ICT Cyber Strategy & Risk Framework Manager

Job type:Permanent
Town/City:Prague
Region:Breclav
Sector:Cyber Security
Client Company Type:In-House
Job ref:10238
Post Date:August 3, 2026

About the Role

ICT Cyber Strategy & Risk Framework Manager

The Opportunity

We are partnering with a major international financial services organisation in Prague that is looking to strengthen its Cyber Security and ICT Risk function with an experienced ICT Cyber Strategy & Risk Framework Manager. This is a highly visible position focused on shaping and developing the organisation's ICT and Cyber Risk strategy, governance and risk management framework across a complex financial environment. You will work closely with senior stakeholders across Cyber Security, Technology, Risk, Compliance and the wider business, helping ensure that ICT and cyber risks are identified, assessed and managed effectively.

The Role

  • Own and continuously develop the ICT & Cyber Risk Management Framework, ensuring alignment with the organisation's wider risk strategy.
  • Define and drive the ICT and Cyber Risk strategy, policies, standards and governance structures.
  • Establish appropriate risk methodologies, controls, risk appetite and reporting mechanisms.
  • Ensure alignment with relevant financial services regulations and frameworks, including DORA, NIS2, EBA requirements, ISO 27001 and NIST.
  • Identify, assess and challenge ICT and cyber risks across technology and business functions.
  • Support the development of KRIs, risk reporting, dashboards and management information for senior leadership.
  • Provide strategic guidance on technology risk, cyber resilience, third-party risk and emerging security threats.
  • Work closely with senior stakeholders across IT, Cyber Security, Operational Risk, Compliance and Internal Audit.
  • Present ICT and cyber risk topics to senior management and relevant governance committees.
  • Drive continuous improvement of the organisation's overall ICT and cyber risk maturity.

What You'll Need

  • Strong professional experience within ICT Risk, Cyber Risk, Technology Risk, Information Security Governance or Cyber Security Strategy.
  • Proven experience developing or managing ICT/Cyber Risk frameworks within a complex organisation.
  • Strong understanding of financial services regulation, particularly DORA and broader ICT risk requirements.
  • Knowledge of frameworks such as ISO 27001, NIST, COBIT or similar.
  • Experience working with senior stakeholders and communicating complex technology risks at management level.
  • Ability to combine strategic thinking with strong risk and governance expertise.
  • Previous experience within banking, insurance or wider financial services is highly desirable.
  • Strong communication, stakeholder management and influencing skills.
  • Fluent Czech is mandatory, alongside strong professional English.
  • Willingness to work onsite in Prague.

How to Apply

Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role.

More Jobs from this Recruiter

Prague, Breclav

ICT Cyber Strategy & Risk Framework Manager

ICT Cyber Strategy & Risk Framework Manager The Opportunity We are partnering with a major international financial services organisation in Prague that is looking to strengthen its Cyber Security and ICT Risk function with an experienced ICT Cyber Strategy & Risk Framework Manager. This is a highly visible position focused on shaping and developing the organisation's ICT and Cyber Risk strategy, governance and risk management framework across a complex financial environment. You will work closely with senior stakeholders across Cyber Security, Technology, Risk, Compliance and the wider business, helping ensure that ICT and cyber risks are identified, assessed and managed effectively. The Role Own and continuously develop the ICT & Cyber Risk Management Framework, ensuring alignment with the organisation's wider risk strategy. Define and drive the ICT and Cyber Risk strategy, policies, standards and governance structures. Establish appropriate risk methodologies, controls, risk appetite and reporting mechanisms. Ensure alignment with relevant financial services regulations and frameworks, including DORA, NIS2, EBA requirements, ISO 27001 and NIST. Identify, assess and challenge ICT and cyber risks across technology and business functions. Support the development of KRIs, risk reporting, dashboards and management information for senior leadership. Provide strategic guidance on technology risk, cyber resilience, third-party risk and emerging security threats. Work closely with senior stakeholders across IT, Cyber Security, Operational Risk, Compliance and Internal Audit. Present ICT and cyber risk topics to senior management and relevant governance committees. Drive continuous improvement of the organisation's overall ICT and cyber risk maturity. What You'll Need Strong professional experience within ICT Risk, Cyber Risk, Technology Risk, Information Security Governance or Cyber Security Strategy. Proven experience developing or managing ICT/Cyber Risk frameworks within a complex organisation. Strong understanding of financial services regulation, particularly DORA and broader ICT risk requirements. Knowledge of frameworks such as ISO 27001, NIST, COBIT or similar. Experience working with senior stakeholders and communicating complex technology risks at management level. Ability to combine strategic thinking with strong risk and governance expertise. Previous experience within banking, insurance or wider financial services is highly desirable. Strong communication, stakeholder management and influencing skills. Fluent Czech is mandatory, alongside strong professional English. Willingness to work onsite in Prague. How to Apply Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role.
Learn More
Munich, Bayern

