Support IT/Cyber Risk Management leadership within Enterprise Resilience Risk team in delivering various oversight and challenge processes
Track and report on status and quality of key Cyber/Technology Risk programs
Develop and utilize effective risk appetite metrics to provide insights into current risk level
Identify issues with policy compliance through analysis and testing of controls
Monitor and assess cyber/technology incidents and perform thematic reviews to investigate issues with value add recommendations
Leverage data driven insight and provide opinions and challenge on key risk indicators
Maintain assigned Domain Risk Profiles to provide a strong fact-based opinion on the Technology Risk profile
Operate a one front door policy by ensuring effective support of business requests and follow through
Provide oversight and challenge on the management of significant cyber incidents
Requirements
7 years in the financial services or other regulated industries
5 years of information technology and operations experience is required; preferably as part of a security operations center or in a dedicated security role
Expert knowledge of Cyber Security concepts, methodology, processes and procedures and controls
Experience with enterprise grade cyber security tools / technologies such as: Endpoint Security, Mobile Device Management (MDM), Email Security, Security Incident and Event Management (SIEM), Web Application Firewall (WAF), Intrusion Detection/Prevention (IDS/IPS), Application Security, Vulnerability Management, Data Loss Prevention (DLP)
5 years’ experience in risk identification, aggregation, analysis, and ranking
Strong metrics and performance management background including data management and analysis
Must have strong knowledge in IT and operational risk management processes, methods, and tools
Good Technical knowledge and experience covering the operating systems (e.g. Unix, Windows, zOS,) and database systems (e.g. Oracle, SQL Server, Sybase, DB2) and middleware (e.g. Tomcat, JBOSS, IIS)
CRISC / CISSP / CISM / CISA or similar certification
Tech Stack
Cyber Security
Oracle
SQL
Unix
Benefits
A comprehensive Total Rewards Program including bonuses and flexible benefits
Competitive compensation
Opportunities to take on progressively greater accountabilities
A world-class training program in financial services