Director - ICT Security Reporting

Job type:Permanent
Town/City:Prague
Region:Jihomoravský kraj
Sector:Cyber Security
Client Company Type:In-House
Job ref:9622
Post Date:May 29, 2026

About the Role

Director, ICT Risk and Security Reporting

Most technology risk reporting roles exist to document what's already happened. This one exists to shape what happens next.

The Opportunity

This is a newly created Director-level position within the Risk function of one of Europe's leading international banks. You'll be joining at the point where the function is being built, not inherited, which means you'll have genuine influence over how ICT risk and security reporting is structured, governed, and matured from the ground up.

The regulatory environment is as complex as it gets right now: DORA is live, EBA ICT guidelines are evolving, and banks are under real scrutiny on operational resilience. You'll be working at the centre of all of it, translating technical and cyber risk into intelligence that drives decisions at board and executive level.

Critically, this isn't a back-seat reporting role. You'll be expected to challenge the first line, push back where data quality or risk transparency falls short, and bring an architectural view of technology risk that goes beyond compliance checklists. The business wants someone with enough credibility and backbone to be genuinely heard.

There is a clear path upward for the right person. This is a role you can grow into a broader leadership position, in a bank that operates at international scale.

The Role

  • Own and evolve the ICT Risk and Security reporting framework across the bank
  • Deliver board-level, executive, and risk committee reporting on technology and cyber risk
  • Translate complex technical and security risk data into clear, actionable business narratives
  • Develop risk metrics, KRIs, dashboards, and management information across ICT and cyber domains
  • Identify emerging risks and systemic themes across technology, cyber, resilience, and third-party environments
  • Challenge the first line on data quality, risk transparency, and governance consistency
  • Support regulatory and governance obligations including DORA and EBA ICT guidelines
  • Drive continuous improvement in reporting automation, data visualisation, and risk analytics
  • Partner with senior stakeholders across Technology, Cyber Security, Risk, Compliance, and Internal Audit

What You'll Need

  • Significant experience in ICT Risk, Technology Risk, Cyber Risk, or Information Security Governance, ideally within banking or regulated financial services
  • An architectural view of technology risk, with the ability to identify systemic issues, not just point-in-time findings
  • Proven experience producing board-facing or executive-level risk reporting
  • Strong working knowledge of DORA, EBA ICT guidelines, and operational resilience frameworks
  • The credibility and confidence to challenge senior stakeholders and first-line teams
  • Exceptional ability to communicate complex risk information clearly to non-technical audiences
  • Relevant certifications such as CISA, CRISC, CISSP, or CGEIT are advantageous
  • Fluent English required

What's on Offer

  • Competitive compensation package commensurate with Director-level seniority
  • Company pension scheme and comprehensive risk coverage including accident insurance
  • Car leasing and bike leasing schemes with tax advantages
  • IT device leasing for personal use
  • Hybrid working model based in Prague
  • Clear scope for progression within an international banking group

How to Apply

Apply via the link below. Your CV doesn't need to be perfect, send what you have and we'll take it from there. If you'd prefer a conversation before committing to anything, just give us a call.

More Jobs from this Recruiter

Frankfurt, Hessen

Manager ICT Third Party Risk

Manager ICT & Information Security Third Party Risk – 2nd Line of Defence  The Opportunity If your current role only lets you flag risk after the decision's already been made, this one is different. Here, you sit in the second line of defence with a genuine mandate to challenge. You'll assess how external providers handle security and technology risk, then push back when what you see doesn't meet the bar, regardless of how senior the stakeholder is on the other side of the table. You'll work across Information Security, IT, Procurement and Operational Risk, with direct visibility into risk committees and senior management reporting. The Role You'll independently review and challenge the first line's risk assessments for third-party providers, from critical suppliers to cloud vendors and outsourcing partners. Assess the security posture of critical suppliers, vendors, cloud providers and outsourcing partners Challenge the first line on identified risks, controls, remediation plans and risk acceptances Evaluate third-party controls across IAM, data protection, vulnerability management, incident response, cloud security and cyber resilience Support and help shape the TPRM and Information Security Risk frameworks Monitor third-party incidents, vulnerabilities and control weaknesses through to remediation Ensure alignment with DORA, NIS2, ISO 27001, EBA Guidelines and MaRisk Prepare risk reporting for senior management and risk committees Support internal audits and regulatory assessments Your findings feed directly into how the organisation manages its third-party exposure, giving you visibility that's hard to get in a first-line role. The Company Our client is a well-established, regulated financial services organisation with a mature second-line risk function. Its size and regulatory footprint mean third-party risk is treated as a genuine priority, not a box-ticking exercise, and the frameworks you'll work within are built to hold up under real regulatory scrutiny. What You'll Need Several years' experience in Information Security, ICT, Third Party or Cyber Risk Solid knowledge of TPRM processes and third-party security assessments Familiarity with ISO 27001, DORA, NIS2 and EBA requirements Knowledge of cloud security, IAM, vulnerability management, incident response and cyber resilience Confidence to independently challenge the first line and communicate risk to senior stakeholders Fluent German and English How to Apply Interested? Your CV doesn't need to be up to date. Send what you have, or just give us a call, and we'll talk you through the details.
Learn More
Germanwide, Nordrhein-Westfalen