Team Lead OT Security

Team Lead OT Security The Opportunity If you're currently doing OT security work inside someone else's framework, this is a chance to build your own. This is a newly created leadership role, giving you ownership of the OT cybersecurity strategy and NIS2 compliance programme for a growing portfolio of critical infrastructure assets across Europe. You'll set the direction, not just execute someone else's. The Role Own and evolve the OT cybersecurity strategy, governance framework and controls across the asset portfolio Translate NIS2 and country-specific regulation into a practical, auditable compliance programme Build a consistent OT risk management framework, giving full visibility across assets and dependencies Set OT security standards covering segmentation, remote access, logging, hardening and backup integrity, aligned to IEC 62443 and NIST Manage third-party and O&M cybersecurity governance, including contracts and remote access assurance Build and run OT incident response capability, including playbooks and post-incident analysis Act as the central point of contact across Operations, Engineering, IT/OT, Legal, Audit and external authorities Build and lead your own OT cybersecurity team, plus the external partner ecosystem The Company You'll be joining an internationally operating business with a fast-growing, multi-site operational footprint across Europe. The business is scaling quickly, which means the OT security function is still being built, not just maintained: you'll have real influence over how it takes shape. It's also a chance to put your expertise to work protecting infrastructure that genuinely matters to how the business runs day to day. What You'll Need At least five years' experience in OT/ICS cybersecurity within energy, utilities or critical infrastructure Proven track record leading multi-country or multi-stakeholder OT security programmes Strong technical grounding in SCADA environments, industrial networks, segmentation and secure remote access Hands-on experience with IEC 62443 and a solid understanding of NIS2 requirements and audit expectations Experience managing external vendors and third-party risk frameworks Confident communicator, comfortable moving between executive and technical conversations Fluent English How to Apply Interested? Get in touch with MAM Gruppe. Your CV doesn't need to be up to date, send what you have, or call for a confidential conversation.
Learn More
German wide, Baden-Württemberg

Director Cyber Security

Director, Cyber Security Consulting The Opportunity Ready to step into a role where your name is on the door, not buried in an org chart? This is a Director-level position with genuine weight behind it - the kind of opportunity to shape a cyber security practice, own client relationships, and make decisions that matter. If you're a senior consultant who's been doing the work but not getting the platform, this is worth reading. The Role You'll lead complex cyber security consulting engagements across Germany, working with clients across sectors on strategy, risk, architecture, and programme delivery. At Director level, that means driving business development as much as delivery - building relationships, identifying opportunities, and bringing in the mandates as well as executing them. You'll be a visible figure in the market, representing the practice externally and mentoring the consultants around you internally. Expect variety: no two clients are the same, and the work spans the full spectrum of cyber security advisory. The Company Our client is a specialist consulting business with a strong footprint in the German market. They're known for the quality of their advisory work and the calibre of the people they hire. This is not a firm where Directors spend their time managing PowerPoint. The environment is fast-moving, collegial, and built around people who are genuinely expert in what they do. What You'll Need Significant experience in cyber security consulting, with a track record at senior level Proven ability to develop and convert business development opportunities Deep fluency in the German market and the cyber security landscape within it Native or near-native German, with strong English alongside Credibility with C-suite stakeholders and the confidence to lead from the front How to Apply Send your CV to the MAM Gruppe team. It doesn't need to be up to date - send what you have, or just get in touch for a conversation.
Learn More
Prague, Jihoceský kraj

ICT Risk Manager

ICT Risk Manager Location: Prague / Hybrid Our client is seeking an ICT Risk Manager to join a Second Line of Defence function, supporting technology risk governance, oversight and regulatory compliance activities within a regulated environment. Key Responsibilities: Provide independent oversight of ICT, cyber and technology-related risks. Review and challenge risk assessments, controls and remediation activities. Support the development and enhancement of ICT risk frameworks and governance processes. Monitor technology, security, outsourcing and operational resilience risks. Contribute to regulatory compliance and risk reporting activities. Support third-party and vendor risk oversight initiatives. Collaborate with stakeholders across risk, technology, security and business functions. Your Profile: Several years of experience within ICT risk, technology risk, cyber risk or operational risk environments. Understanding of risk governance and Second Line of Defence responsibilities. Experience within banking, financial services or another regulated environment. Knowledge of ICT risk management, operational resilience and regulatory frameworks. Strong analytical, communication and stakeholder management skills. Relevant certifications such as CRISC, CISA or CISSP would be advantageous. Fluent English language skills. What’s on Offer? Opportunity to work within an international and regulated environment. Exposure to technology risk, resilience and governance initiatives. Flexible hybrid working model. Long-term development and progression opportunities.
Learn More

Latest Blogs

View all blogs