Partner with and support CIO-1 areas in risk management and control implementation. Partner with portfolio owners and audit / regulatory / self-identified issue finding owners to ensure overall risk posture for the area is improved.
Support CIO-1 portfolio(s) in managing audit / regulatory / self-identified findings to ensure appropriate and timely resolution of risks/gaps in controls, and resolve non-compliance with Bank policies, procedures and processes and non-compliance with regulations and laws. Review and revise findings lifecycle event documentation.
Participate in, and coordinate with technology stakeholders, on internal and external audit and regulatory exams
Ensure appropriate senior management awareness/oversight of follow-up on action items to resolve identified technology issues
Support application teams in control implementation requirements
Ensure risk remediation programs are initiated and executed. Design and implement processes to test effectiveness and sustainability of technical controls.
Develop strategies for reducing the risk exposure of CIO-1 portfolio(s), including preparedness of critical applications for audit and regulatory exams and working with application owners to address and prevent common risk issues
Assist application owners and other technology stakeholders in identifying and documenting risks and developing remediation
Tracking and reporting on CIO-1 portfolio(s) key risk indicators (KRI) and control uplift programs. Assisting application owners in developing plans to ensure compliance with KRIs and close control gaps.
Ensure risk remediation programs are initiated and executed in line with the Bank s policies, procedures and standards.
Work with the application teams and control owners to identify and resolve potential issues in control design. Advise on effectiveness metrics, ensure control design includes proper evidence, and provide input to the design and effectiveness of centrally provided tooling.
Your Skills and Experience:
Excellent communication skills, both written and verbal to present ideas and concepts effectively
Extensive experience in technology risk management and risk advisory
Excellent analytical and investigatory skills to identify underlying technology issues
Extensive experience in assessing risk, writing issues, and developing appropriate corrective actions
Demonstrate viable solutions and problem solving
Relevant experience working with auditors, regulators and external auditors on exams, reports and information requests
Prefer experience with designing and testing technology controls and processes