Capco poland

DORA Governance & TPRM Specialist

Italy - Milan Full Time

Joining Capco means joining an organization that is committed to an inclusive working environment where you’re encouraged to #BeYourselfAtWork. We celebrate individuality and recognize that diversity and inclusion, in all forms, is critical to success. It’s important to us that we recruit and develop as diverse a range of talent as we can, and we believe that everyone brings something different to the table – so we’d love to know what makes you different. Such differences may mean we need to make changes to our process to allow you the best possible platform to succeed, and we are happy to cater to any reasonable adjustments you may require. You will find the section to let us know of these at the bottom of your application form or you can mention it directly to your recruiter at any stage and they will be happy to help.

About Capco

Capco is a global technology and business consultancy, focused on the financial services sector. We are growing at fast pace in our Italian office, the opportunity for growth is large, accessible, and immediate. We are passionate about helping our clients succeed in an ever-changing industry. Capco is going through a significant growth journey, now is a very good time to join us as we expand our consulting team in Italy.

Role Description:

As part of the consulting team, the DORA Governance & TPRM Specialist will:

  • Support the definition, implementation, and evolution of the Digital Operational Resilience framework in line with DORA, including governance, roles, responsibilities, and reporting
  • Monitor and manage ICT and third-party risks, with a focus on service providers and outsourcing arrangements
  • Contribute to the ICT Third-Party Risk Management (TPRM) framework, including risk assessment, due diligence, and ongoing supplier monitoring
  • Support second line of defense activities within the ERM framework (e.g., KRI, RAF, controls), focusing on ICT and security risks
  • Maintain and update the Register of Information (RoI), ensuring data quality and completeness of ICT services and providers
  • Support the definition and maintenance of policies and procedures related to ICT risk, digital resilience, and third-party management
  • Contribute to the ICT Risk Appetite Framework, including indicators, thresholds, and escalation mechanisms
  • Support ICT incident management oversight and remediation processes
  • Prepare reporting and dashboards to communicate ICT and third-party risk exposure to senior stakeholders
  • Collaborate with cross-functional teams to ensure alignment on digital resilience initiatives

Skills and Experience

To qualify for the role you must have:

  • Bachelor’s degree in economics, engineering, law or related fields
  • 3–6 years of experience in ICT Governance / Risk & Compliance / Operational Resilience / Third Party Risk Management, and consulting
  • Good knowledge of Digital Operational Resilience Act (DORA) and ICT risk management frameworks
  • Understanding of ICT outsourcing and third-party risk management processes
  • Experience in drafting policies, procedures and regulatory documentation
  • Strong analytical skills and excellent communication skills
  • Ability to interact with multiple stakeholders across different functions

Nice to have:

  • Professional certifications (e.g. CRISC, CISA, CISM, ISO 27001, ISO 22301)
  • Experience in financial services or insurance sector

Why join Capco?

You will work on engaging projects with some of the largest banks in the world, on projects that will transform the financial services industry.

We offer:

  • A work culture focused on innovation and building lasting value for our clients and employees
  • Ongoing learning opportunities to help you acquire new skills or deepen existing expertise
  • A flat, non-hierarchical structure that will enable you to work with senior partners and directly with clients
  • A diverse, inclusive, meritocratic culture

Location: Piazza Gae Aulenti 1, Milan (Garibaldi FS/MM Garibaldi)

#LI-Hybrid

#LI-AD1