All roles

Senior DORA ICT Risk Consultant

Advise banks, insurers and payment firms on the Digital Operational Resilience Act. You shape ICT risk frameworks, register of information and testing programmes that stand up to BaFin supervision.

Apply nowTakes about 3 minutes

About the role

DORA has applied since January 2025, and supervisors are now looking at how firms run it in practice rather than on paper. This role works with financial entities in Frankfurt and across Germany on that second phase. You review ICT risk management frameworks, improve the register of information on ICT third-party providers and prepare resilience testing programmes. You work with our third-party risk and incident response teams and with client CISOs, risk functions and internal audit.

What you will do

  • Assess ICT risk management frameworks against DORA and the related RTS and ITS
  • Improve the register of information and contract terms for ICT third-party service providers
  • Design digital operational resilience testing programmes and prepare clients for TLPT scoping
  • Align major ICT incident classification and reporting with BaFin requirements
  • Write findings and remediation plans for management bodies and supervisors

What you bring

  • 6+ years in IT risk, information security or IT audit in financial services
  • Detailed knowledge of DORA and earlier BaFin guidance such as BAIT and VAIT
  • Experience working with second-line risk functions and internal audit
  • Ability to explain technical risk in the language of a management board
  • Professional German and English

Good to have

  • CISA, CRISC or CISSP certification
  • Experience with TIBER-DE or other threat-led testing frameworks from the oversight side
  • Knowledge of EBA outsourcing guidelines

Languages

English (C1), German (B2)

Skills

  • DORA
  • ICT risk
  • BaFin
  • Third-party risk
  • Register of information
  • TLPT
  • IT audit