Review and challenge front line issues aligned to Technology and Information Security as part of the Issue Management lifecycle, partnering with Independent Risk Management ORBOs and risk type teams
- Evaluate appropriateness of risk type exposure and risk level of business impact defined by the front line and challenge as needed
- Execute and support Independent Risk Management (IRM) review and challenge for issue intake, submission and/or closure tollgate to validate Root Cause Analysis, Corrective Action, and other key issue details
- Contribute to IRM challenges related to oversight of frontline issue management activities
- Maintain a balance between risk mitigation and operational efficiency
- Evaluate the adequacy and effectiveness of policies, procedures, processes, systems, and internal controls
- Analyze business and system changes to determine impact, assess operational risk issues, and evaluate risk ratings consistent with established policy standards
- Provide technology/information security risk expertise
- Consult with risk type partners to develop corrective action plans and effectively manage change, for IRM-owned issues
- Provide qualitative feedback on issue development and remediation
- Report findings and develop thematic analyses to influence management on the need for processes and controls to mitigate risk
- Assist in maintaining Desktop Procedures and Job Aids for the team's internal processes
- Coordinate production of periodic operational risk performance reports for management, including trend research and recommended strategies
- Collaborate and consult with peers, colleagues, and managers to resolve issues and achieve goals
Required Qualifications, International:
Experience in Operational Risk or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
Desired Qualifications:
- CISA (Certified Information Systems Auditor) certification
- CISM (Certified Information Security Manager) designation
- CISSP (Certified Information Systems Security Professional) certification
- ITIL (Information Technology Infrastructure Library) certification
- CRISC (Certified in Risk and Information Systems Control) designation
Didn’t find the job appropriate? Report this Job