Deputy Director, Technology Governance, Risk & Compliance

Ethniki Asfalistiki
Πλήρης απασχόληση Μακρινός
Εργασία εξ αποστάσεως
Ethniki Asfalistiki has been a leading company in the Greek insurance market for 135 years. Since its establishment in 1891, the company has been offering simple, innovative, and reliable solutions that protect what matters most to its policyholders, enabling them to face each day with confidence and peace of mind.

In November 2025, Ethniki Asfalistiki entered a significant new chapter in its history by becoming part of the Piraeus Group, one of the largest and most dynamic financial organizations in Greece.

Today, Ethniki Asfalistiki employs more than 700 people, has a flexible and extensive network of Certified Insurance Intermediaries, and is trusted and preferred by 1.9 million policyholders. Guided by values such as integrity and reliability, the company places people at the heart of its business, making insurance clear and accessible and removing complexity to help customers feel informed and in control.

Ethniki Asfalistiki’s vision is to remain a leading insurer, always standing by its customers, redefining insurance through innovation, empathy, and simplicity, while building a sustainable future.

About The Role

Ethniki Asfalistiki is looking for a Deputy Director, Technology Governance, Risk & Compliance to lead a newly consolidated unit reporting directly to the Chief Technology Officer. The Head of IT GRC sits at the centre of technology risk and compliance: the single owner of the consolidated ICT risk and remediation register, of the ICT internal control framework and its evidence, and of the reporting of the technology risk and compliance posture to the CTO, the Executive Committee, Board committees and the supervisor. The CISO remains accountable for security, resilience and the operational DORA obligations, and the Chief Data & AI Officer for EU AI Act conformity; the Head of IT GRC makes sure that every obligation, finding and action has an owner, a deadline and the urgency it deserves.

Working as the first-line counterpart to Risk Management, Compliance, the DPO, Internal Audit and external auditors, and as the coordinator of supervisory reviews and inspections, the role turns findings and obligations into remediation programmes delivered together with IT Operations & Service Management and Change Delivery.

Key Responsibilities

  • Establish and lead the IT GRC unit, defining its mandate, its operating rhythm — including the monthly technology risk and remediation review chaired by the CTO — and its interfaces with the Technology directorates, the CISO, Data & AI and the second and third lines of defence.
  • Own the technology obligation map — DORA, EIOPA ICT guidelines, EU AI Act, GDPR, Solvency II ICT requirements, ISO 20000/27001 — assigning each obligation to its accountable owner and keeping the map current as regulation evolves.
  • Own the consolidated ICT risk and remediation register: the single view of the risk surface across RCSA and key risk indicators, internal audit, external audit and Bank of Greece findings, DORA and EU AI Act action plans, resilience-test and third-party findings.
  • Drive remediation with urgency: action plans with named owners and deadlines, escalation of slippage to the CTO, and remediation projects planned through the IT Portfolio Board and delivered with IT Operations & Service Management and Change Delivery.
  • Maintain the ICT internal control framework and the IT policy set; coordinate the annual first-line control-testing plan (including the CISO's yearly user-access recertification campaign), RCSA and key risk indicators, and the production of evidence for audits and supervisory reviews.
  • Report the technology risk and compliance posture through decision-ready dashboards and packs to the CTO, the Executive Committee, the Risk and Audit Committees and, through the CTO, the Board; coordinate supervisory reviews and inspections and the follow-up of their findings.
  • Act as first-line counterpart to Risk Management, Compliance, the DPO and Internal Audit, and support external auditors on IT general controls.
  • Track DORA compliance across its owners — the ICT risk-management framework, the management and classification of all major ICT incidents and their reporting to the Bank of Greece, business continuity, resilience testing and third-party risk, owned by the CISO with IT Operations & Service Management — ensuring that findings and actions land in the register and that evidence is complete; compile the Register of Information from the inputs of the CISO, Procurement and the contract owners.
  • Track EU AI Act compliance, owned end to end by the Chief Data & AI Officer — inventory, classification, conformity, post-market monitoring — as a member of the Model Risk Committee, ensuring that AI risks and actions are part of the consolidated register.
  • Embed compliance-by-design in Change and Run processes — stage gates, change control and vendor onboarding — so that regulatory requirements are addressed up front.
  • Lead and develop a small team of GRC specialists, building capability and a culture of accountability and transparency.

What You Bring

  • Bachelor's degree in Computer Science, Engineering, Economics, Law or a related field.
  • Master's degree in Information Systems, Information Security, Risk Management or a related discipline will be considered an asset.
  • At least 5 years of experience in IT governance, IT risk, IT audit or technology compliance, including 3+ years in a managerial role.
  • Working knowledge of DORA, EIOPA ICT guidelines, the EU AI Act and GDPR, and of frameworks such as ISO 27001, ISO 20000, COBIT and NIST.
  • Proven experience managing audit and supervisory engagements and driving remediation programmes to closure across teams that do not report to you.
  • Structured, evidence-driven and pragmatic, with excellent analytical and report-writing skills.
  • Ability to influence senior stakeholders without direct authority, to create urgency and to communicate risk clearly to executive and Board-level audiences.
  • Integrity, discretion and independence of judgement.
  • Fluency in Greek and English, both written and spoken.

Will be considered a plus

  • Relevant certifications (CISA, CRISC, CGEIT, CISM, ISO 27001 Lead Implementer / Auditor).
  • Experience within highly regulated industries such as insurance, banking, or financial services; Big-4 technology-risk experience.
  • Experience with GRC tooling (e.g. ServiceNow IRM) and with risk registers and dashboards.

What We Offer

The company invests in long-term cooperation and provides a modern and stable work environment, with a hybrid work model. We offer a competitive remuneration package and excellent career prospects, coupled with continuous training and development.

Applications

All applications will be treated with strict confidentiality and successful candidates will be contacted.

At Ethniki Asfalistiki, we believe in creating an inclusive workplace that values diversity and celebrates the unique contributions of each individual.

We are an equal opportunity employer, and we recognize that a diverse workforce is essential for our success. By bringing together people from different backgrounds and experiences, we can promote a more innovative, creative, and productive work environment.

We are committed to fostering a culture of belonging where everyone feels respected, valued, and empowered to contribute their best.

Πώς να κάνετε αίτηση

Μην χάσετε τις νέες ευκαιρίες εργασίας

Ακολουθήστε το MyCarriera.gr στο Viber για νέες αγγελίες με μισθό κάθε μέρα.