Sygnum is a global digital asset banking group, founded on Swiss and Singapore heritage. We empower professional and institutional investors, banks, corporates and DLT foundations to invest in digital assets with complete trust. Our team enables this through our institutional-grade security, expert personal service and portfolio of regulated digital asset banking, asset management, tokenization and B2B services.
In Switzerland, Sygnum holds a banking licence and has CMS and Major Payment Institution Licences in Singapore. The group is also regulated in the established global financial hubs of Abu Dhabi, Luxembourg and is registered in Liechtenstein.
We believe that the future has heritage. Our crypto-native team of banking, investment and digital asset technology professionals are building a trusted gateway between the traditional and digital asset economies that we call Future Finance. To learn more about how Sygnum's mission and values are shaping this digital asset ecosystem, please visit sygnum.com and follow us on LinkedIn and X.
Our Values
A key pillar of our success are the Sygnum values that define and unite us a team. We proudly call them our SYGN values:
- S stands for the importance we hold in Seeking and seizing opportunities, and the way we take personal ownership for delivering results for our clients;
- Y represents the way we say Yes to maintaining the highest level of integrity and fairness in everything we do. Sygnumers always display confidence without attitude;
- G reminds us to always Grow and win together. We only succeed by supporting each other and challenging ourselves, and our team-mates, to reach for new heights;
- N is here for Nose for value because we are always looking to focus on what matters most to our clients, partners and team.
Sygnum has one of the most diverse teams in the industry. Diversity plays a central role in keeping our work culture open, our teams productive and energised, and our solutions at the forefront of the industry. In the spirit of our SYGN value to “grow and win together”, we fully embrace an equal opportunity mindset in the way we onboard, develop and promote our team members.
About the role
This is a unique opportunity to work at the intersection of a digital-native and FINMA-regulated bank with an international footprint, combining the pace and technology stack of a digital-first organization with the rigor of a regulated financial institution.
We are looking for an experienced Information Security Risk Manager to join our Information Security function in Zurich. Reporting to the CISO, you will own the security control catalogue end to end, drive the enterprise information security risk assessment process, and act as the primary liaison for regulatory and audit engagements. You will also help modernize how we monitor and report on control performance by automating oversight across cloud, endpoint, and other data sources, and you will keep the organization security-aware through an engaging awareness program.
Key responsibilities
- Own the information security control catalogue, including control oversight, effectiveness rating, KPI measurement, and deficiency remediation.
- Manage and perform the top-down and bottom-up information security risk assessment processes.
- Provide subject matter expert input relating to all aspects including IT risks, security measures, controls, and remedial actions.
- Drive automation of security oversight processes, integrating information from multiple sources (cloud, endpoint, and others) into unified reporting dashboards.
- Provide information risk and security subject matter expertise inputs and assessments to our IT and business teams in support of their risk management activities.
- Oversee information security audits, whether performed by the Bank or third- parties.
- Support our culture development of information and security risk awareness, hence, good conduct through supporting regular communications, awareness, and training.
- 5+ years of professional experience in information risk frameworks and management and IT audit, preferably in a mid/large-sized financial institution or audit company.
- Solid working knowledge of recognized frameworks such as NIST CSF, ISO 27001, or CSA CCM, and experience applying them to real-world control environments.
- Professional certification such as CISSP, CISM, or CRISC (or actively working toward one).
- Familiarity with security tooling and data sources across cloud and endpoint environments, and an interest in automating oversight and reporting (e.g., dashboards, GRC platforms, scripting/BI tools).
- Proven communication and interpersonal skills, including multi-stakeholder management.
- Strong communication skills, written and verbal in English.
- Understanding in and knowledge of digital assets, hence, some experience working in Agile, or DevSecOps models is a plus.
- Experience with cloud security in AWS and Microsoft Azure, as well as in Cloud Security Posture Management (CSPM) tools, such as Wiz, is a plus.
Our Offer
Joining Sygnum means being part of a dynamic, global team that is building a trusted gateway between the traditional and digital asset economies. Working at Sygnum, you will experience our fast-paced, exciting work environment that embraces meritocracy and collaboration and open communication. Alongside our ambitious long-term mission, we also come together for reaching important milestones and annual crypto-industry anniversaries like Bitcoin Pizza Day, and regularly celebrate together at themed company events as part of our journey to shape Future Finance.
Sygnum offers a comprehensive package of benefits for all team members. They include:
- Attractive combination of market salaries and entrepreneurial incentive scheme
- Professional development via Mentoring and Buddy programs
- One-month fully paid sabbatical after five years of continuous employment
#J-18808-Ljbffr
Information Security Risk Manager in Zürich Arbeitgeber: Sygnum Bank
Sygnum Bank in Zürich ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern nicht nur ein wettbewerbsfähiges Gehalt, sondern auch flexible Arbeitsbedingungen und umfangreiche Weiterbildungsmöglichkeiten bietet. Die Unternehmenskultur fördert Innovation und Zusammenarbeit, was es Ihnen ermöglicht, in einem dynamischen Umfeld zu wachsen und bedeutende Beiträge zur Entwicklung digitaler Vermögenslösungen zu leisten.