In this role you will be responsible for the execution of local and global Technology Risk Programs across multiple Technology business units and local Technology Risk Programs.
Responsibilities:
- Provide advice, guidance, and IT risk program management
- Assess various technology risks that the business faces in its operations and implement action plans, policy and procedural changes for risk avoidance and mitigation
- Conduct risk readiness reviews over large information technology projects ensuring appropriate systems development lifecycle methodologies are being applied and followed
- Conduct in depth information technology risk assessments including identifying and documenting controls, creating detailed process flows, identifying potential gaps and/or inconsistencies and making sound recommendations for improvement and/or mitigation
- Identify and track appropriate KPIs/KRIs for IT risk monitoring
- Understand and provide consultation on information security standards and industry best practices
- Raising awareness of Risk and Compliance related matters with business partners
- Awareness of third-party vendors engagements to ensure appropriate controls are in place and adhered to
- Providing ad hoc support and consultation to the business partner and internal and external audit teams
- Tracking action steps and ensure that findings are remediated appropriately and in a timely manner
- Bachelor’s degree in Computer Science, Information Technology or equivalent required
- 5+ years’ experience in a Risk, Compliance, Information Security, Controls or Audit Role with focus in Technology Risk Controls management for large-scale, complex IT infrastructures and distributed environments
- An ability to understand complex technical concepts and translate these to business and non-technical language.
- Demonstrated skills and expert understanding of Information Security concepts such as ISO27001 or NIST
- Strong knowledge of Information Technology processes and IT General controls
- Strong analytical skills and problem-solving ability
- Must be able to influence and work with people across a complex organisation