Apply now »

Operations Risk & Security Audit Manager

Location: 

Cluj, RO Iasi, RO Timisoara, RO Remote, RO Brasov, RO Sibiu, RO Bucuresti, RO

Who we are

 

We are looking for an experienced Operational Risk & Security Audit Manager to assume combined responsibility for programme-level operational risk management and security audit activities within a large-scale, complex IT services environment.

The role requires strong experience in enterprise risk management, information security, audit and compliance, together with the ability to coordinate effectively across multiple delivery teams, contractors and senior stakeholders.

 

What you'll be doing

 

  • Maintain and continuously develop the overall Programme Risk Register, covering strategic, operational, financial, contractual, security and delivery risks, while ensuring appropriate integration with security risk management activities.
  • Identify, assess and coordinate programme-level risks in collaboration with workstream leads, business owners, delivery teams and other relevant stakeholders.
  • Perform qualitative and quantitative risk assessments, including likelihood and impact analysis, residual risk evaluation and ongoing monitoring of agreed mitigation measures.
  • Develop formal risk communications, mitigation plans and escalation materials for senior management and relevant programme governance bodies.
  • Ensure identified risks, dependencies and mitigation measures are appropriately reflected in project plans, statements of work and strategic planning activities.
  • Monitor the overall programme risk profile and maintain risk dashboards, KPIs and management reporting, providing clear visibility of key risks, trends, mitigation progress and areas requiring management attention.
  • Maintain operational risk information required for security, operational and management dashboards and contribute risk-related analysis to periodic strategic, operational and financial programme reporting.
  • Facilitate risk workshops, periodic risk reviews and executive-level risk reporting, ensuring appropriate ownership, follow-up and escalation of identified risks.
  • Coordinate risk management activities across multiple workstreams, delivery organisations and third-party contractors, promoting a consistent approach to risk identification, assessment and treatment.
  • Work with internal and external delivery partners to align risk assessment methodologies, proposed mitigation actions and residual risk acceptance.
  • Ensure appropriate traceability of risks, decisions, mitigation activities, approvals and lessons learned within the programme's knowledge management environment.
  • Contribute to continuous service improvement by incorporating lessons learned from risk events, incidents, audit findings and completed mitigation activities.
  • Align programme risk management activities with recognised information security and risk management standards and frameworks, including ISO 27001, while considering applicable European cybersecurity and operational resilience requirements, including NIS2, CRA and DORA.
  • Plan, coordinate, execute and report on periodic internal security audits covering relevant security controls, processes, systems and supporting evidence.
  • Conduct security and compliance assessments across areas including security controls, risk treatment plans, vulnerability and patch management, incident handling, access control and supply-chain security.
  • Identify non-conformities, control weaknesses and improvement opportunities, prepare formal audit findings and recommendations, and monitor remediation through agreed corrective action plans.
  • Support external audits and regulatory or customer inspections, including the preparation, review and coordination of required evidence packages.
  • Represent the service provider during relevant audit, compliance and inspection activities and coordinate responses with internal stakeholders and delivery partners.
  • Maintain the audit universe, audit calendar, audit evidence, findings and associated documentation, ensuring appropriate governance, traceability and record keeping.
  • Ensure appropriate audit independence and objectivity, remaining organisationally independent from the activities and teams being audited.
  • Contribute to periodic security programme, risk, compliance and management reporting, providing clear visibility of audit findings, remediation status and recurring control issues.
  • Support continuous improvement of the Information Security Management System (ISMS) based on audit findings, risk assessments, incidents and lessons learned.
  • Drive continuous improvement and, where appropriate, automation of risk and audit processes, dashboards, KPIs, evidence management and management reporting.
  • Act as backup for the Security Risk Management function when required and support broader programme security governance activities.

