To support the 2nd line of defence (2LoD) team in fulfilling its oversight role by:
- Ensuring robust risk monitoring by producing accurate timely and actionable data about the Groups risk profile to its committees supported by minute taking and action tracking.
- Working with Salesforce to continue to enhance the GRC system (Riskonnect).
- Training the business in the use of Riskonnect and ensuring that this supports the requirements of the Enterprise Risk Management Framework and the Operational Risk Management Policy as a minimum.
- Ensuring that the Bank has the risk related data available to support its regulatory and governance related reporting for example ICAAP REP018 etc.
Role Responsibilities:
Business Impact
- Identify and implement ways in which the team and the Group can use technology specifically the Riskonnect tool to improve the collection collation and presentation of data and how this can be used across multiple risk types / business areas.
- Lead Riskonnect enhancements this includes introducing the policies procurement compliance and operational resilience modules. Ensuring that that Riskonnect remains fit for purpose as the Group grows.
- Performing UAT testing as required following enhancements to Riskonnect.
- Incident Management: Provide oversight and challenge of identified risk incidents / data breaches / security incidents and identification of any themes and trends emerging from data with escalation as appropriate. Ensure that appropriate remediation is undertaken by the 1LoD along with root cause analysis and action tracking.
- Responsible for performing thematic reviews.
- Driving data quality by ensuring the requirements of the Incident Management Standard are understood by the business via review and challenge of the information being added to the system. Training provided to areas where the requirements of the Standard are not met.
- Collate RCSA risks controls and processes in a central library (Riskonnect) to provide a consolidated view of all risks and controls across the business.
- Support the development of control assurance and testing within Riskonnect. Support the wider team in performing control testing from a 2LoD perspective.
- Provide monthly (or as required) MI for reporting purposes. Ensure Board metrics are monitored with any breach escalated in a timely manner.
- Ensure that the business has high quality data to support regulatory submissions for both the Group and Bank as required.
- Training & Development: Provide 1LoD risk champions and the business with relevant training on Riskonnect to complete incidents RCSAs etc. in line with the requirements set out in the Group Enterprise Risk Management Framework and Operational Risk Management Policy.
- Support VPs within the team to develop Group policies and procedures.
- Lead on the initial process mapping exercise within Riskonnect creating various linkages between risks controls assurance findings etc.
- Support the development of ICAAP scenarios and correlations as required.
- Conduct reviews of information held within Riskonnect to ensure the quality and consistency of data and that the risk control and process library is maintained.
- Internal & External Audit: Log and review all open audit actions ensuring a timely closure escalate as required. When audit actions are presented to closure business should evidence that action has been closed. This to be independently verified.
- Maintain a central policy library ensuring annual reviews are completed in a timely manner and appropriate governance is adhered to for approval.
- Support the embedding of an effective risk culture encourage risk awareness across the Bank and its activities.
- Responsible for preparing the minutes of the Operational Risk Committee (ORC)
- Provide support/ cover for BCP / DR / Crisis Communications as and when required.
Stakeholder Management
- Working in partnership with the business to build effective business relationships becoming the first point of call (from a 2LoD perspective).
Teamwork
- Work collaboratively across the team to identify knowledge gaps encourage open dialogue offer support to one another with a view of working effectively to resolve issues in a proactive manner.
Qualifications :
Experience:
- Knowledge of the UK financial services and regulatory framework
- Knowledge and experience of managing operational risk in either a 1LoD or 2LoD position is desriable
- Demonstrable experience of using analysis tools such as PowerBI or Tableau.
- Experience of using a GRC system.
Skills:
- Advanced knowledge of Excel
- A can do and positive learning attitude
- Solutions driven mind-set
- Ability to engage and influence stakeholders
Additional Information :
- Hybrid working
- Contributory personal pension plan: - Minimum: Employee 2% and Employer 7%. Employer matches contributions in 1% increments to a maximum of: Employee 5% and Employer 10%
- Life Assurance 4 times annual salary
- Group Income Protection
- Private Medical Insurance this may include cover for partner and or children at company cost. Cover includes Optical Dental and Audiology
- Discretionary Bonus
- Competitive Annual Leave
- 2 Volunteering Days
- Benefit Hub
Remote Work :
No
Employment Type :
Full-time