DescriptionAs a world leading bank our culture is all about thinking outside the box challenging the status quo and striving to be best-in-class.
As a Compliance Risk Management Lead in our Technology & Cyber CCOR organisation you will have the opportunity to materially contribute and develop the Technology Compliance programme through your deep knowledge and experience of European andGlobal technology and cybersecurity laws rules and will work closely with the wider Technology & Cybersecurity CCOR team who is responsible for the design implementation and oversight of the 2nd Line of Defence independent risk management program for technology and cybersecurity risks. As part of the team you will also be able to broaden this platform to work on legal entity regional and global initiatives in addition to being part of local and firmwide community and Diversity Opportunity and Inclusion initiatives.
Job responsibilities
- Perform regulatory assessments of technology compliance related matters including resiliency outsourcing data loss prevention AI and cloud technology related matters
- Review regulations and impact assessments and work with divisional partners to advise the relevant owners on the development of policies and procedures within the legal entity and across other group legal entities as necessary
- Keep abreast of emerging technologies and related regulatory and legislative changes and provide advice to enable the business to implement applicable changes and operate in a compliant and controlled manner
- Support the review of significant events (including security events) over a defined economic threshold including but not limited to examination of event and resolution back-testing against the firms risk management framework results metrics escalations reporting and scenarios
- Perform ongoing monitoring to ensure appropriate application of policies standards and procedures by employing data analytics on critical systems of records to identify potential issues and areas of risk in a highly efficient manner
- Provide independent assessments of the risks and controls related to the adoption of technologies including Cloud and AI/ML
Participate in the assessment of emerging risks as part of strategic business risk reviews analysis of regulatory and marketdevelopments New Business Initiative Approvals and review of external risk events
Required qualifications capabilities and skills
- Professional experience in risk management compliance or technology-related fields.
- Strong technical experience in technology cybersecurity governance operational risk or technology compliance within the financial services industry or experience in an equivalent role in the technology industry
- Knowledge and experience with Information Security and Risk Management standards and frameworks such as NIST ISO 27001/27002 and modern development practices and supporting toolsets (e.g. Agile DevOps)
- Ability to understand complex technical systems and the business processes they support and synthesize the corresponding risks and controls and recommend adjustments if required
- Understanding of technology risk management and control principles with a proven ability to anticipate and identify risks and effective mitigating actions
Strong organizational project management data analysis and modern data analytic techniques multi-tasking and stakeholder management skills with demonstrated ability to manage expectations and deliver results with a high level of professionalism self-motivation and integrity
Preferred qualifications capabilities and skills
- EMEA technology regulatory knowledge is preferred and an understanding of EU regulation (i.e. DORA EU AI Act NIS etc.)
- Professional IT and Information Security certifications such as CISSP CISA CISM CRISC CGEIT as well as Cloud related certifications (e.g. CCSP AWS Certified Practitioner) are beneficial
- Knowledge of innovative and automation technologies and supporting toolsets such Alteryx UiPath Qlik sense Tableau etc
Experience of implementing innovative methods of overseeing risks using modern data driven and analytical techniques would be a key advantage.
DescriptionAs a world leading bank our culture is all about thinking outside the box challenging the status quo and striving to be best-in-class.As a Compliance Risk Management Lead in our Technology & Cyber CCOR organisation you will have the opportunity to materially contribute and develop the Tec...
DescriptionAs a world leading bank our culture is all about thinking outside the box challenging the status quo and striving to be best-in-class.
As a Compliance Risk Management Lead in our Technology & Cyber CCOR organisation you will have the opportunity to materially contribute and develop the Technology Compliance programme through your deep knowledge and experience of European andGlobal technology and cybersecurity laws rules and will work closely with the wider Technology & Cybersecurity CCOR team who is responsible for the design implementation and oversight of the 2nd Line of Defence independent risk management program for technology and cybersecurity risks. As part of the team you will also be able to broaden this platform to work on legal entity regional and global initiatives in addition to being part of local and firmwide community and Diversity Opportunity and Inclusion initiatives.
Job responsibilities
- Perform regulatory assessments of technology compliance related matters including resiliency outsourcing data loss prevention AI and cloud technology related matters
- Review regulations and impact assessments and work with divisional partners to advise the relevant owners on the development of policies and procedures within the legal entity and across other group legal entities as necessary
- Keep abreast of emerging technologies and related regulatory and legislative changes and provide advice to enable the business to implement applicable changes and operate in a compliant and controlled manner
- Support the review of significant events (including security events) over a defined economic threshold including but not limited to examination of event and resolution back-testing against the firms risk management framework results metrics escalations reporting and scenarios
- Perform ongoing monitoring to ensure appropriate application of policies standards and procedures by employing data analytics on critical systems of records to identify potential issues and areas of risk in a highly efficient manner
- Provide independent assessments of the risks and controls related to the adoption of technologies including Cloud and AI/ML
Participate in the assessment of emerging risks as part of strategic business risk reviews analysis of regulatory and marketdevelopments New Business Initiative Approvals and review of external risk events
Required qualifications capabilities and skills
- Professional experience in risk management compliance or technology-related fields.
- Strong technical experience in technology cybersecurity governance operational risk or technology compliance within the financial services industry or experience in an equivalent role in the technology industry
- Knowledge and experience with Information Security and Risk Management standards and frameworks such as NIST ISO 27001/27002 and modern development practices and supporting toolsets (e.g. Agile DevOps)
- Ability to understand complex technical systems and the business processes they support and synthesize the corresponding risks and controls and recommend adjustments if required
- Understanding of technology risk management and control principles with a proven ability to anticipate and identify risks and effective mitigating actions
Strong organizational project management data analysis and modern data analytic techniques multi-tasking and stakeholder management skills with demonstrated ability to manage expectations and deliver results with a high level of professionalism self-motivation and integrity
Preferred qualifications capabilities and skills
- EMEA technology regulatory knowledge is preferred and an understanding of EU regulation (i.e. DORA EU AI Act NIS etc.)
- Professional IT and Information Security certifications such as CISSP CISA CISM CRISC CGEIT as well as Cloud related certifications (e.g. CCSP AWS Certified Practitioner) are beneficial
- Knowledge of innovative and automation technologies and supporting toolsets such Alteryx UiPath Qlik sense Tableau etc
Experience of implementing innovative methods of overseeing risks using modern data driven and analytical techniques would be a key advantage.
View more
View less