DescriptionJoin our team to play a pivotal role in mitigating tech risks and upholding operational excellence driving innovation in risk management.
As a Tech Risk & Controls Lead in Enterprise Technology you will be responsible for identifying and mitigating compliance and operational risks in line with the firms standards. You will also provide subject matter expertise and technical guidance to technology-aligned process owners ensuring that implemented controls are operating effectively and in compliance with regulatory legal and industry standards. By partnering with various stakeholders including Product Owners Business Control Managers and Regulators you will contribute to the reporting of a comprehensive view of technology risk posture and its impact on the business. Your advanced knowledge of risk management principles practices and theories will enable you to drive innovative solutions and effectively manage a diverse team in a dynamic and evolving risk landscape.
Job responsibilities
- Ensure accountability for risk & control governance in Product Lines to better manage defend & drive the product lifecycle
- Ensure product line risks and control gaps are acknowledged registered and correctly treated (risk assess and approve findings/treatments breaks uplift programs CORE items)
- Provide oversight of process management risk assessment structure for Technology Product Line
- Owns effective product line interactions with CTC Assurance Audit Compliance and CCOR
- Owns proactive product line control reviews & to develop/enhance increased risk telemetry for all risk management personas
- Provides line of sight of emerging technologies and view into how fit into current risk posture and control framework of CTO
- Coordinate and monitor issue management to ensure timely and sustainable remediation and provide thematic analysis to identify trends
- Proactively monitoring CORE Key Risk Indicators to identify non-compliance and assist in remediation with compensating controls to address security risk and control gaps
- Collaborate with team members and stakeholders on firm-mandated product line horizontal and regional audits
Required qualifications capabilities and skills
- 5 years of experience or equivalent expertise in technology risk management information security or related field emphasizing risk identification assessment and mitigation
- Strong written and verbal communication skills with ability to effectively communicate and present security risk concepts with business and technology partners
- Strong personal leadership collaboration bias for action and experience working within fast paced complex and high performing Digital/Agile/Scaled Agile teams
- Strong analytical skills including solving and communicating complex problems data analytics measurement and reporting needed to drive continuous improvement
- Experience working in regulated industries in particular leveraging technology standards frameworks compliance and industry recognized best practice / standards (e.g. NIST ISO PCI SOC)
- Familiarity with risk management frameworks industry standards and financial industry regulatory requirements
- Proficient knowledge and expertise in data security risk assessment & reporting control evaluation design and governance with a proven record of implementing effective risk mitigation strategies
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives
Preferred qualifications capabilities and skills
- CISM CRISC CISSP or similar industry-recognized risk and risk certifications are preferred
Required Experience:
Manager