CyberSecurity Frontline Risk and Control Manager
Job in
Genf, Geneva, Switzerland
Listed on 2026-07-11
Listing for:
UBP - Union Bancaire Privée
Full Time
position Listed on 2026-07-11
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Mission
Lead and strengthen UBP’s cybersecurity first line of defence by overseeing Security Risk & Governance and Vulnerability Management. Establish, maintain, and evolve a robust, transparent control framework aligned to global banking regulations (FINMA, EU, UK, Hong Kong, Singapore). Partner with Technology, Business, Risk, and Compliance stakeholders to proactively manage cyber risks, ensure regulatory adherence, and safeguard UBP’s clients and assets.
Governance & Risk Management- Own and evolve the cybersecurity risk management framework, policies, standards, and security controls catalogue for first line of defence.
- Drive risk identification, assessment, and ensure that adequate and achievable treatment plans are defined and implemented in effective timescales.
- Maintain risk registers and key risk indicators (KRIs). Ensure discrete risks are clearly identified, challenged and catalogued without duplication or unnecessary overlap.
- Ensure alignment with group risk appetite, regulatory expectations, and industry best practices (ISF, NIST CSF, ISO/IEC 27001/27005).
- Lead enterprise vulnerability management strategy and operations (infrastructure, applications, cloud, third parties).
- Oversee vulnerability scanning, assessment, risk-based prioritisation, and timely remediation in line with SLAs.
- Partner with Infrastructure, Dev Sec Ops , and application owners to embed secure‑by‑design principles and shift‑left controls.
- Report on exposure, trends, and risk posture to senior management and risk committees.
- Interpret and operationalize cyber requirements across FINMA, EU (including DORA/NIS2 where applicable), UK (PRA/FCA), Hong Kong (HKMA), and Singapore (MAS).
- Prepare evidence and responses for internal/external audits, regulatory exams, and board‑level reporting.
- Maintain control mapping to regulatory frameworks; ensure continuous readiness and closure of findings.
- Manage and mentor a small team; build capabilities and career growth for junior staff.
- Communicate complex cyber risk topics clearly to senior management and non‑technical stakeholders.
- Champion a risk‑aware culture across technology and business functions.
- Manage and mentor a small team; build capabilities and career growth for junior staff.
- Communicate complex cyber risk topics clearly to senior management and non‑technical stakeholders.
- Champion a risk‑aware culture across technology and business functions.
- Experienced cybersecurity risk leader with deep first line of defense experience in financial services.
- Strong knowledge of regulatory environments across Switzerland (FINMA), EU, UK, Hong Kong, and Singapore, with proven ability to operationalize requirements.
- Strategic thinker with hands‑on rigor—able to sustain current frameworks while maturing them for scalability and transparency.
- Influential communicator and collaborative partner comfortable engaging senior executives and guiding junior staff.
- Bachelor’s or master’s degree in information security, Computer Science, Engineering, Risk Management, or a related field.
- Relevant certifications preferred: CISSP, BISM, CRISC, ISO 27001 Lead Implementer/Auditor, CEH, or equivalent.
- 8–12+ years in cybersecurity with significant exposure to first line risk and control management in a regulated bank.
- Proven track record in:
- Designing and operating cyber risk and control frameworks (policies, standards, KRIs/KPIs, control testing).
- Leading enterprise vulnerability management (tools, processes, SLAs, metrics, remediation governance).
- Regulatory engagement, audit response, and evidence management.
- Cross‑border regulatory alignment (FINMA, EU/DORA, UK PRA/FCA, HKMA, MAS).
- Practical familiarity with:
- Frameworks/standards: NIST CSF, NIST 800‑53, ISO/IEC 27001/27002/27005, OWASP, CIS Controls, MITRE ATT&CK.
- VM tooling & ecosystems:
Qualys/Tenable/Rapid7, SAST/DAST, SCA, container and cloud posture management (CSPM), EDR/XDR. - Enterprise environments:
Windows/Unix, networks, databases, microservices, SaaS, public cloud (AWS/Azure/GCP). - Secure SDLC/Dev Sec Ops and CI/CD…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×