
Senior Cyber & Tech GRC Risk Management Analyst
- Porto
- Permanente
- Horário completo
- Lead the operation of the Cyber & Tech Risk Management Program, ensuring continual identification, assessment, tracking, and visibility of key risks.
- Facilitate risk identification and documentation in the risk register.
- Guide and support risk owners in evaluating risks and selecting appropriate treatment strategies.
- Ensure periodic reviews and updates of risks and associated actions.
- Develop dashboards and concise reports that clearly communicate risk metrics and trends.
- Present risk insights and updates to both technical and non-technical senior stakeholders.
- Act as a Subject Matter Expert (SME) on cyber and technology risks for business initiatives.
- Ensure emerging and evolving risks are captured and aligned with Flutter’s risk appetite.
- Support internal and external audits related to cyber and technology risk domains.
- Contribute to the ongoing improvement of risk frameworks, methodologies, and tools.
- Contribute to the maintenance and enhancement the Flutter Controls Library to ensure accurate reflection of controls, to mitigate our key risks across the enterprise.
- Drive value from GRC tooling to streamline risk management, governance, and reporting processes.
- Monitor emerging threats, regulatory changes, and industry standards to identify and propose enhancements to Flutter’s cyber risk posture and control environment.
- Partner with GRC teams across the group to ensure a unified and consistent risk management approach.
- Build strong relationships with cyber, technology, and business stakeholders to ensure risk-related activities are embedded and effective.
- Maintain deep awareness of divisional risk profiles, control environments, and operating models.
- Promote a risk-aware culture through thought leadership and practical engagement.
- Minimum 5 years’ experience in information security.
- Experience in governing or managing cyber and technology risks, including good understanding of assessment methodologies, controls, and mitigation strategies.
- Previous experience of using tools (such as GRC or service management ones) to operate risk management processes.
- Proficiency in industry frameworks and standards (e.g., NIST, ISO 27001, PCI DSS, COBIT, ITIL); certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Implementer/Auditor, ITIL Foundation or COBIT Foundation are a plus
- Solid technical knowledge of security technologies and best practices.
- Awareness of the 3 lines of defence model, roles of second line/assurance functions and internal audit
- Demonstrated ability to communicate complex information clearly to diverse audiences.
- Strategic thinker with the ability to influence and drive change across varied business functions.
- Strong analytical and investigative mindset; able to provide objective, data-driven insights.
- Results-focused, with a pragmatic approach to risk mitigation and decision-making.
- Fluent in English with excellent written and verbal communication skills.
- Highly organized, methodical, and adaptable to a fast-paced, dynamic environment.
- Influential and Trustworthy: Builds strong, trust-based relationships with stakeholders across the business.
- Objective: Approaches challenges with neutrality and fairness, ensuring consistent, evidence-based decisions.
- Collaborative: Works seamlessly with cross-functional teams to deliver on shared objectives and business outcomes.
- Adaptable: Navigates diverse perspectives with flexibility to reach optimal outcomes.
- Strategic Thinking: Maintains a forward-looking mindset aligned with Flutter’s broader technology and business goals.
- Effective Communication: Proactively engages stakeholders, communicates with purpose, and helps influence change through insight and clarity.
We are committed to including everyone regardless of their race, disability, age, gender identity, sexual orientation, and religion.
Everyone brings different perspectives and experiences; you don’t have to meet all the requirements listed to apply for this role.If you need any adjustments to apply for the position and to ensure this role aligns with your needs, please send an email to accommodations@blip.pt .We will only respond to inquiries related to disabilities.