Lead IT Risk Manager
Upvest provides regulated, API-first investment infrastructure for fintechs, banks, brokers, and wealth managers across Europe and the UK. Its platform supports brokerage, settlement, custody, fractional investing, portfolios, savings plans, and investment operations.
Funding history
About Upvest GmbH
Upvest is a regulated investment infrastructure company offering a cloud-native Investment API for brokerage, settlement, custody, and real-time investment functionality. It also provides middle- and back-office business process outsourcing, regulatory licences, fractional securities, portfolios, savings plans, and operating models for financial institutions launching or scaling investment and pension products.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Lead the second-line IT risk function in a regulated financial services environment, overseeing IT governance, controls, risk assessments, audits, resilience, business continuity, and regulatory compliance.
Requirements
- University degree in Computer Science, Information Technology, Information Security, or equivalent experience.
- 5+ years of progressive experience in IT GRC or IT Security within a regulated financial institution, bank, fintech, or scaling B2B platform.
- Deep knowledge of ISO 27001, BaFin BAIT/MaRisk, DORA, and technology resilience standards.
- Exceptional English communication skills and ability to engage with international stakeholders and executives.
- Product engineering and security-focused mindset with commercial pragmatism and comfort operating under ambiguity.
Responsibilities
- Own and evolve the IT Risk and Business Continuity Management Framework.
- Provide independent second-line oversight and challenge to the first-line IT GRC team.
- Lead IT risk identification, assessment, and mitigation across cyber, resilience, third-party, and data security.
- Mature the ISMS and run continuous assessments against ISO/IEC 27001:2022.
- Oversee third-party IT risk, technology exposures, and business continuity assessments.
- Drive assurance reviews, audits, and remediation tracking.
- Lead DORA obligations, including ICT risk management and third-party ICT risk oversight.
- Track regulatory developments and translate requirements into actionable guidance.
- Report IT risk posture and material events to senior stakeholders, the C-suite, and the Risk Committee.
Benefits
- €20,000 per year for AI tools
- 30 days of annual leave
- Sports benefits
- Confidential professional coaching
- Remote work abroad for up to 183 days per year
- One-month fully paid sabbatical every four years
- Personal development budget
- Hybrid or remote work across European hubs
- Competitive salary and employee equity participation
- Company-wide events and celebrations
