ICT & IS Risk Manager, reporting to the Head, ICT & IS Risk, Group Operational Risk
Role context
Habib Bank AG Zurich is a Swiss-incorporated banking group operating in eight geographies. In response to evolving global regulatory expectations, including FINMA Circular 2023/1, OSFI B-13, SBP Guidelines, UAE Central Bank ICT regulations, and others—the Group is enhancing its Operational Risk function by establishing a dedicated vertical for ICT & IS (Cyber) Risk Oversight.
This mid-level role is integral to setting up this function and transitioning it into steady-state operations. The incumbent will support risk governance across technology, information security, change risk, and third-party risk management, with particular emphasis on dependencies linked to critical data and critical service providers. The role is suited for a self-motivated professional with strong ICT risk knowledge, capable of working independently with senior stakeholders across IT, IS, Projects, and Risk.
Responsibilities
- Framework Development and Function Setup
- Support the design and rollout of the Group’s ICT & Cyber Risk Framework, including policies, procedures, taxonomies, and governance models.
- Develop oversight structures aligned with regulatory expectations (FINMA, SBP, OSFI, HKMA, SARB, UAE CB).
- Support the formalization of control libraries, KRIs, RCSAs, issue tracking, and escalation thresholds – across Group Technology & Information Security Functions
2. Oversight of ICT & IS Risk (2LOD Role)
- Independently review and challenge ICT and IS risk assessments, including technology infrastructure, cybersecurity, and data protection domains.
- Support management in identifying material ICT/IS risks and maintaining the ICT & Cyber Risk Register.
- Provide effective oversight of IT and IS control environments, including user access, change controls, incident response, and business continuity.
3. Change and Project Risk Oversight
- Act as the 2nd line lead for Change Risk Assessments (CRA) by ensuring material changes (systems, architecture, security controls) undergo formal pre-implementation reviews.
- Monitor high-impact or complex projects, ensuring residual risks are identified, mitigated, and accepted appropriately.
- Coordinate and perform Post-Implementation Reviews (PIRs) to assess risk outcomes versus planned mitigations for major or high-risk changes.
4. Third-Party and Critical Data Risk Oversight
- Provide oversight of third-party IT and IS providers, focusing on service criticality, data handling, and risk controls.
- Support the implementation of third-party risk governance in line with ICT outsourcing and cyber resilience expectations.
- Ensure adequate controls are in place to manage the confidentiality, integrity, and availability of Critical Data as defined under FINMA Circular 2023/1.
- Participate in risk reviews of contracts, SLAs, and vendor performance metrics.
5. Risk Monitoring & Reporting
- Maintain an integrated ICT & Cyber Risk dashboard, including KRIs and early warning indicators.
- Support regular reporting to Group Risk Control Committee (GRCC), Senior Management, and Board-level governance forums.
6. Regulatory & Internal Compliance
- Interpret and map local and international regulatory requirements related to ICT and Cyber risk.
- Support audit and regulatory reviews, ensuring timely resolution of findings related to IT, IS, and third-party risk domains.
7. Incident and Resilience Management
- Participate in incident analysis involving ICT, cybersecurity, or third-party failures.
- Support BCP/DR testing, IT resilience scenarios, and the review of incident root causes.
8. Training & Awareness
- Assist in developing and delivering awareness programs and targeted training to promote risk ownership and culture across IT, IS, and project teams.
Education & Certifications:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related discipline.
- Professional certifications preferred: CRISC, CISA, CISSP, CISM, COBIT or equivalent.
Experience:
- 5–7 years of relevant experience in ICT/Cyber risk, technology audit, or operational risk roles within financial services.
- Experience working with regulatory frameworks across multiple jurisdictions (e.g., FINMA, OSFI, SBP, UAE CB, HKMA, SARB).
- Demonstrated ability to implement or contribute to risk frameworks, perform risk assessments, and engage with IT & IS stakeholders.
- Experience in project governance, risk change, or post-implementation reviews is highly desirable.
Skills and Attributes
- Proficient in ICT risk domains including infrastructure, cloud, cybersecurity, change controls, and third-party oversight.
- Analytical mindset with ability to challenge constructively and operate with independence.
- Skilled in risk documentation, reporting, and regulatory interpretation.
- Excellent communication, stakeholder engagement, and problem-solving skills.
Location:
Karachi, Pakistan
Special requirements:
Must be able to occasionally work across Swiss and UAE time zones to coordinate with Group stakeholders.
- Travel to Dubai or Zurich may be required.