Manager, IT Risk
Lodz, PL
About The Role
The Manager, IT Risk will play a key role in developing, leading, and overseeing initiatives to identify, assess, manage, and report IT and cybersecurity risks across Amcor. Working closely with business and technology stakeholders, the role will support risk-based decision-making and contribute to the continued enhancement of Amcor’s cybersecurity maturity and resilience in an evolving threat landscape.
The role is responsible for overseeing the effective management of risks to the organization’s information assets, facilitating internal and external risk workshops, coordinating risk assessments, and maintaining strong collaboration across relevant teams. The role will also lead the preparation of risk committee presentations and management reporting, support compliance with applicable standards and requirements, and drive the ongoing monitoring and management of IT and cybersecurity risks.
Key Job Accountabilities
Prepare, coordinate, and lead periodic IT and cybersecurity risk committee meetings, including agenda setting, risk prioritization, stakeholder alignment, presentation of key risks, and follow-up of agreed decisions and actions. Develop and report IT and cybersecurity risk metrics, key risk indicators, trends, and risk statistics to the IT Leadership Team, Audit Committee, and other relevant governance forums to support effective oversight and risk-based decision-making. Apply and continuously improve qualitative risk assessment and scoring methodologies to support strategic and tactical risk-based decision-making. Lead and oversee risk assessments relating to existing and emerging technologies, services, projects, third parties, and significant organizational changes. Provide risk oversight, independent advice, and constructive challenge to IT, cybersecurity, business teams, and risk owners. Drive improvements to the organization’s risk posture by supporting the development of appropriate risk treatment plans, monitoring remediation activities, and assessing residual risk. Lead the continuous improvement of the IT and cybersecurity risk management framework, including risk identification, assessment, treatment, monitoring, escalation, and reporting. Establish and maintain effective relationships and communication channels with stakeholders involved in managing IT and cybersecurity risks across the organization.
Qualifications/Requirements
- Minimum of 12 years of total professional experience, including at least 7 years of relevant experience in IT and cybersecurity risk management, technology risk, IT audit and assurance, cybersecurity governance, governance, risk and compliance (GRC), cyber operations, or related consulting and advisory roles.
- Demonstrated experience in leading or coordinating enterprise-wide IT and cybersecurity risk management activities, including risk assessments, risk treatment oversight, governance committees, and senior management reporting.
- Bachelor’s degree in Information Technology, Audit or a related field Strong knowledge of cybersecurity and technology risk concepts, governance practices, risk assessment methodologies, and applicable regulatory, assurance, and industry requirements.
- Proven experience working in a complex global and matrixed organization and engaging effectively with senior IT, cybersecurity, business, audit, and risk stakeholders.
- Relevant professional certifications such as CRISC, CISA or ISO27001 LA is preferred.
- Strong knowledge of IT and cybersecurity risk management principles, methodologies, governance frameworks, and relevant regulatory requirements.
- Ability to identify, assess, prioritize, and clearly communicate the business impact of IT and cybersecurity risks.
- Strong analytical judgment and the ability to balance business objectives, security requirements, and risk exposure.
- Excellent communication, presentation, and facilitation skills, including the ability to communicate complex risk matters to senior leadership and governance committees.
- Strong stakeholder management and influencing skills, with the ability to drive ownership and accountability without direct authority.