US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs

   

Tech Risk and Controls Lead

The role involves managing security risk and controls, participating in security-related projects, promoting risk reduction, investigating potential changes to risk management tools and processes, managing backlog requests for reporting enhancements, and coordinating with other teams.

The role requires a deep understanding of technology and cyber domains, and the ability to work with data from disparate sources to build a cohesive view on risk.

Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.

Job responsibilities


* Document and monitor operational risk and control environment to identify existing and emerging operational risk and issues


* Evaluate and document issues related to changes in the risk environment and operational risk priorities


* Assess risks and drive actions for remediation activities


* Identify and aggregate thematic risks and trends


* Communicate heightened risk that is relevant to stakeholders and customers to ensure transparency and appropriate prioritization for remediation


* Identify technology risk impacting the business that is quantified, communicated, and managed, including recommendations for resolution, and identifying the root cause/key themes


* Partner with Third Party Oversight teams to ensure effective vendor risk management, with a focus on Cloud computing / emerging technologies


* Maintain an understanding of application team strategies, product roadmaps and key investment programs


* Apply working experience in multiple security or risk management domains (e.g., application security, vulnerability management, data protection, encryption, logging and monitoring, network security)


* Assess technology risks and businesses and products evolve to effectively identify and suggest remediation plans.

Required qualifications, capabilities and skills


* Formal training or certification on Operational Risk including Tech and 5+ years of Experience in banking and financial services


* Experience in Operational Risk including Tech/Cyber Risk


* Experience in Technology and Cyber domains e.g.

Software Development, Identity and Access Management, Vulnerability Management, etc.


* Ability to work with data from disparate sources to build a cohesive view on risk


* Strong written and verbal communication skills with ability to effectively communicate and present security risk concepts with business and technology partners.

Preferred qualifications, capabilities and skills


* Experience working in regulated industries, in particular leveraging technology standards, frameworks, compliance, and industry recognized best practice/standards (e.g., ITIL, NIST, ISO, PCI, SOC)


* Collaboration with internal and external technology audits (3rd Line of Defense), CCOR Operational Risk Management deep dives and testing (2nd Line of Defense), and the...




Share Job