This role will provide control design guidance and conduct independent
control assessments within the Cybersecurity GRC function. The primary focus
will be on the design, implementation, and testing of security controls,
ensuring that technical systems and information assets are appropriately
protected within the Cloud and on-prem environments. The role also emphasizes
comprehensive risk management, including the identification, assessment, and
management of inherent, control, and residual risks. Prior experience within
the Banking or Financial Services sector would be a plus.
Primary
Responsibilities:
- Regulatory and Compliance: Maintain a high degree of
knowledge with current and proposed security changes impacting regulatory,
privacy, and security industry best practice guidance, leveraging
technological solutions to meet enterprise needs.
- Evaluate the extent to which the first line of defense
is aligned with internal and external control standards, as well as
regulatory and audit requirements.
- Communication and Guidance: Provide clear and
consistent communications to lines of business related to cybersecurity
topics. Guide the lines of business through assessments, translating the
technology/security questions so that they can be understood by the
business; then guide them as to how to gather the required information.
- Stay abreast of innovative business and technology
trends in IT security, risk, and controls while advising management of
technology initiatives that support such trends
- Serve as liaison and a point of contact for information
security event reporting
- Create technical assessments and cyber threat profiles
of current events on the basis of inventive collection and research to
enable advanced threat intelligence
- Develop and maintain analytical procedures to meet
changing requirements and enable more strategic detections
- Ensure effective execution of the risk management
framework by managing relationships with key stakeholders within strategic
business groups and technology
- Verify that information security risks are
appropriately mitigated and leading multiple stakeholders in agreement on
appropriate solutions/controls
- Identify applicable regulatory risks from changes or
additions to regulatory guidance and requirements
- Provide expertise for resolution and risk mitigation
- Champion information security within the Bank to
provide security training, increase security awareness and/or discuss
potential security issues and scenarios
- Develop tracking and reporting on Key Risk Indicators
(KRIs) for information security
- Risk Management and Control: Ensure that internal
controls designed to mitigate technology and cyber risks are managed,
mitigated, and commensurate with the business risk.
- Support Information Security oversight and governance
by ensuring the control environment is monitored through relevant
KRI/KPIs.
- Ensure gaps are addressed via remediation plans with
timely resolution which address root cause of control failures.
- Compile and distribute program level reporting to relevant
stakeholders.
- Implementation and Sustainability
- Drive implementation, sustainability, and maturity of
the firm's Information Security control framework.
Qualifications:
- Experience: Minimum of 5-7 years' experience in a
combination of IT Security, Cyber Security, Risk Management, Information
Security, or IT related roles.
- Prior IT audit experience a plus.
- High technical knowledge across Cybersecurity domains
such as Identity Access Management, Data Security, Configuration
Management, Log Generation, Incident Response, security risk
assessment/testing methodologies, Secure Software Development Lifecycle,
evaluating the adequacy and efficiency of internal controls; and
identifying issues resulting from internal and/or external compliance
examinations especially in cloud environments.
- Cloud Security: In-depth knowledge of cloud security practices and
technologies for major providers.
- Documentation: Experience in writing process documentation and
designing/executing control test scripts.
- Regulatory Knowledge: Knowledge of domestic and international banking
regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with
enforcement agencies oversight activities (regulatory examinations,
matters requiring attention (MRAs), consent orders, etc.) within a global
systemically important financial institution's information technology and
information security environments.
- Technical Understanding: Understanding of the regulatory environment and
regulations related to technology risk, and Office of the Comptroller of
the Currency (OCC) and Client Board (FRB) expectations.
- Collaboration: Ability to constructively work both independently and
in collaborative environments involving all levels of management and
employees.
- Multitasking:
Ability to manage multiple priorities concurrently, prioritize, and
efficiently complete responsibilities while maintaining the highest
quality.
- Education & Certifications: Bachelor's degree in
information security or a closely related discipline, or equivalent
related experience
- Professional certifications such as CCAK, CISA, CRISC,
CISM, CGEIT, CSX, or CISSP.