthen key governance processes, support critical initiatives, and gain hands-on exposure to the risk environment of a Swiss private bank.
Qualifikationen und Fähigkeiten
5–7 years’ experience in operational, IT, or business risk, including 2+ years in financial services or IT audit
Experience conducting Business Impact Analysis interviews and maintaining Business Continuity Plans
Solid knowledge of FINMA, LPD operational risk frameworks, BCM/DR, and outsourcing requirements
Experience with third-party/vendor assessments (ISAE reports) and operational controls
Good understanding of IT, information security, and ITIL frameworks
Proven experience in access management, including recertifications and segregation of duties
Strong analytical and problem-solving skills, balancing business priorities with risk
Ability to challenge audit findings and provide pragmatic recommendations
Project and change management experience, including complex operational or IT initiatives
Knowledge of critical functions, business impact analyses (BIA), and operational resilience
Curious and motivated to contribute quickly, while gaining deeper exposure to private banking operations and resilience practices
Strong written communication in French and English for reports, policies, and governance documentation
Excellent verbal and written command in French and English, German an asset
Bachelor’s degree in Computer Science, Management or equivalent
Current relevant professional certification in Information Security (CISSP, CISA, CISM) highly appreciated