Job responsibilities
- Assist in monitoring technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices
- Collaborate with stakeholders to develop and implement risk mitigation strategies, controls, and action plans for technology-aligned processes
- Monitor and evaluate the effectiveness of implemented controls, contribute to the recommendations for improvements and addressing gaps in risk management
- Communicate risk-related findings and updates to relevant stakeholders, ensuring alignment with organizational objectives and risk appetite
Required qualifications, capabilities, and skills
- Experience or equivalent expertise in technology risk management, information security, or a related field
- Expertise in information security domains, including access controls, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, third party risk management, data protection and infrastructure & cloud security.
- Proficient in risk identification, assessment, and control evaluation, with a strong understanding of, and exposure to, risk management frameworks, regulations, and industry best practices (SOC1, SOC2, ISO27001, NIST Cybersecurity Framework, DORA, etc.)
- Demonstrated ability to analyze complex issues, and develop and execute risk mitigation strategies that are tailored to the unique needs of a specific business unit, while maintaining alignment with broader organisational goals
- Strong communication skills, with the ability to engage and influence stakeholders both within the business unit and across the larger organization.
- Demonstrated ability to thrive in a dynamic, fast-paced environment, with a track record of implementing innovative solutions to complex risk challenges.
Preferred qualifications, capabilities, and skills
- Entry level security certifications such as Security+, GSEC, SSCP, or other industry-recognized security certifications such as CISSP/CISM
- Experience with public Cloud Infrastructure security (Azure, AWS) would be a plus