The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
The DORA Implementation & Oversight Analyst the implementation, maintenance and continuous improvement of the DORA governance and control framework across the relevant Apex entities in scope.
The role operates across all European entities of the Apex Group subject to DORA, ensuring a consistent, pragmatic, and well-governed approach to ICT governance, ICT risk management, ICT third-party oversight, incident governance, resilience documentation, and regulatory evidence.
This role focuses on governance, stakeholder coordination, compliance monitoring, documentation management, and management reporting. The successful candidate will work closely with technology, risk, compliance, business, and support functions to help ensure that regulatory obligations, governance activities, and remediation actions are effectively tracked, documented, and reported.
The Analyst reviews the completeness and consistency of DORA documentation, provides constructive challenge within the authority of the role, and escalates material gaps, delays or inconsistencies through the appropriate governance channels.
This position is ideal for professionals with backgrounds in compliance, risk management, internal audit, operational risk, IT governance, regulatory reporting, or program coordination who are looking to develop expertise within a regulated financial services environment.
Job Specification and key responsibilities
DORA framework implementation and maintenance
Support the implementation, maintenance and periodic review of the DORA governance and control framework across the in-scope Luxembourg entities.
Coordinate DORA gap assessments, implementation plans, remediation roadmaps and supporting evidence.
Maintain the consolidated DORA implementation roadmap, clearly identifying accountable owners, milestones, dependencies and target dates.
Support the drafting and review of DORA-related policies, procedures, controls, methodologies, standards, templates and guidance.
Coordinate the incorporation of entity-specific requirements into Group frameworks and identify where local adaptations or supplementary controls are required.
Monitor relevant regulatory developments and prepare documented impact assessments and implementation recommendations.
Promote consistent terminology, documentation standards, evidence requirements and control design across the in-scope entities.
ICT Risk and Control governance
Review the completeness and consistency of ICT risk assessments, control assessments, risk registers, risk-treatment plans and documented risk acceptances.
Coordinate with first-line teams, second-line functions and other control functions to support consistent implementation and evidence standards.
Escalate material gaps, high-risk exposures, recurring deficiencies and significant delays through the appropriate governance channels.
Register of Information and ICT third-party governance
Coordinate the preparation, maintenance, reconciliation and quality review of the DORA Register of Information across the in-scope Luxembourg entities.
Monitor DORA-related requirements concerning ICT third-party arrangements supporting critical or important functions.
Outsourcing and ICT third-party oversight
Support oversight of ICT third-party arrangements and applicable DORA contractual and governance requirements.
Monitor the availability and quality of due diligence, risk assessments, contractual assessments, approvals and supporting evidence.
Monitor concentration risk, subcontracting arrangements, service continuity measures, exit strategies and termination plans.
Support the identification and remediation of material contractual or governance gaps.
Escalate material contractual deficiencies, overdue remediation and unsupported risk decisions.
Digital operational Resilience Testing
Support the planning, coordination and monitoring of the digital operational resilience testing program.
Support a consolidated overview of planned and completed tests, scope, critical functions covered, findings, evidence, action owners and remediation dates.
Monitor testing activities including business continuity exercises, disaster recovery tests, backup restoration tests, scenario-based testing, vulnerability assessments and penetration testing.
Support the coordination and governance of threat-led penetration testing where applicable.
Monitor whether material changes, incidents or identified weaknesses trigger additional testing or reassessment.
Audit, evidence, and regulatory readiness
Maintain an audit-ready evidence repository covering DORA implementation, governance, third-party oversight, and remediation status.
Support preparing concise and high-quality documentation for supervisory interactions and internal governance reporting.
Governance, management reporting and escalation
Maintain the DORA action tracker, risk and issue log, decision log and escalation log.
Report progress, dependencies, emerging risks, overdue actions and management decisions across the in-scope entities.
Escalate high-risk control gaps, regulatory deadline risks, unresolved classification issues and persistent owner non-delivery.
