Sr. IT Risk ManagerThe Sr. IT Risk Manager will play a key role in the ongoing technology transformation journey of the Bank.
This position will be responsible for overall assurance of the compliance of enterprise platforms with established security, risk and governance requirements of the Bank. Streamlining existing processes and maximizing automation is a major responsibility for this role, and it includes developing and operationalization programmatic guardrails in collaboration with owners and architects of established and emerging enterprise platforms.In this role you will interact directly with a cross-functional team of multiple stakeholders across the bank including leadership teams of enterprise Cloud, API and DevSecOps platforms as well as overall enterprise platform governance leadership.Once here you will:Assess existing control frameworks and implementations within enterprise platforms against the security, risk and compliance requirements of the bankDesign Controls framework and Controls library for Cloud, API and DevSecOps platforms meeting Industry standards and best practicesProvide subject matter expertise to strength controls design and implementation effectivenessCommunicate platform control gaps and remediation plan to internal and external stakeholdersImplement processes for continuous compliance of enterprise technology platforms against control framework across people, process and technologyPartner with technical leadership and architects of enterprise platforms to continuously improve and maximize automation of the controls within the frameworkPartner with product managers of enterprise platforms to ensure control gap remediation are incorporated into platform delivery roadmaps and prioritizedEngage with teams leveraging the platforms to ensure understanding of the risk mitigation provided by controls within the framework and what additionally is required by adopting teamsDevelop metrics and reporting to provide visibility to leadership and stakeholders on maturity of adoption of the controls framework across enterprise platformsManage stakeholders and their expectationsEffectively communicate ideas and information with peers, management, and customersServe as a Change Agent and contribute to a culture of continuous complianceLiaison with 1st, 2nd and 3rd Risk LODLiaison with Modern Platform owners and Application owners to ensure complianceWhat you'll bring:10+ years of overall industry experience, specifically around cybersecurity, IT risk management, IT audit or compliance4+ years working experience with cloud platforms (AWS) and DevOpsPassion for achieving excellence in delivery, solving complex problems, and taking ownershipExpertise in IT operations and security control domains (including application security, change management, disaster recovery, data center operations, information security and networking)Knowledge of, and experience with, financial services regulatory frameworks such as PCI, SOX, FFIEC, CIS20, GDPR, GLBA, CCPAAt least one of the following security certifications: CISSP, CISM, PCI-QSA certifications, or Certified ISO27001 Lead ImplementerExperience with enterprise IT management frameworks (e.g. COBIT, ITIL)Excellent technical, analytical, problem solving, multitasking, and time management skills with consistent attention to detailAbility to effectively learn, communicate and use new processes, concepts, tools, and methodology to support the needs of the businessStrong interpersonal skills, with the ability to work across functional lines and at many levelsExcellent presentation (written and verbal) communication skills.
Ability to effectively communicate technical issues and solutions to all levels of businessAbility to effectively share technical information and train and mentor less experienced or knowledgeable team members