ING BE’s Non Financial Risk team
Non-Financial Risk (NFR) ING BE is a trusted business partner challenging and advising business and IT on performing balanced and pragmatic Non-Financial Risk Management. As second Line of Defense (2LoD), its main activities consist of identifying, assessing, monitoring, and reporting on non-financial risks. To achieve this, NFR sets and monitors policies and risk appetite statements, defines and monitors key risk indicators, objectively challenges the execution of non-financial risk management by the 1LoD and advises the organisation on NFR related topics.
Position Overview
The Head of Information Risk Management (IRM) is a leadership role responsible for developing, implementing, and overseeing the bank’s IT risk management framework. This position ensures that the bank’s information technology systems are secure, resilient, and aligned with regulatory requirements and business objectives. The role involves strategic oversight, risk governance, a strong pragmatic approach, and collaboration across business units to safeguard the bank’s digital assets and operations. The Head of IRM also leads and coaches a team of local and global experts, fostering a culture of accountability, growth, and excellence.
Key Responsibilities
Challenge and enhance IT risk management execution implementing corrective actions where necessary.
Continuously refine and optimize methodologies and procedures to ensure robust IT risk oversight and to support business management in effectively controlling IT risks within designated business processes.
Foster strong relationships with strategic clients, serving as a trusted business partner to build professional credibility and mutual trust.
Motivate stakeholders to commit fully to IT Risk objectives and drive exceptional performance in achieving IT risk management goals.
Ensure the IT risk team possesses the necessary expertise, leveraging individual strengths for maximum impact
Support the first-line and business stakeholders through specialist guidance on interpreting and applying IT risk policies and procedures, resolving queries and issues efficiently.
Contribute to the development and enhancement of IT risk policies, procedures, ensuring alignment with established IT risk principles and compliance with internal and external regulatory requirements.
Ensure that IT risks, issues, dependencies, and constraints are proactively managed at the project level. Where IT risks or issues threaten project delivery, develop and agree on recovery plans to mitigate impacts and maintain strategic alignment.
Qualifications & Experience
A Master degree in IT or equivalent through experience
Deep understanding of IT infrastructure, cybersecurity, and emerging technologies and risks
Professional certifications such as CISM, CRISC, CISSP, or equivalent are highly desirable.
Strong leadership and people management skills, with experience coaching and developing teams.
Strong understating of ING’s IT Risk Control framework combined with a pragmatic risk-based approach with regards to its day-to-day use.
Ability to influence, work effectively, across all levels of the organization including Exco level
Very good knowledge of English, Dutch and/or French
Very good problem solving, communication and self-organization skills
Have a dynamic personality, take initiative and be flexible
Willing to work in a constantly changing environment
Be a team player
Skills Required
- Master’s degree in IT or equivalent experience
- Deep understanding of IT infrastructure, cybersecurity, and emerging technology risks
- Professional certification such as CISM, CRISC, CISSP, or equivalent
- Strong leadership and people management experience, including coaching and team development
- Strong understanding of ING’s IT Risk Control framework and pragmatic risk-based application
- Ability to influence stakeholders across all organizational levels, including executive leadership
- Very good knowledge of English and Dutch and/or French
- Strong problem-solving, communication, and self-organization skills
- Dynamic, proactive, flexible, and collaborative approach
- Willingness to work in a constantly changing environment
What We Do
ING is a pioneer in digital banking and on the forefront as one of the most innovative banks in the world. As ING, we have a clear purpose that represents our conviction of people’s potential. We don’t judge, coach, or tell people how to live their lives. However big or small, modest or grand, we empower people and businesses to realise their vision for a better future. We made the promise to make banking frictionless, removing barriers to progress, and make people confident in their financial decisions. As a global bank we have a huge opportunity – and responsibility – to make an impact for the better. We can play a role by financing change, sharing knowledge, and innovating. Being sustainable is in all the choices we make—as a lender, as a partner and through the services we offer our customers









