CEE Technology Risk & Assurance Officer
Job description
We are Flutter Central & Eastern Europe (CEE). As a proud member of the Flutter family - a global leader in sports betting and iGaming - we are building one of the Group`s most dynamic tech and product hubs in Central and Eastern Europe. We aren`t just here to participate; we`re here to change the game. By uniting local powerhouses like MaxBet, Adjarabet.com, and Adjarabet.am, we combine deep regional expertise with the scale and strength of Flutter`s global platforms. We are setting a new standard for entertainment, responsibility, and innovation — powered by real customer signals that shape everything we build. READY TO CHANGE THE GAME? Join the Flutter Central & Eastern Europe team. This is where bold, ambitious minds build scalable platforms, drive innovation, and shape the future of iGaming in the region. The CEE Technology Risk & Assurance Officer reports directly to the Technology GRC Director and is responsible for implementing and maintaining the Technology Governance, Risk, and Compliance (GRC) framework across Flutter CEE brands and entities, including Adjarabet and MaxBet. The role provides independent second-line oversight by performing technology and cybersecurity risk assessments, control assurance activities, governance reviews, and regulatory compliance assessments. The position evaluates the effectiveness of technology controls, supports alignment with Group standards and regulatory requirements, and provides risk-based recommendations to first-line technology teams. The role contributes to the continuous improvement of GRC processes, governance, and assurance practices, helping strengthen the organization's technology risk management, compliance, and operational resilience. What You'll Do: Provide oversight of technology and cyber risk management activities, ensuring effective implementation and monitoring of technology and cyber controls and processes. Monitor the adequacy of risk management and compliance practices through periodic assessments, control testing in line with assurance plans. Support first-line technology and cyber teams identifying, assessing, and managing technology and cyber risks, ensuring adherence to regulatory requirements and internal policies. Review technology policies, standards, and procedures. Ensure first-line activities are aligned with group minimum standards and best practices. Conduct the organization's assessments in compliance with applicable technology regulations and industry standards (e.g., NIST CSF 2.0, ISO/IEC 27001, COBIT, ITIL, NIS2, PCI DSS) by collecting evidence, performing evaluations, and reporting findings to the Technology GRC Director Report to Technology GRC Director on the security and technology risk posture, highlighting key risks, trends, and mitigation strategies. Conduct data maturity assessments to support overall data management practices. What We're Looking For: Minimum of 4 years of professional experience in technology governance, risk management, and compliance. Strong background in Technology and Cyber risk management practices, cybersecurity control assurance. Deep understanding of technology risk management frameworks and industry standards and regulations, including but not limited to NIST CSF 2.0, ISO 27001, ISO 31000, NIS2, GDPR, PCI DSS, COBIT. Experience conducting technology and information security assessments independently, including evaluating controls, identifying risks and control deficiencies, and preparing high-quality assessment reports and recommendations for stakeholders and management. Experience developing and/or reviewing technology and information security related documentation (policies, procedures, guidelines, etc.) Professional certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001/27002 Lead Auditor/Implementer are highly preferred. Strong strategic thinking with the ability to influence and collaborate with senior leadership and cross-functional teams Excellent written and verbal communication skills, with the ability to convey complex technical concepts to non-technical stakeholders. Strong analytical and problem-solving skills, with the ability to assess complex technology risks and provide strategic solution. Experience preparing executive-level presentations that communicate technology, information security, governance, and risk matters in a clear, concise, and visually effective manner. Why choose us At Flutter CEE, people have access to vast opportunities for career growth and self-development. Our employee benefits package goes far beyond offering the minimum: We support our people in becoming their best version at work and beyond - and our benefits reflect that commitment. These are some of the benefits included in our employee package: Generous annual leave Hybrid work Individual health insurance Paid sick leave Paid maternity & paternity leave Family reward Performance & referral bonuses