About this role
We are looking for a Senior Security GRC professional to join our team and strengthen our cybersecurity, risk, and compliance capabilities in a regulated banking environment .
In this role, you will act as a liaison between IT, business leadership, and regulators , ensuring that security and compliance are effectively embedded across the organization.
Key responsibilities:
- Execute cyber & ICT risk assessments , BIA, and risk treatment plans
- Ensure compliance with FINMA circulars, ISO 27001, LPD , PCI DSS and relevant regulations
- Oversee third-party / vendor risk management
- Maintain and enhance the ISMS, policies, and controls framework
- Oversee IT & security audits (internal/external)
- Develop GRC dashboards, KPIs and reporting for CISO
What do we offer?
- Flexibility in working from home and the management of working hours in order to guarantee a healthy work-life balance
- Numerous benefits and incentives
- Well-being, motivational and team-building activities
Requirements
- 5+ years in Cybersecurity, IT Risk, Audit, or GRC (banking/fintech preferred)
- Strong knowledge of ISO 27001, NIST, PCI DSS
- Experience with regulatory environments (FINMA highly valued)
- Professional certifications (CISSP, CISM, CISA, CRISC, CDPSE) are a plus
- Ability to translate technical risks into business insights
- Fluent English and Italian (mandatory). German (strong advantage)
- Based in Ticino, or willing to relocate to Ticino