Governance, Risk and Control Assessments Support oversight of the following risk and control capabilities: IT and security policies, standards, and procedures management Threat identification and risk assessment Metrics and reporting Testing and external assurance oversight Remediation management Support first and second line of defense risk functions and relevant governance committees and other stakeholders as appropriate to develop the technology risk management agenda. Support the design and implementation of best practices and technology risk management frameworks across the Information Technology Group (ITG). Help establish and contribute to the application of Technology risk policies, and governance processes to create lasting solutions for minimizing losses from failed internal processes, inadequate controls, and emerging risks. Assess risks and drive actions to address the root causes that persistently lead to operational/technology risks losses by challenging both historical and proposed practices. Review control exception requests and ensure risk mitigation or acceptance strategies are appropriate with input from your manager. Provide advisory services to technology and business teams on technology risk and control matters pertaining to projects on firm initiatives and projects. Enable the creation of and distribution of actionable risk metrics and reports. Facilitate collaboration for risk analysis, remediation scoping and prioritization, reporting and engagement with stakeholders to enable oversight and effective risk decision making. Support the design and implement the collection and reporting of key risk and control metrics. Support the technology risk governance committee as well as other risk committees in the organization to establish a shared view of risk. Monitor for emerging risks; recommend and implement mitigation strategies to address those risks. Qualifications:
You have a bachelor’s degree in IT, risk and security management, computer science or related field. You have at least 5-7 years of technology risk and security management experience successfully identifying, assessing, and mitigating technology risks in a complex, fast paced environment. You have experience managing technology risk for infrastructure environments at an enterprise scale (e.g., Information Security, Cyber Security, Security Operations, Governance, etc.). You have experience supporting technology risk programs. You have expertise supporting the management of risks associated with agile software engineering practices, use of public cloud environments and big-data analytics. You’ve worked with internal risk and security teams, auditors, and regulatory examiners. You have superior analytical skills and demonstrated success identifying and solving ambiguous risk related problems. You have proven ability to balance risk mitigation proposals with business objectives and always do what is in the client's best interests. You have experience designing and implementing processes to identify, assess and test key technology and information security controls. You have the ability to operate with a limited level of direct supervision. You can exercise independence of judgement and autonomy.
#J-18808-Ljbffr