Skip to content

Open nowPosted 20 days ago

IT and IS Risk Senior Specialist

Workable (global search)108,016 open roles

Where
Baku, Azerbaijan
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT and IS Risk Senior SpecialistWorkable (global search) · Baku, Azerbaijan
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 20 days ago

Workable (global search) median: 7 days open

The posting

Purpose of the Role

The Senior IT & IS Risk Specialist supports the Group's Information Security and IT risk management across the Corporate Center and Strategic Assets. This role plays a key part in establishing and enhancing risk strategies, frameworks, and baselines, monitors IT/IS risks and key metrics, and provides expert analysis on emerging cyber threats.

Strategic Context

Within the Corporate Center, the Senior Specialist oversees information security policies and standards, data security and identity controls, incident response, and third-party risk mitigation. The role collaborates with stakeholders across the Group to promote consistent risk practices, strengthen cyber resilience, protect critical assets, and ensure operational continuity.

The Senior Specialist works closely with the IT and IS Risk Manager and partners with Strategic Asset risk and information security teams to align cyber and technology risk priorities across the Group.

Key Responsibilities

Group-wide IT & Information Security Risk Management — Governance & Strategy

• Contribute to shaping the direction of Information Security and Technology Risk management across the Corporate Center and Strategic Assets.

• Drive implementation and tracking of strategic targets related to cyber resilience and technology risk across the Group.

• Facilitate the integration of IT and cyber risk considerations into enterprise risk management processes.

• Provide expert analysis on emerging cyber threats and technology risk exposures to relevant stakeholders.

• Coordinate cyber capability maturity assessments and track improvement initiatives across Strategic Assets.

• Follow up on the execution of IT and Information Security roadmaps across Strategic Assets and highlight gaps against strategic objectives.

Frameworks, Baselines & Methodologies

• Maintain and enhance the Group-wide IT and Information Security Risk Management framework.

• Establish and maintain the Group-wide methodology for Critical Services and Systems Availability.

• Maintain and communicate Business Continuity baseline requirements across the Group.

• Maintain the Third-Party Cyber Risk Management baseline and monitor its application.

• Coordinate Group-wide Penetration Testing requirements and practices.

• Ensure frameworks and methodologies remain aligned with recognized standards such as ISO 27001 and the NIST Cybersecurity Framework.

• Participate in defining the Group-wide Artificial Intelligence (AI) security management framework, including governance principles, risk assessment methodologies, and control requirements for the secure use of AI solutions.

Risk Monitoring & Reporting

• Maintain standards for IT and Information Security risk reporting across the Group.

• Establish and track Key Risk Indicators (KRIs) for cyber and technology risks.

• Review quarterly IT and Information Security risk reports from Strategic Assets and consolidate key insights.

• Contribute to updates of the Risk Appetite Statement related to IT and cyber risk.

• Maintain Risk Health Index metrics for technology and cyber risk domains.

• Escalate material cyber and technology risks with recommended mitigation options to the IT and IS Risk Manager and Risk Director.

Stakeholder Engagement & Communication

• Act as a key point of contact on cyber and technology risk topics for Strategic Assets.

• Participate in Strategic Asset Risk Management Committees and provide subject matter expertise.

• Promote alignment on cyber and technology risk priorities across the Corporate Center and Strategic Assets.

• Maintain and contribute to the Group-wide Information Security community.

Industry & Regulatory Alignment

• Benchmark cyber risk management practices against industry standards and peers.

• Monitor regulatory and industry developments related to IT security and cyber risk.

• Promote adoption of relevant regulatory expectations and leading practices across Strategic Assets.

Information Security of the Corporate Center — Security Policy and Standards

• Develop, implement, and maintain information security policies, standards, and procedures aligned with industry best practices and regulatory requirements.

• Promote effective communication and understanding of policies among relevant personnel.

• Regularly review and update policies to address evolving threats and technologies.

• Monitor adherence to security policies and standards across the organization.

• Provide guidance and support to employees in understanding and complying with security requirements.

Data Security Monitoring and Control

• Monitor and analyze data protection alerts to identify potential data leakage, unauthorized data transfers, or misuse of sensitive information.

• Investigate suspicious activities, validate incidents, and coordinate with relevant stakeholders to ensure timely remediation.

• Continuously fine-tune monitoring rules and detection scenarios to improve accuracy and reduce false positives.

• Monitor user access activities and changes to critical systems to detect unauthorized or inappropriate access to sensitive data.

• Review access control reports and privilege assignments to monitor alignment with internal policies and segregation of duties principles.