Associate Partner Cyber Security Sales

Associate Partner Cyber Security Sales The Opportunity If you're already winning Cyber Security business for someone else, when do you start building something that's genuinely yours? This role gives you ownership of a strategic sales pipeline within an established consulting business, with real autonomy to grow it your way. You'll be measured on revenue and account growth, and there's a genuine path to Partner level for the person who delivers. The Role You'll identify and win enterprise Cyber Security clients across Germany, running full sales cycles from first contact through to proposal, negotiation and close. You'll build direct relationships with CISOs, CIOs and CTOs, working as a trusted advisor rather than a vendor. You'll also take ownership of a set of existing strategic accounts, finding ways to expand the Cyber Security services they already buy. This isn't a delivery role. You won't be running projects yourself. Your job is to open doors, grow revenue, and help shape where the Cyber Security practice goes next, including feeding into go-to-market strategy and tracking regulatory and market developments that create new commercial opportunities. You'll work closely with colleagues across the wider consulting business, drawing on their relationships and expertise to open doors you couldn't reach alone. The Company You'll be joining an established consulting organisation whose Cyber Security practice is still being shaped, not one that's already fixed in place. That means real influence over how the practice grows, who it targets, and how it's positioned in the German market. It's a business with the scale and credibility to open enterprise doors, but with enough flexibility that a strong commercial lead can still make their mark and be recognised for it. What You'll Need Significant experience in Cyber Security consulting, professional services or technology advisory A demonstrable track record of Cyber Security sales and revenue generation Proven success winning new enterprise clients in Germany Experience growing and expanding existing strategic accounts An established network of senior decision-makers in the German market Comfort engaging credibly with CISO, CIO, CTO and executive-level stakeholders Fluent German and strong English How to Apply Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role. Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More
Munich, Bayern

Senior Manager Information Security

Senior Manager Information Security If your current cyber strategy work never gets past the slide deck stage, this one's different. You'll be the person clients call when the board wants to know what to actually do about cyber risk, not just what the risk is. The Opportunity You'll lead projects at the top decision-making level of major, household-name clients. That means building risk-based, business-led cyber strategies with executives, not just writing them up for someone else to present. You'll design target operating models, advise on regulatory pressure points like DORA, and run transformation programmes from target state through to operational rollout. The client work spans sectors: financial services, public sector, and industrial environments protecting connected production systems. You'll also help shape how the practice uses emerging tools like generative AI in live project work, so this isn't a role where the methodology stays static. The Role Develop risk-based, business-oriented cyber strategies directly with client executives Advise leadership on regulatory requirements and translate them into action Manage transformation programmes end to end, from governance model to implementation Build target operating models that improve how people, technology and process work together Own project delivery for executive-level client relationships Coach and develop the team working alongside you on each engagement The Company This is a leading global consultancy with a well-established cybersecurity practice, working with some of the largest organisations in the market. You'd be joining a team that's actively growing its footprint in strategy and transformation work, with the backing and reputation to get straight into the room with senior stakeholders rather than working your way up to it. What You'll Need 5+ years in cybersecurity management, with a focus on strategy, governance or transformation work for large enterprise clients Proven track record managing complex projects with senior, demanding stakeholders Solid knowledge of cybersecurity standards such as ISO 27001, IT-Grundschutz, NIST, ISF or DORA Fluent German and English, with strong communication and presentation skills at management and C-level Willingness to travel How To Apply Get in touch with the team at MAM Gruppe for a confidential conversation. Your CV doesn't need to be up to date, send what you have or just give us a call.
Learn More
Munich, Bayern

Senior Manager IAM

Senior Manager IAM If you're the one everyone calls when an IAM rollout goes sideways, but you're never the one who got to design it from scratch, this is worth a look. The Opportunity You'll own IAM and PAM projects end to end, from initial requirements through to go-live and ongoing operation. You're the subject matter expert in the room: governance, architecture, integration, and the customer's target vision all sit with you. This means working with international clients on real regulatory pressure, including MaRisk and BAIT/VAIT requirements, and being the central point of contact for governance, standards and compliance throughout. You'll also lead and coach the project teams around you, so this is as much about people as it is about systems. The Role Act as project manager across all phases, from initial requirements analysis through conception, implementation, go-live and operation Own governance, architecture and integration as the subject matter expert Adapt IAM tools to client requirements and act as central contact for governance, standards and regulations Help shape product and service development based on market needs Lead and coach project teams, fostering a collaborative way of working The Company This is a leading global consultancy with a well-established cybersecurity practice, advising international clients on identity and access management. You'd be joining a team with real scope to shape how IAM/PAM work gets delivered, rather than just executing someone else's design. What You'll Need 5+ years of professional experience in identity and access management Solid experience with regulatory requirements such as MaRisk and BAIT/VAIT in relation to IAM implementation In-depth knowledge of IAM processes, from design through to rollout Strong knowledge of IT security standards such as ISO 27001 and NIST Confident communication at all levels, with experience leading international, interdisciplinary teams Fluent German and English, and willingness to travel How To Apply Get in touch with the team at MAM Gruppe for a confidential conversation. Your CV doesn't need to be up to date, send what you have or just give us a call.
Learn More

Latest Blogs

View all blogs