As a Tech Risk & Controls Senior Associate in Corporate Sector, you will be a part of a team that drives risk reduction for the group with activities such as controls monitoring and testing, and risk analytics. Working closely with the technology risk teams and cross-functional partners, you contribute your skills and insights to the continuous improvement of risk management methods. As a valued member of the team, you will have the opportunity to learn and grow in a dynamic and fast-paced environment, making a tangible impact on technology risk and controls at the firm.
Job responsibilities:
- Conduct Technology Controls testing for the group, with an opportunity to show impact and efficiency using automation.
- Assist in monitoring technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices
- Collaborate with stakeholders to develop and implement risk mitigation strategies, controls, and action plans for technology-aligned processes
- Monitor and evaluate the effectiveness of implemented controls, contribute to the recommendations for improvements and addressing gaps in risk management
- Communicate risk-related findings and updates to relevant stakeholders, ensuring alignment with organizational objectives and risk appetite
Required qualifications, capabilities, and skills:
- 3+ years of experience or equivalent expertise in technology risk management, information security, or a related field
- Proficient in risk identification, assessment, and control evaluation, with a strong understanding of industry standards
- Demonstrated ability to analyze complex issues, develop risk mitigation strategies, and communicate effectively with stakeholders
- Knowledge of risk management frameworks, regulations, and industry best practices
Preferred qualifications, capabilities, and skills:
- Strong experience in technology risk and controls
- Experience in technology controls testing or automation thereof is a plus
- Exposure to python a plus
- Ability to articulate risks visually and verbally to various audience
- CISM, CRISC, CISSP, or other industry-recognized risk certifications is preferable