DescriptionJoin our team to play a pivotal role in mitigating tech risks and upholding operational excellence driving innovation in risk management.
As a Tech Risk & Controls Lead in Cybersecurity & Tech Controls you will be responsible for identifying and mitigating compliance and operational risks in line with the firms standards. You will also provide subject matter expertise and technical guidance to technology-aligned process owners ensuring that implemented controls are operating effectively and in compliance with regulatory legal and industry standards. By partnering with various stakeholders including Product Owners Business Control Managers and Regulators you will contribute to the reporting of a comprehensive view of technology risk posture and its impact on the business. Your advanced knowledge of risk management principles practices and theories will enable you to drive innovative solutions and effectively manage a diverse team in a dynamic and evolving risk landscape.
Job responsibilities
- Manage horizontal execution of outsourcing controls.
- Ensure accurate monitoring transparent reporting and issue/risk escalation with leaders and partners
- Ensure compliance with firm wide outsourcing policy and/or standards
- Identify escalate and implement solutions for identified issues and risks along business stakeholder decisions.
- Demonstrate superior judgment to mitigate risk impacts to the operational processes: Reputation Regulatory Legal Operational and Financial.
- Collaborate with stakeholders in a consulting role to add value and address unresolved critical problems and exposures
- Develop and maintain key contacts and working relationships with various areas within Enterprise Technology Controls peer groups and CTPO
- Ensure timely escalation of key risks and issues to management and interested stakeholders
- Represent the Third Party and IAS Oversight team in various governance legal and controls forums
Required qualifications capabilities and skills
- 5 years of experience or equivalent expertise in technology risk management information security or related field emphasizing risk identification assessment and mitigation
- Familiarity with risk management frameworks industry standards and financial industry regulatory requirements
- Proficient knowledge and expertise in data security risk assessment & reporting control evaluation design and governance with a proven record of implementing effective risk mitigation strategies
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives
- Familiarity with outsourcing risk and processes implementing policies/standards and risk management
- Ability to coordinate engagement with key stakeholders and proficiency in cross-functional frameworks
- Strong understanding of controls framework and compliance standards
- Adaptability to thrive in a fast-paced collaborative team-oriented cross-functional environment
- Self-motivated and confident decision-maker with the ability to lead challenge and influence change where necessary
- Synthesizes data quickly and communicates analysis succinctly and professionally
Preferred qualifications capabilities and skills
- CISM CRISC CISSP or similar industry-recognized risk and risk certifications are preferred
- Ability to maintain professional documentation for internal and external reporting purposes
- Demonstrated knowledge/background in internal control philosophies