New

ICT Risk & Resilience Manager (Dublin)

Dublin, Ireland

Position Title: ICT Risk & Resilience Manager (Dublin)

Entity: Kroll Bond Rating Agency Europe Limited

Employment Type: Full-time

Location: Dublin, Ireland 

Summary/Overview:

The First Line ICT Risk & Resilience Analyst is responsible for supporting the effective operation of the organization’s ICT governance, risk management, resilience, and incident response processes in line with the EU Digital Operational Resilience Act (DORA). The role will focus on ensuring that ICT risk and resilience controls are implemented, maintained, and evidenced on a day-to-day basis, while coordinating with ICT Owners, the Operational Resilience Committee, and the wider business.

This is a hands-on first line of defense role requiring close collaboration with technology teams, business units, second line oversight functions, and regulators.

We are seeking a proactive ICT Risk & Resilience Manager to join our first line of defense team.  The role will focus on ensuring that ICT risk and resilience controls are implemented and maintained and  plays a key part in ensuring our IT governance, risk management, and operational resilience practices meets regulatory requirements.  This is a hands-on first line of defense role requiring close collaboration with technology teams and business stakeholders.

You will work closely with IT teams and business stakeholders to implement controls, manage incidents, and support resilience testing.

About the Job:

  • Implement the ICT Risk Management Framework in day-to-day operations working closely with IT teams and other stakeholders.
  • Maintain evidence of ICT control operation and track remediation of compliance gaps.
  • Support management reporting by maintaining dashboards of ICT risk and resilience activities, incidents, and testing.
  • Maintain and update the ICT risk register, asset inventories, dependency mapping, and business impact analyses.
  • Participate in ICT incident management, including classification, reporting, and post-mortem reviews.
  • Plan and deliver business continuity, disaster recovery, information security and other resilience tests.
  • Conduct scenario-based walkthroughs to validate resilience against severe but plausible risks.
  • Conduct due diligence and monitoring of ICT third-party providers, including maintenance of register of ICT third-party providers.
  • Support ICT governance, including preparation of committee materials and escalation of ICT risk issues.
  • Collate and document first line evidence of resilience test results, remediation actions, and progress tracking.

Skills & Competencies:

  • Strong understanding of ICT risk management frameworks (e.g., NIST, ISO 27001) and operational resilience principles.
  • Knowledge of DORA requirements and practical experience in ICT governance, risk, and compliance (GRC).
  • Experience with disaster recovery and information security testing.
  • Strong incident management and reporting skills.
  • Ability to work across first and second line functions with a collaborative mindset.
  • Excellent written and verbal communication skills, strong attention to detail, analytical thinking, and problem-solving capabilities.

You will be successful in this role if you have:

  • Bachelor’s degree in information technology, information security, risk management, or related field
  • 3-5 years of experience in ICT risk management, ICT operations, or ICT audit.
  • Professional certifications preferred (e.g., CISA, CRISC, CISM, CISSP).
  • Experience with GRC platforms (e.g., AuditBoard) desirable.
  • Experience within financial services or other regulated sectors advantageous.
  • Familiarity with Generative AI tools such as ChatGPT for research, data insights, and general productivity is a plus.

Benefits

  • A flexible hybrid work schedule – Tuesdays, Wednesdays, Thursdays in the office
  • Competitive benefits and paid time off
  • Paid family and disability leave
  • Pension plan
  • Educational and professional development financial assistance
  • Employee referral bonus program

About Us

KBRA (Kroll Bond Rating Agency, LLC) is a full-service credit rating agency registered with the U.S. Securities and Exchange Commission as an NRSRO. Kroll Bond Rating Agency Europe Limited is registered as a CRA with the European Securities and Markets Authority. Kroll Bond Rating Agency UK Limited is registered as a CRA with the UK Financial Conduct Authority pursuant to the Temporary Registration Regime. In addition, KBRA is designated as a designated rating organization by the Ontario Securities Commission for issuers of asset-backed securities to file a short form prospectus or shelf prospectus. KBRA is also recognized by the National Association of Insurance Commissioners as a Credit Rating Provider. Kroll Bond Rating Agency Europe is located at 2nd Floor, One George's Quay Plaza, George's Quay, Dublin 2 D02 E440.

 

#LI-KS1

#HYBRID

Create a Job Alert

Interested in building your career at KBRA? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in KBRA’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.