Principal Responsibilities
- Provide clear and concise verbal and written advice to business and technology users on (1) understanding of relevant Engineering Risk policies and standards and (2) principles of security & controls as defined by external risk frameworks and the firms Technology Risk and Control Framework, and (3) adoption of secure and resilient solutions
- Build and maintain an understanding of global, regional and local regulatory requirements that have a technology impact, to conduct internal self-assessments and gap analyses to ensure compliance
- Participate in global, regional and local Engineering Risk initiatives aimed at improving baseline on information protection, resiliency and controls of technology processes and services
- Work on business initiatives ensuring regulatory requirements are appropriately understood, communicated, and mitigated
- Maintain relationships with stakeholders to facilitate oversight and effectiveness of the technical control environment
- Perform risk assessments to identify gaps in compliance to information security (both application and infrastructure), external risk frameworks and BCP standards and policies, for both internal technology solutions as well as solutions provided by third-party service providers. Ensuring critical and high priority issues are identified and resolved.
Qualifications, capabilities and skills:
- 5+ years of technology experience in one or more of the following areas: Technology Infrastructure, Information Security, External Risk Frameworks, Technology Governance, Compliance, Control management, Operational Risk and/or Technology Audit
- Infrastructure security knowledge in Windows Server, Desktop OS and applications, Unix/Linux OS, Storage, Networking hardware and protocols, Databases, Messaging and Exchange Connectivity, Remote Access, Firewall and IDS/IPS technology, Voice and Audio Visual platforms, and experience in configuration, change and vulnerability management is a significant advantage.
- Understanding of the regulatory environment as it relates to technology control and/or business continuity requirements
- Familiar with Risk Analysis and Risk Management methodologies
- Excellent program and project management skills
- Understanding of the business functions and the Technology role in a financial services firm a significant advantage
- Ability to work effectively as part of the regional and global team, serving a large diverse Engineering community