 

What you'll bring along

 

  • Strong professional experience in operational risk management, enterprise risk management, information security risk management and security auditing, ideally within large-scale or complex IT services environments.
  • Demonstrable experience maintaining enterprise or programme-level risk registers and coordinating risk identification, assessment, mitigation and escalation across multiple teams and stakeholders.
  • Hands-on experience planning and conducting security and compliance audits, documenting findings, identifying control weaknesses and managing corrective action plans through to closure.
  • Strong knowledge of ISO 27001, ISMS principles and recognised information security, audit and risk management practices and frameworks.
  • Good understanding of relevant European cybersecurity and operational resilience regulations, including NIS2, the Cyber Resilience Act (CRA) and DORA.
  • Experience working within complex multi-vendor or multi-contractor delivery environments, coordinating effectively across internal teams, customers, suppliers and external delivery partners.
  • Strong analytical capabilities, including experience with qualitative and quantitative risk assessment, likelihood and impact analysis, residual risk evaluation and mitigation effectiveness monitoring.
  • Experience developing, maintaining and improving risk and audit KPIs, dashboards, metrics and management reporting.
  • Ability to facilitate risk assessments, workshops, audit meetings and management reviews and to translate complex risk and security topics into clear, actionable information.
  • Strong understanding of security controls and compliance areas such as vulnerability and patch management, incident management, access control, supply-chain security and risk treatment.
  • Experience supporting external audits, customer assessments, regulatory inspections or similar assurance activities, including evidence preparation and stakeholder coordination.
  • Strong documentation and governance capabilities, with particular attention to auditability, evidence quality, traceability and consistency.
  • Excellent stakeholder-management and communication skills, with the ability to engage effectively with technical specialists, delivery teams, management and executive stakeholders.
  • Ability to challenge constructively, maintain appropriate audit independence and provide objective, evidence-based risk and compliance assessments.
  • A structured, analytical and proactive approach, with the ability to operate independently while coordinating effectively across security, operational, technical, commercial and management functions.
Document

What’s in it for you


✔ New beginnings can be a challenge. We promise a smooth integration and a supportive mentor
✔ Pick your working style: choose from Remote, Hybrid or Office work opportunities
✔ Early bird or night owl? Our projects have different working hours to suit your needs
✔ Nobody is born an expert. Sharpen your tech skills with our sponsored certifications, trainings and top e-learning platforms
✔ We want you to stay healthy! Enjoy our Private Health Insurance ⁠– it’s custom-made for you
✔ A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School
✔ Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

✔ NTT DATA recruiters will never ask job seekers and candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties that may try to impersonate NTT DATA recruiters, either in writing or by phone, in an attempt to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will be associated with an @nttdata.com email address. NTT DATA will not use any non-NTT DATA or personal email domains (Gmail, Yahoo, etc.) or personal communication channels (WhatsApp, Facebook etc) at any time during the recruitment process. If you suspect any fraudulent activity, please contact us.


NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ancestry, age, sex, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic protected by law. We are committed to creating a diverse and inclusive environment for all employees.


Not the job for you? Perhaps you have a friend who would be a perfect fit. Send them this link!

What’s in it for you

  • New beginnings can be a challenge. We promise a smooth integration and a supportive mentor
  • Pick your working style: choose from Remote, Hybrid or Office work opportunities
  • Early bird or night owl? Our projects have different working hours to suit your needs
  • Nobody is born an expert. Sharpen your tech skills with our sponsored certifications, trainings and top e-learning platforms
  • We want you to stay healthy! Enjoy our Private Health Insurance ⁠– it’s custom-made for you
  • A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School
  • Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

 

Make this the place you grow

Your unique talent is what matters. NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ethnicity, age, gender, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic.

 

Document

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers and candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties that may try to impersonate NTT DATA recruiters, either in writing or by phone, in an attempt to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will be associated with an @nttdata.com email address. NTT DATA will not use any non-NTT DATA or personal email domains (Gmail, Yahoo, etc.) or personal communication channels (WhatsApp, Facebook etc) at any time during the recruitment process. If you suspect any fraudulent activity, please contact us.


#LI-AR2


Job Segment: Information Security, Compliance, Risk Management, Supply Chain Manager, Operations Manager, Technology, Legal, Finance, Operations

Apply now »