HBP (Amsterdam - Haarlerbergpark), Netherlands
Onsite
Do you have passion and experience in making risk visible, measurable, and manageable in a workflow management and process automation domain with engineering background? As a Risk Engineer in Workflow Management, you will translate internal risk and external regulatory requirements into practical controls that help us protect our Platforms and improve engineering quality. You will combine risk expertise, data, and automation to reduce manual compliance effort and improve audit readiness.
The team
You will join the Workflow Management domain, where our engineering and product teams build and run PEGA and Camunda Platform as-a-service that support core business processes. In this role, you operate at the intersection of Engineering, Risk, Compliance, and Audit.
Your mission is to ensure controls are not just documented, and evidenced but also operational, testable, and effective. You will partner with IT area and product leads, control owners, DevOps teams and first- and second-line risk stakeholders to strengthen control maturity, close findings, and build a sustainable risk-by-design culture.
Team is currently undergoing a strategic move to engineering driven approach, focusing on automating reporting, creating dashboards and codifying or automating manual tasks. Development, as well as risk background is required.
Roles and responsibilities
In this role, you will improve the domain's risk posture through clear ownership, strong execution, and measurable outcomes. You will:
Ensure ongoing compliance with IT Risk Management Policy (ITRMP) and The Third and Intragroup Party Management Control Standard (TIPM CS) requirements across the Workflow Management area.
Translate risk & compliance policies, regulatory requirements, and internal control requirements into implementable team level controls, control objectives, and evidence standards.
Design, implement, and continuously improve team’s internal controls governance with clear owners, frequencies, and test criteria.
Monitor control performance using KPIs and OKRs, and escalate underperformance or control breaks with clear remediation plans.
Automate (python/java) control evidencing and monitoring workflows to reduce manual effort and increase evidence quality.
Build and maintain risk and control dashboards (Power BI/GSOC portal) to report control effectiveness, findings trends, and residual risk.
Coordinate SOX and internal CAS audit activities, including evidence preparation, walkthrough support, and timely closure of action items.
Lead issue management for security related incidents by tracking findings, driving root cause analysis, and ensuring corrective actions are implemented and verified.
Collaborate with engineering and product teams to embed risk-by-design principles in delivery processes and change governance.
How to succeed
We hire smart people like you for your potential. Our biggest expectation is that you'll stay curious. Keep learning. Take on responsibility. In return, we'll back you to develop into an even more awesome version of yourself.
You will be successful in this role when you can:
Demonstrate strong working knowledge and experience (4+ years) of ITGC, SOX, and at least one recognized framework (ITRMP, TIPM) and apply these to real engineering controls.
Show hands-on experience in control design, testing, and evidencing in a technology environment (not only policy writing).
Show hands-on experience in writing automation in one of the programming/scripting languages (2+ years of experience)
Use data to build dashboards and visual aids that help to steer risk decisions by creating clear reporting on control effectiveness, issue backlog, and remediation performance,
Lead cross-functional stakeholders toward timely remediation, even when owners and priorities are distributed.
Identify structural control weaknesses and implement practical process improvements that increase control maturity.
Communicate complex risk topics in clear business language to engineers, product managers, and auditors.
Application screening criteria
Proven experience (typically 4+ years) in IT Risk, IT Controls, Technology Compliance, or IT Audit in a regulated or large enterprise environment.
Practical experience with SOX and ITGC controls, including control execution/testing/evidence and audit support.
Demonstrable experience designing or improving controls in engineering or IT operations processes.
Working knowledge of one or more control frameworks: COBIT, ISO 27001, or NIST.
Ability to produce clear, audit-ready documentation in English.
Experience automating control monitoring/evidence collection.
Strong dashboarding and analytics capability (Power BI, GSOC portal or equivalent).
Experience in workflow/process platforms and control implementation in those environments.
Track record of reducing repeat findings and improving control effectiveness metrics.
Evidence of strong stakeholder leadership across engineering, risk, and audit.
Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.
The benefits of working with us at ING include:
25-28 vacation days depending on contract
Pension scheme
13th month salary
8% Holiday payment
Hybrid working
Personal growth and challenging work with endless possibilities
An informal working environment with innovative colleagues
About us
Curious about how ING empowers people and businesses to move forward?
Discover what we do and what we can offer you.
Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.
Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.
Want to know if this job is worth applying to?