GRC Specialist – IT Risk & Digital Operational Resilience (Netherlands)
Neema · Netherlands
Apply directly with the employer or job board. Applications are never handled here.
Amsterdam, Netherlands - hybrid (Netherlands-based) | Reports to CEO, Neema EU · standing access to the Management Committee
ABOUT NEEMA
Neema builds infrastructure for seamless cross border money movement.
We enable financial institutions and fintechs to access real time payments multi currency capabilities and hard to reach financial destinations through a growing global network.
We operate in a dynamic startup environment that combines speed ownership and high standards. Senior team members are expected to take initiative, move decisively and drive measurable impact.
ROLE OVERVIEW
You are the owner of the Digital Operational Resilience Act (DORA) framework and of IT risk management within the EMI, accountable for keeping the ICT environment - payment pipelines, cloud infrastructure and third-party dependencies, compliant with EU regulatory requirements and resilient against cyber and operational disruption. Reporting directly to the CEO of Neema EU, you are the bridge between technology delivery, the risk and compliance functions, and the Dutch regulators (DNB and AP).
This is a hands-on, individual-contributor role: you author the policies and procedures, build and maintain the registers, run the assurance programme over the entity’s ICT service providers, and prepare the entity for supervisory scrutiny. The role sits in the entity’s GRC function as a first-line capability. Independent audit of the ICT risk management framework is provided separately under Article 6(6) DORA, and control ownership within service provider entities stays with those entities, so that your assurance role over them is preserved.
KEY RESPONSIBILITIES
IT and ICT risk management
- Develop, maintain and operate the ICT risk management framework in line with DORA (Regulation (EU) 2022/2554), including the risk taxonomy, assessment methodology, scoring model and risk appetite thresholds.
- Own the IT risk register end to end — identification, assessment, treatment, acceptance, exception handling and remediation tracking — across systems, ICT assets, business processes and change.
- Maintain the determination of critical or important functions under DORA Article 3(22), which drives register scope, contractual requirements and testing scope.
- Ensure controls are designed, implemented, documented and evidenced; maintain the control framework mapping and report risk indicators and control effectiveness to the Management Committee.
Group IT risk management
- Participate in group technology risk governance forums, contribute to consolidated risk reporting, and translate incoming EU technology regulation into practical implications for group technology teams.
Third-party ICT risk management and provider assurance
- Govern ICT third-party service providers across the full lifecycle — due diligence, contracting, ongoing monitoring, concentration risk, sub-contracting chains and exit strategy — ensuring arrangements meet the mandatory provisions of Article 30, including audit, access and inspection rights and supervisory access.
- Plan and execute the audit and assurance programme over the entity’s primary ICT service provider and other providers supporting critical or important functions.
- Build and maintain the Register of Information, deliver its annual submission to DNB, and manage prior notification of planned arrangements covering critical or important functions.
Incident management and regulatory reporting
- Own the classification, logging, escalation and resolution of ICT-related incidents against the DORA classification criteria, and maintain the incident taxonomy, root-cause analysis and lessons-learned loop.
- Deliver the initial, intermediate and final incident notifications to DNB within the prescribed regulatory deadlines and manage the supervisory follow-up.
Resilience testing, continuity and recovery
- Own the annual digital operational resilience testing programme — vulnerability assessments, network security reviews, scenario-based testing and penetration testing — ensuring tests are performed by parties with appropriate independence and that findings are prioritised, remediated and closed with evidence.
- Coordinate, challenge and process the results of the Business Impact Analysis, and ensure ICT-related Business Continuity and Disaster Recovery Plans are maintained, tested at least annually, and demonstrably effective.
Periodic review, assurance and regulatory liaison
- Perform periodic ICT risk and control reviews across the entity and its critical ICT providers and run the mandatory annual review of the ICT risk management framework under Article 6(5) and following any major ICT-related incident.
- Prepare for and support the independent internal audit of the framework; track and report remediation of audit and review findings to the Management Committee.
- Act as the primary internal point of contact for DORA matters, maintain ICT and resilience documentation for supervisory reviews and inspections, and deliver periodic ICT risk briefings and training to the Management Committee in support of Article 5(4).
PROFESSIONAL EXPERIENCE
- Fintech / payments expertise: minimum 3 years in IT risk, cybersecurity, IT audit or ICT compliance, preferably within financial services (EMI, PI or banking).
- IT risk management: proven experience building and running an IT risk management framework end to end — risk register, assessment methodology, appetite, indicators and remediation — not only regulatory gap assessment.
- DORA expertise: hands-on experience implementing DORA requirements, including ICT risk management, third-party risk and the Register of Information.
- Provider assurance: demonstrable experience auditing or assuring ICT service providers, including the ability to hold a firm line with a provider that is larger and better resourced than the entity you represent.
- DNB engagement and communication: experience responding to DNB information requests and managing supervisory correspondence, and familiarity with DNB’s expectations for ICT and operational resilience. Professional working proficiency in English is mandatory; proficiency in Dutch (CEFR C1) is an advantage.
- Analytical and stakeholder skills: able to translate regulatory and technical requirements into practical guidance for DevOps and engineering teams, to operate within the Three Lines of Defence model, and to produce formal reports on DORA matters for senior management.
NICE TO HAVE
- At least one of the following certifications: CISA, CISM, CRISC or CISSP.
- Familiarity with: DNB’s Good Practice Information Security, GDPR, the EU AI Act (Regulation (EU) 2024/1689), PCI DSS, or ISO/IEC 27001, NIST CSF, COBIT.
Applicants must hold, or be eligible for, the right to work in the Netherlands. Neema is an equal opportunity employer.
Keep looking
2,500+ English-friendly jobs in Netherlands
Every one checked for language requirements, updated daily.