.
Risk Assessor in OCRA Team
  • Kraków
Risk Assessor in OCRA Team
Kraków, Kraków, Lesser Poland Voivodeship, Polska
UBS
22. 1. 2026
Informacje o stanowisku

Join to apply for the Risk Assessor in OCRA Team role at UBS

3 days ago – Be among the first 25 applicants

Responsibilities

You will evaluate the security posture of third‑party vendors that have access to sensitive information or systems of UBS. You will conduct risk assessments to identify and evaluate potential security threats posed by third‑party vendors and recommend risk mitigation strategies to minimize the organization’s exposure to cyber threats. You will also work closely with internal stakeholders to ensure that third‑party vendors comply with UBS’s cybersecurity policies and procedures.

Key Experience

  • Conduct risk assessments of third‑party vendors to identify potential security threats and vulnerabilities
  • Conduct cloud assessments
  • Conduct audits
  • Analyse and evaluate vendor security controls, policies, and procedures to ensure compliance with regulatory requirements and industry best practices
  • Develop and implement risk mitigation strategies to address identified vulnerabilities and reduce the organization’s exposure to cyber threats
  • Communicate assessment findings and recommendations to internal stakeholders, including senior management, legal, and compliance teams
  • Monitor and track vendor compliance with security policies and procedures through ongoing assessment activities

Job Details

Job Type: Full Time

Job Reference #: 328120BR

City: Kraków, Wroclaw

Your team: You’ll be working in the CISO/OCRA (Operational Consolidate Risk assessment) team. You’ll support colleagues from different areas of the firm, including Risk Taxonomy Owners, Compliance & Operational Risk Controllers and Outsourcing & Supplier Management, in improving the overall risk assessment process and implementing the most effective remediation measures.

Additional Assets

  • Experience with industry recognized standards for IT security controls and best practices like NIST, ISO27001, PCI DSS, COBIT, SOC 2 etc.
  • Professional qualification obtained: CEH, CISSP, CISA, CISM, CRISC or ITIL

Requirements

  • Bachelor’s degree with professional certification in Cybersecurity, Cloud Security or a related field of study
  • Audit experience/mindset
  • 5+ years of experience in third‑party risk assessment or cybersecurity assessment
  • Ability to communicate effectively with both technical and non‑technical stakeholders
  • Strong analytical and problem‑solving skills
  • Certifications such as Certified Third‑Party Risk Professional (CTPRP) or Certified Information Systems Security Professional (CISSP) are a plus

Personal Traits

  • A strong communicator, with good spoken and written English
  • Good team player with analytical ability to provide practical solutions for minimizing risk
  • Well organized, detail oriented, with the ability to collect data, coordinate tasks and lead projects
  • Comfortable taking the lead, but not hesitant to bring in the expertise of colleagues to help the team
  • Having risk identification and risk articulation skills
  • Ability to build and maintain strong relationships with stakeholders
  • Ability to show initiative, make logical decisions and stay goal oriented at unclear times
  • Available to work in a hybrid model at least 3 days from the office

About UBS

UBS is a leading and truly global wealth manager and the leading universal bank in Switzerland. We also provide diversified asset management solutions and focused investment banking capabilities. Headquartered in Zurich, Switzerland, UBS is present in more than 50 markets around the globe.

Why Join UBS

We know that great work is never done alone. That’s why we place collaboration at the heart of everything we do. At UBS, we’re dedicated to our craft and passionate about putting our people first, offering new challenges, a supportive team, opportunities to grow and flexible working options when possible.

We’re committed to disability inclusion and if you need reasonable accommodation/adjustments throughout our recruitment process, you can always contact us.

UBS is an Equal Opportunity Employer. We respect and seek to empower each individual and support the diverse cultures, perspectives, skills and experiences within our workforce.

Report misconduct: If you are made aware of any of our employees or individuals acting on behalf of UBS engaging in acts of misconduct under the Poland Whistleblowing Act, you may report your concerns through Poland-Whistleblowing@ubs.com

#J-18808-Ljbffr

  • Praca Kraków
  • Team leader Kraków
  • Kraków - Oferty pracy w okolicznych lokalizacjach


    138 684
    20 326