- Location: Amsterdam
- Type: Permanent
- Job #16652
ABOUT THE ROLE
As an IT Risk Officer, you’ll play a key role in ensuring the security, resilience, and regulatory compliance of the organisation’s technology infrastructure. Operating in a dynamic environment with services including brokerage, custody, market-making, and lending, the role is crucial in maintaining operational integrity and safeguarding client assets.
You will focus on identifying, assessing, and mitigating IT and cyber risks in line with regulatory frameworks like the Digital Operational Resilience Act (DORA), and collaborate across departments to implement strong risk controls and monitoring. A strong understanding of the crypto industry and its unique security challenges is essential.
Key Responsibilities
-
Design and maintain the IT risk management framework in line with regulatory standards and industry best practices.
-
Conduct comprehensive IT risk assessments and recommend mitigation strategies.
-
Manage third-party risks and ensure vendor compliance with security standards.
-
Collaborate with IT and Security teams to strengthen incident response and business continuity measures.
-
Track and report key risk indicators (KRIs) to proactively manage emerging threats.
-
Advise on IT governance and compliance matters relating to digital asset operations.
What You Bring
-
3+ years of experience in IT risk, cybersecurity, or operational risk within financial services, fintech, or crypto sectors.
-
Familiarity with IT governance standards (e.g., ISO 27001, NIST) and regulations such as DORA, MiCA, and GDPR.
-
Experience managing risks in crypto custody, trading platforms, and blockchain infrastructure.
-
Knowledge of cloud and network security, particularly in fast-paced trading environments.
-
Understanding of vendor due diligence and third-party risk processes.
-
Ability to articulate complex technical risks in a business context.
-
Self-starter mindset with the ability to operate in a high-risk, evolving regulatory environment.
-
Competence in risk assessment methodologies and security frameworks.
Nice to Have
-
Professional certifications (e.g., CISM, CISSP, CRISC, CISA).
-
Experience in crypto exchanges, DeFi, or Web3 ecosystems.
-
Understanding of blockchain security and smart contract audits.
-
Familiarity with SOC 2 and IT control frameworks applicable to digital asset firms.