Responsibilities
- Perform in-depth assurance activities across technical and operational domains.
- Evaluate and maintain Avaloq’s information security risk posture.
- Drive consistency in control design, testing, and audit readiness.
- Collaborate closely with stakeholders across Architecture, IT Operations, Cloud Engineering, Audit, Legal, Risk Management and Product Teams.
- Support the continuous evolution of Avaloq’s security control framework and risk assessment processes.
- Contribute significantly to strengthening Avaloq’s security posture and ensuring robust alignment with regulatory and contractual expectations.
- Determine and document Technical IT security controls, ensuring they are effectively mapped to Avaloq’s internal control framework.
- Determine the information security risk profile for each relevant service and asset.
- Perform and maintain asset-based information security risk assessments in line with ISO 27005, including recurring reviews.
- Identify and assess residual risks and consolidate aggregate risk across services and environments.
- Ensure that Avaloq maintains Operational Resilience in line with regulatory, business continuity, and reliability requirements.
- Track all requirements from Legal, Regulatory, and Contractual sources and translate them into actionable obligations.
- Map legal and regulatory requirements to the control framework and ensure recurring validation of control adequacy.
- Execute repeatable and automated testing of security control effectiveness.
- Lead or support audit preparation, coordination, evidence collection, automation of audit workflows, and audit response activities.
- Collaborate with Engineering, Architecture, Operations and Compliance teams to drive remediation and continuous improvement in the Information Security Management System (ISMS), ensuring alignment with emerging threats and industry best practices.
- Contribute to maintaining a strong and transparent Security Assurance documentation base.
Requirements
- Perform in-depth assurance activities across technical and operational domains.
- Evaluate and maintain Avaloq’s information security risk posture.
- Drive consistency in control design, testing, and audit readiness.
- Collaborate closely with stakeholders across Architecture, IT Operations, Cloud Engineering, Audit, Legal, Risk Management and Product Teams.
- Support the continuous evolution of Avaloq’s security control framework and risk assessment processes.
- Contribute significantly to strengthening Avaloq’s security posture and ensuring robust alignment with regulatory and contractual expectations.
- Determine and document Technical IT security controls, ensuring they are effectively mapped to Avaloq’s internal control framework.
- Determine the information security risk profile for each relevant service and asset.
- Perform and maintain asset-based information security risk assessments in line with ISO 27005, including recurring reviews.
- Identify and assess residual risks and consolidate aggregate risk across services and environments.
- Ensure that Avaloq maintains Operational Resilience in line with regulatory, business continuity, and reliability requirements.
- Track all requirements from Legal, Regulatory, and Contractual sources and translate them into actionable obligations.
- Map legal and regulatory requirements to the control framework and ensure recurring validation of control adequacy.
- Execute repeatable and automated testing of security control effectiveness.
- Lead or support audit preparation, coordination, evidence collection, automation of audit workflows, and audit response activities.
- Collaborate with Engineering, Architecture, Operations and Compliance teams to drive remediation and continuous improvement in the Information Security Management System (ISMS), ensuring alignment with emerging threats and industry best practices.
- Contribute to maintaining a strong and transparent Security Assurance documentation base.
Work Arrangement
Hybrid