Key deliverables
Consolidated DORA implementation and maintenance roadmap.
DORA action tracker and remediation dashboard.
Register of Information coordination, validation and quality-assurance records.
Digital operational resilience testing overview and findings tracker.
DORA policy and procedure review log.
Required Qualifications
Bachelor's degree in Business Administration, Risk Management, Information Systems, Law, Compliance, or a related field.
Skills Required
5+ years of experience in one or more of the following areas:
Compliance
Risk Management
Internal Audit
Operational Risk
IT Governance
Regulatory Reporting
Good knowledge of ICT risk management, ICT third-party / outsourcing governance, and control documentation
Strong coordination, tracking, and stakeholder management skills
Ability to interpret regulatory requirements and translate them into practical governance arrangements, controls, documentation and actions.
Strong drafting and reporting skills, with the ability to prepare management-ready and audit-ready material
Fluent English
Experience coordinating cross-functional initiatives and managing action trackers.
Strong written and verbal communication skills in English.
Experience preparing reports, presentations, or management information.
Strong organizational and stakeholder management skills.
The role holder is expected to demonstrate:
Regulatory awareness and curiosity.
Analytical and structured thinking.
Strong attention to detail.
Clear and concise drafting.
Evidence-based and risk-based judgement.
Accountability for assigned deliverables.
Strong stakeholder coordination.
Ability to work across multiple functions and legal entities.
Regulatory knowledge
Good working knowledge of DORA and its application to ICT risk management, ICT incident reporting, digital operational resilience testing and ICT third-party risk.
Familiarity with relevant DORA Regulatory Technical Standards, Implementing Technical Standards and ESA guidance.
Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.
Skills Required
- Bachelor's degree in Business Administration, Risk Management, Information Systems, Law, Compliance, or related field
- 5+ years experience in Compliance, Risk Management, Internal Audit, Operational Risk, IT Governance or Regulatory Reporting
- Good knowledge of ICT risk management, ICT third-party/outsourcing governance, and control documentation
- Experience coordinating cross-functional initiatives and managing action trackers, roadmaps and remediation dashboards
- Ability to interpret regulatory requirements and translate them into practical governance, controls and documentation
- Strong drafting and reporting skills; ability to prepare management-ready and audit-ready material
- Fluent English with strong written and verbal communication skills
- Experience preparing reports, presentations, or management information
- Regulatory knowledge of DORA and familiarity with related RTS, ITS and ESA guidance
- Strong organizational, stakeholder coordination and accountability for assigned deliverables
Apex Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Apex Group and has not been reviewed or approved by Apex Group.
-
Flexible Benefits — Flexible benefits are positioned as being tailored by country, with localized packages and perks that can differ by jurisdiction. Mobility options such as the JUMP program add a non-cash element that can increase the perceived total rewards value for those who can access it.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is described as including EAPs, mental-health workshops, mentoring support, and local lifestyle perks like gym or cycle-to-work schemes. These offerings broaden the benefits mix beyond purely financial rewards.
-
Retirement Support — Retirement support is described in at least one jurisdiction as including an employer match structure and an additional automatic contribution after tenure. This can strengthen the non-salary portion of total compensation where offered.
Apex Group Insights
What We Do
We are a single-source financial solutions provider dedicated to driving positive change while supporting the growth and ambitions of asset managers, allocators, financial institutions, and family offices around the world. Established in Bermuda in 2003, we have continually disrupted the industry through our investment in innovation and talent. Today, we set the pace in fund and asset servicing and stand out for our unique single-source solution and unified cross asset-class platform which supports the entire value chain, harnesses leading innovative technology, and benefits from cross-jurisdictional expertise delivered by a long-standing management team and over 13,000 highly integrated professionals. As a pioneering data and fintech-enabled company, we are a disruptor driving digital tools into fund and asset servicing. However, our vision to drive positive change extends beyond the industry. The Apex Foundation, a not-for-profit entity, is our passionate commitment to empower sustainable change






