Job responsibilities
- Facilitate the execution of assessments to ensure they align with organizational goals, risk tolerance, and regulatory standards.
- Govern and track issues from assessments, ensuring timely resolution and closure of control deficiencies.
- Monitor technology risks to ensure adherence to company standards, regulatory mandates, and industry best practices.
- Collaborate with cross-functional teams to implement effective controls.
- Analyze complex scenarios, advise on risk management strategies, and support risk mitigation efforts.
- Develop threat modeling processes to identify and prioritize potential threats to the organization's technology infrastructure.
- Work with stakeholders to integrate threat modeling into the risk management framework, ensuring alignment with governance and compliance goals.
Required qualifications, capabilities, and skills
- Formal training or certification on Tech Risk & Controls concepts and 2+ years applied experience
- Experience in identifying, assessing, and evaluating risk controls, with a solid grasp of industry standards.
- Proven capability to analyze intricate issues, devise and execute risk mitigation strategies, and communicate efficiently with senior stakeholders.
- Well-versed in risk management frameworks, regulations, and industry best practices.
- Experienced in threat modeling, with the ability to identify and evaluate potential threats and incorporate threat modeling into risk management processes.
- Familiar with threat modeling tools and methodologies, such as STRIDE, DREAD, or PASTA, is a plus.
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred