Job responsibilities
- Ensure effective identification, quantification, communication, and management of technology risk, focusing on root cause analysis and resolution recommendations.
- Develop and maintain robust relationships, becoming a trusted partner with LOB technologists, assessments teams, and data officers to facilitate cross-functional collaboration and progress toward shared goals.
- Execute reporting and governance of controls, policies, issue management, and measurements, offering senior management insights into control effectiveness and inform governance work.
- Proactively monitor and evaluate control effectiveness, identify gaps, and recommend enhancements to strengthen risk posture and regulatory compliance.
- Lead data privacy strategy initiatives, including AIML, for Global Technology, including evaluation of privacy projects and data protection impact through Privacy by Design and Default assessments.
- Develop and maintain Data Privacy policies and technology data governance standards.
- Enhance guidance for technology teams based on changes in laws and regulations.
- Prepare and communicate status, issues, and key decisions to stakeholders and executives.
Required qualifications, capabilities, and skills
- Advanced applied experience or equivalent expertise in technology risk management, information security, or related field, emphasizing risk identification, assessment, and mitigation
- Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements
- Proficient knowledge and expertise in data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives
- Excellent verbal and written communication and presentation skills.
- Proficient knowledge and expertise in data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies.
Preferred qualifications, capabilities, and skills
- Certified Information Privacy Professional (CIPP) or Certified Information Privacy Technologist (CIPT) certification preferred.
- Related experience in Financial Services or Regulatory experience preferred
- Prior experience protecting Personal Information and Confidential Data in a global organization.
- Understanding of global privacy laws, regulations, and compliance requirements (GDPR, the EU AI Act etc.).