Skip to main content

IT and Cybersecurity Auditor

Auto-translated from Yoruba · original: Auditor IT a kybernetickej bezpečnosti

4 × 9hr days€3kHybrid · Bratislava, Slovakia

VÚB banka is the second-largest bank in Slovakia and part of the international Intesa Sanpaolo Group, one of the leading banking groups in Europe. First and foremost, we are a community of passionate people who believe in an environment where everyone has room to grow and develop their potential. Our greatest value is our people. We build our corporate culture on respect, empathy and trust, so that our employees feel appreciated and supported. As the first bank in Slovakia to earn the international TOP Employer title, we have set a new standard for the working environment. We offer flexible ways of working: where the nature of the position allows, employees choose for themselves when they work from home and when from the office. We see technology as the key to the future and are constantly looking for digital solutions that simplify work and move us forward. We support learning, not only in professional expertise but also in personal growth and the development of human potential. We recognise the importance of mental health, which is why we offer comprehensive programmes and benefits that help our colleagues maintain their psychological well-being and balance. We do our utmost to create a healthy, modern and satisfying working environment. If you want to be part of our team, please get in touch.

Salary conditions

3250 EUR

The final salary level depends on professional qualifications and experience.

Purpose and scope of the role

We are looking for an auditor for our Information Technology and Cybersecurity Audit department, who will help the bank achieve its objectives through independent assessment of the internal control environment in the areas of ICT, Business Continuity Management and cybersecurity, through independent audits.

The new colleague will provide independent consulting activities focused mainly on improving the effectiveness of risk management, control and process management in the areas of ICT and cybersecurity.

Job responsibilities:

  • Carry out independent audits, controls and analyses in the areas of ICT, Business Continuity Management and cybersecurity;
  • Evaluate the actual level of: risk of IT processes, products and services, and compliance with legislative requirements;
  • Lead audit teams when performing audits;
  • Assess the design and implementation of internal controls;
  • Identify changes whose implementation may improve the quality of the control environment as well as process performance;
  • Provide advice to various bank departments;
  • Identify and communicate audit findings to bank management;
  • Create and update audit methodologies and comment on the bank's internal regulations and policies;
  • Apply on a daily basis a results-based approach to the continuous assessment of risk developments in the bank;
  • Actively participate in preparing annual and three-year audit plans;
  • Attend meetings of bank committees and boards, steering committees of selected projects, or other management meetings to contribute to the bank's effective risk management.
  • Actively communicate with bank management to regularly inform them about ongoing internal audit activities for ICT and cybersecurity, and to flag emerging and newly identified risks, whether during audits or during the continuous risk assessment process in these areas.
  • Assess the bank's digital operational resilience in line with DORA requirements, including ICT risk management, incident management, digital resilience testing and management of risks related to external ICT service providers.
  • Evaluate the adequacy of cybersecurity governance, security controls and risk management according to recognised frameworks, in particular the NIST Cybersecurity Framework 2.0, ISO/IEC 27001, COBIT and the internal standards of the banking group.
  • Audit risks associated with the use of artificial intelligence and automation in banking processes, including data security, model governance, access rights, transparency, accountability and compliance with internal and regulatory requirements.
  • Monitor legislative and regulatory changes in cybersecurity, in particular the requirements of Act No. 69/2018 Coll. on Cybersecurity, NIS2, guidelines of NBÚ, NBS and European supervisory authorities relevant to the banking sector.
  • Prepare clear audit reports and recommendations for senior management that link technical findings to their impact on operational resilience, client protection, regulatory compliance and the bank's reputational risk.

Required experience

Field of education

University degree (Master's level), technical field

Language skills

English - Upper intermediate (B2)

Years of experience

At least 5 years of relevant experience, ideally including at least 3 years in IT/ICT audit, cybersecurity, IT risk management or technology risk management in the financial sector

Required skills, qualifications and knowledge

  • At least 3 years of experience in IT audit, IT operations or IT security;

  • Knowledge of and practical experience with auditing or assessing controls against frameworks and requirements such as COBIT, ITIL, ISO/IEC 27001, ISO 22301, NIST Cybersecurity Framework 2.0, PCI DSS, DORA, NIS2, the Cybersecurity Act and relevant IIA methodologies;

  • Good overview and knowledge of information technology, BCM and cybersecurity and related risks;

  • Good understanding of banking ICT processes and risks, in particular in core banking systems, payment services, digital channels, cloud services, outsourcing, identity and privileged access management, data security and continuity of critical services;

  • Ability to assess risks associated with artificial intelligence, machine learning and automated decision-making, including data quality, model security, explainability, ethical use and responsible management of AI solutions;

  • Experience in assessing incident management, vulnerability management, security monitoring, response to cyber incidents, disaster recovery, BCM and digital operational resilience testing;

  • Ability to independently lead audit engagements, define audit scope and testing approach, conduct interviews with management and specialist departments, evaluate evidence and formulate clear, factual and actionable recommendations;

  • Experience using tools for analysing system configuration and security (e.g. Nessus, Nmap, Nikto, RAT, etc.);

  • CISA, CRISC or CISM certification is an advantage.

  • Experience in the banking or financial sector is an advantage, as is knowledge of the regulatory environment of NBS/EBA/ECB and familiarity with requirements on client data protection, outsourcing, cloud and critical or important functions.

  • Knowledge of relevant international standards for the professional practice of internal auditors under the IIA;

If this job description interests you, send us your CV and we will get back to you. We will discuss everything important about working at VÚB at an online or in-person meeting. We look forward to meeting you!