Posted Updated
Bnode is strengthening its Group CISO Office and is looking for a senior Cyber Risk Control Architect to help shape how cybersecurity risk is governed across our international organisation. In this role, you will design and continuously evolve the Group Cyber Risk Control Framework , providing a common approach to cyber risk, controls, compliance and reporting across more than 20 entities. Working closely with the Group CISO and Cyber Program Management Lead, you will translate evolving cyber threats, regulatory requirements, audit findings and business priorities into clear risks, controls and actions. You will combine strategic thinking with practical implementation, helping senior leaders make informed, risk-based decisions and strengthening cyber governance across Bnode. Your mission Shape our Group Cyber Risk Control Framework Own and continuously improve the Group Cyber Risk Control Framework. Define cyber risk scenarios, control objectives, KRIs and maturity criteria. Translate emerging threats, regulatory requirements, audit findings and maturity assessments into clear cyber priorities. Support risk appetite discussions and risk-based decision-making at Executive Committee and Board level. Strengthen governance, compliance and reporting Define and maintain the methodology supporting the Group Cyber Plan. Create clear traceability between cyber risks, controls, regulatory requirements, remediation plans and strategic initiatives. Develop integrated reporting covering cyber risk, programme delivery, control effectiveness and NIS2 compliance. Support reporting to senior management, the Board and the Audit Risk Committee. Develop our cyber data, processes and tooling Design scalable processes to collect, validate and consolidate cyber data across more than 20 entities. Establish reporting cycles, responsibilities and data-quality standards. Develop the data model connecting risks, controls, compliance obligations, action plans and reporting. Lead the selection and evolution of GRC and related cyber governance tooling. Drive greater automation and standardisation across cyber risk, compliance and reporting. Drive continuous improvement Ensure the framework evolves with the threat landscape, regulation, audit findings and changing business priorities. Promote greater consistency and maturity across the Group while recognising the needs of different entities. Identify opportunities to improve control effectiveness, risk visibility and the quality of cyber reporting.