IT GRC Specialist
Join our Security & Governance team as an IT GRC Specialist: shape governance, manage risk, and drive compliant, resilient tech in a dynamic financial environment.
As our IT Governance, Risk & Compliance Specialist, you will play a key role in safeguarding information and ensuring regulatory alignment across our organization. Your mission as part of the Security & Governance organization is to design and operationalize governance frameworks, risk and security controls, and continuity and compliance processes that strengthen our resilience and meet evolving regulatory requirements.
This is a hands-on role combining strategic influence with operational execution. You will collaborate closely with both IT and business stakeholders to embed best practices, translate complex regulations into actionable controls, and drive continuous improvement in governance maturity. Operating in a dynamic, highly regulated financial services environment, you will help balance compliance obligations with practical implementation realities.
Key Responsibilities:
Develop and maintain ICT governance frameworks, policies, and procedures aligned with regulations (DORA, NIS2, GDPR, EU AI Act).
Lead or support governance and compliance initiatives, including security & risk control implementation and process improvements.
Ensure quality of continuity processes and routines.
Facilitate risk management activities and integrate them into daily operations.
Design and test internal controls with process owners.
Coordinate audits and manage remediation follow-up.
Collaborate with IT and business teams to embed GRC and security requirements in projects and systems.
Support third-party risk management and vendor governance.
Prepare reports on risk posture and compliance for senior management and regulators.
Promote risk and control awareness through guidance and training.
Qualifications:
Degree in Information Security, Computer Science, or related field.
5+ years in IT GRC, risk management, or compliance (financial sector preferred).
Strong knowledge of ICT governance and EU regulations (DORA, GDPR, NIS2, EU AI Act).
Experience implementing GRC frameworks and leading cross-functional projects.
Skilled in documentation, communication, and problem-solving.
Professional certifications (CISM, CRISC, ISO 27001) highly desirable.
Behaviors:
Structured, self-driven, and results-oriented.
High integrity and professionalism.
Comfortable with ambiguity and change.
Collaborative and solution-focused.
Prioritizes effectively and respects deadlines.
- Department
- Technology
- Role
- IT GRC Specialist
- Locations
- Rīga
- Remote status
- Hybrid
- Employment type
- Full-time
Rīga
About TF Bank
TF Avarda Bank is a digital bank offering consumer banking services and e-commerce solutions through a proprietary IT platform with a high degree of automation. The platform is designed for scalability and adaptability to different products, countries, currencies and digital banking solutions. TF Avarda Bank prioritizes organic growth under controlled conditions and expansion is taking place in carefully selected segments and markets. Operations are conducted in the Nordics, the Baltics, Poland, Germany, Austria, Spain, Ireland, the Netherlands and Italy through subsidiary, branch, or cross-border banking with the support of the Swedish banking license.
The business is divided into three segments: Credit Cards, Ecommerce Solutions and Consumer Lending. The target group for all services is creditworthy private individuals, and the loan amounts are relatively small with short repayment terms. TF Bank also offers deposit products in several markets.
Already working at TF Bank?
Let’s recruit together and find your next colleague.