• Support regular access reviews and contribute to strengthening data access controls across the organization.

Identity Infrastructure Monitoring and Control

• Monitor core identity and authentication systems to detect unauthorized account changes, privilege escalations, and abnormal access activities.

• Track the creation, modification, and deletion of user accounts, roles, and group memberships to ensure compliance with access governance standards.

• Investigate high-risk or suspicious identity-related events and coordinate timely remediation with relevant teams.

• Review and analyze changes within identity repositories and authentication policies to ensure integrity, traceability, and accountability.

• Support periodic access recertification and segregation of duties controls across critical systems.

• Identify gaps in identity and access monitoring processes and recommend enhancements to strengthen overall security posture.

Incident Response and Management

• Develop and maintain a comprehensive incident response plan, outlining procedures for identifying, containing, and resolving security incidents.

• Conduct regular tabletop exercises and drills to test the effectiveness of the incident response plan.

• Lead investigations into security incidents to determine root cause, extent of damage, and necessary corrective actions.

• Gather and analyze evidence to support investigations and legal proceedings, if required.

• Coordinate with relevant stakeholders, including law enforcement and external experts, as needed.

• Conduct post-incident analysis to identify lessons learned and improve future prevention efforts.

• Implement recommendations to strengthen security controls and prevent similar incidents from occurring.

Security Awareness and Training

• Develop and deliver security awareness training programs to educate employees about security best practices and the importance of protecting sensitive information.

• Promote a culture of security awareness through various communication channels, including newsletters, posters, and workshops.

• Provide specific training on phishing and social engineering tactics to help employees recognize and avoid potential threats.

• Conduct phishing simulations to assess employee awareness and identify areas for improvement.

Vendor and Third-Party Risk Management

• Assess the security practices of third-party vendors and suppliers to ensure they meet the organization's security standards.

• Require vendors to sign appropriate security agreements and undergo regular security audits.

• Develop and implement measures to mitigate risks associated with third-party relationships, such as data sharing agreements and access controls.

• Monitor vendor performance and address any security concerns that arise.

Key Relationships

Internally, the role collaborates closely with IT Security Engineers, Network Engineers, Systems Administrators, Application Developers, and IT Project Managers on the design and integration of security controls; with Operational and Financial Risk Managers on IT-related risk; with Legal Counsel on data privacy and incident response matters; with HR Business Partners and Training and Development Specialists on security awareness programs; and with Business Unit Heads, Line Managers, and Data Owners on communicating and enforcing security requirements.

Externally, the role engages with regulators (including the Central Bank, Insurance Supervisory Authority, and Data Protection Authority), industry and cybersecurity associations, technology and cloud service vendors, external IT and financial auditors, and cybersecurity consultants such as threat intelligence analysts, penetration testers, and forensic investigators. The role also works closely with Strategic Asset risk management and information security teams on risk identification, security baselines, incident response coordination, and cyber maturity improvement initiatives.

Requirements

Required:

• Bachelor's degree or higher in Information Security, Informatics, Computer Science, Management of Information Systems, or a related field.

• Minimum of 4+ years of professional experience in Information Security and IT, with a strong focus on risk management, compliance, and incident response.

• Strong understanding of operating systems, networking, firewalls, application security, virtualization, cloud security, and data privacy.

• Familiarity with information systems concepts, including security and control risks, logical and physical access security, change management, information security and privacy, business recovery practices, and network technology.

• Proficiency in one or more relevant certifications, such as CRISC, CISM, CISSP, ISO/IEC 27005 Risk Management, or equivalent technology industry certifications (e.g., Certified Network Engineer, Certified Security Professional).

• Experience with information security standards and regulations such as the ISO 27k family, NIST, and PCI DSS.

• In-depth understanding of information security paradigms and risk management concepts.

• Work experience and sound knowledge of the banking or insurance industry.

• Excellent written and verbal communication skills, including the ability to present technical information to both technical and non-technical audiences.

• Strong writing and documentation skills for creating clear and concise reports, policies, and procedures.

• Proven experience working within group structures and collaborating with multiple entities, subsidiaries, or business units in a complex organizational environment.

• Demonstrated ability to identify, assess, and mitigate security risks in complex IT landscapes.

• Experience developing and implementing information security policies, standards, and procedures.

Preferred:

• Experience coordinating cyber capability maturity assessments or leading improvement initiatives across multiple business units or subsidiaries.

• Familiarity with AI security governance, risk assessment methodologies, and control requirements for the secure use of AI solutions.

• Prior experience engaging directly with regulators or industry associations on cybersecurity and data privacy matters.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.