Natixis in Portugal is hiring an

IT Risk Analyst - French Speaker

Porto, Portugal

The Groupe BPCE DSG provides the second line of defense (LoD2) regarding IT risks (including cyber risk), business continuity, safety of staff and premises and external fraud.

The Groupe BPCE DSG oversights all the entities of the Group, which includes the retail banking (such as the French Banques Populaires and the Caisses d’Epargne), but also the global banking (such as the CIB or the Asset and Wealth Management).

The TRM center of expertise (CE TRM) coordinates LoD2 operations (risk analysis, level 2 controls, action plans, security reviews, etc.) for all group establishments that have adopted the Technology Risks Management (TRM) model.

The DSG works in close collaboration with the entities of the Group (BPCE-IT, BPCE SI, IT departments of Natixis and BPCE SA, etc.), and the Operational Risk departments.

The G-TRM team at Natixis Portugal oversees operating level 2 controls of TRM type for all the entities covered by CE TRM. These L2 controls are related to all taxonomies covered by CE-TRM and policies validated on BPCE Groupe.

As part of the G-TRM team, you will be part of the Security Design & Delivery team, working alongside our global Governance, Risk & Compliance, and Security Operations teams. Your mission consists in supporting the TRM Center of Expertise (CE TRM) located in Paris, by performing Security by design activities.

Main tasks and goals:

  • Owning the security architecture deliverables within SI’s cloud Center of Excellence strategy
  • Owning the creation and development of all technical standards within the security roadmap, working with Security Operations and Leadership to deliver functional requirements.
  • Providing dedicated technical expertise and knowledge to support the risk management framework
  • Driving security by design throughout both lines of business and BPCE through engagement with stakeholders from all levels
  • Assessing business requirements to select the most appropriate security controls.
  • Mastering the internal catalog of security solutions and be able to advise the business on requirements implementation and analyze technical alternatives if needed.
  • Identifying new tools and technologies which enable the achievement of business goals.
  • Proactively identifying vulnerabilities to business systems, and designing and implementing security controls

Gap analysis and refinement of use cases for response to relevant threats.

What we require of you

  • Strong background across the wide security landscape
  • Demonstrable experience of being in senior technical and hands-on security roles
  • Proven track record of designing and delivering cloud infrastructure security controls
  • Cost-benefit analysis skills to assess security tools to improve BPCE security by design framework
  • Evidence of a strong understanding of securing a software development life cycle
  • Significant experience in a role with all IaaS / SaaS / Cloud; specifically AWS and MS Azure
  • Fully competent in delivering technical projects using Project Management methods

You will be in close cooperation with all the players in the second line of defense teams (Information system Security, Legal, Business Continuity, Data Privacy) and other IT Departments

We would expect you to have:

  • Degree in one of these areas: Cybersecurity; IT Engineer; Managing IT Systems
  • +3 years of Managing IT Risks and Security by Design;
  • 1-3 years of Risk HeatMap;
  • >1 year of Pentests and Audits;
  • Fluency in English and Good level of French (Mandatory);
  • Advanced Knowledge of Drive (Archer); MS Excel; PowerBI; Splunk.
  • Certification of other security or IS audit standard (preferred)
  • a good knowledge of information systems and technologies.
  • a critical and result-oriented mindset.
  • been able to demonstrate your autonomy and proactiveness.
  • knowledge of the banking and insurance sectors.

At Natixis, we are committed to fostering a working environment where each and every one of our people is treated with dignity and respect and where every voice is heard. Our differences make us collectively stronger and are a source of fulfilment, innovation and performance.

In the framework of its Diversity, Equity & Inclusion policy, Natixis in Portugal has implemented a Blind CV Screening process, with the purpose of reducing hiring bias. A blind CV excludes any personal details which refer to the applicant’s gender, age or ethnicity. When applying for our positions, please submit a blind CV, that is, with no picture, name, gender, age, nationality, ethnicity and address. Your personal statement, work experience, courses and certifications, education, skills and contact information is what matters to us.


Early morning. Campo 24 de Agosto. In 4 minutes, you are clocking in at the office. After grabbing a cup of coffee and fresh fruit, pick up your laptop and choose your spot for the day. It's going to be a busy one: French class before lunch and, just after, quick medical appointment at Natixis doctor's office.

Lunch break. Outside in the big terrace (look at your crops at the Urban Garden; ready to harvest!) or, if you feel like stretching your legs, walk downtown to grab lunch.

Back inside. Quick sprint review (working together anywhere means virtual happy birthday to that colleague in Paris that just turned 35). The afternoon went flying (tasks, reports, calls, some jokes with your teammates). End it on a high note: just one PlayStation game or the final match for that ping-pong tournament.

Tomorrow, you complete that certified technical training and the day after, you will work from home, taking advantage to finally do that online course on Udemy. Once you are done with your tasks for the day, you can visit the office for a board games session or show up at the rehearsal of one of Natixis bands. If that is too steady for you, meet your colleagues to surf some waves or join them in a football match.

This job is no longer available

Enter your email address below to get notified whenever we find a similar job post.

Unsubscribe at any time.