JOB SUMMARY: This position serves as an independent Second Line of Defense (2LoD) risk management function primarily responsible for the development, implementation, execution, maintenance, and continuous enhancement of the Controls Testing Program. The role provides independent oversight, credible challenge, and testing activities designed to evaluate the design and effectiveness of Information Technology (IT) and Cybersecurity controls and assess compliance with internal policies, regulatory requirements, and industry standards.
This position serves as a subject matter expert for controls testing methodologies and works closely with Information Technology, Information Security, Risk Management, Compliance, and Internal Audit teams to identify control weaknesses, communicate risk insights, support remediation validation activities, strengthen the overall control environment, and support regulatory examinations, audits, and strategic risk management initiatives.
The position operates independently from First Line of Defense (1LoD) control ownership and execution and does not assume responsibility for designing, implementing, operating, or remediating 1LoD controls. Accountability for control ownership, operation, testing, remediation, and risk treatment remains with the appropriate business, technology, and Information Security functions.
The ideal candidate possesses strong analytical, communication, and critical thinking skills and can translate assessment results into meaningful risk and control insights for management and stakeholders.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Develops, implements, maintains, and continuously enhances the Controls Testing Program.
- Establishes and maintains methodologies, standards, procedures, and support documentation for independent assessments and testing activities.
- Executes independent assessments to evaluate the design and effectiveness of IT and Cybersecurity controls.
- Evaluates controls against internal policies, regulatory requirements, and industry-recognized frameworks.
- Provides credible challenge to First Line of Defense control owners regarding control effectiveness and remediation activities.
- Analyzes and documents assessment results, identify control gaps, root causes, and risk themes, and determine remediation priorities.
- Validates corrective actions and prepares clear, concise, and actionable reports that communicate findings and recommendations to management and stakeholders.
- Supports internal audits, external audits, regulatory examinations, and inquiries by providing documentation and supporting evidence.
- Monitors emerging threats, technology risks, regulatory developments, audit observations, and industry practices and incorporate relevant changes into methodologies and program coverage.
- Identifies opportunities to enhance assessment methodologies through automation, analytics, and approved AI-enabled capabilities.
- Coordinates internal and external penetration testing engagements, including scope, objectives, and testing requirements.
- Reviews penetration testing results, assess the adequacy of remediation plans and corrective actions, and maintain supporting documentation and historical records.
- Supports other Second Line of Defense Cyber and Technology Risk activities as assigned.
- Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).
- Adheres to Bank policies and procedures and completes required training.
- Identifies and reports suspicious activity.
SUPERVISORY RESPONSIBILITIES
N/A
QUALIFICATIONS
Education
Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Risk Management, or a related field preferred.
Experience
- Minimum 4-6 years of experience in controls testing, IT audit, cybersecurity, technology risk, compliance, or related disciplines.
- Experience performing control design assessments, control effectiveness evaluations, and remediation validation activities.
- Experience evaluating IT and Cybersecurity controls and documenting observations, findings, and recommendations.
- Experience developing, implementing, executing, and maintaining controls testing, validation, or oversight program preferred.
- Experience coordinating penetration testing engagements preferred.
- Experience working within banking, financial services, or other highly regulated industries preferred.
- Experience interacting with auditors, regulators, and senior management preferred.
Licenses and Certifications
Professional certifications such as CISA, CRISC, CISSP, CISM, CCSP, or equivalent are highly desirable.
Knowledge, Skills, and Abilities
- Strong understanding of risk management principles, controls frameworks, and regulatory requirements.
- Knowledge of controls testing methodologies, program development, evidence evaluation techniques, and remediation validation processes.
- Strong understanding of the Three Lines Model and the respective responsibilities of 1LoD, 2LoD, and Internal Audit.
- Familiarity with NIST Cybersecurity Framework (CSF), NIST SP 800-53, CIS Controls, FFIEC guidance, and related industry standards.
- Familiarity with penetration testing processes and remediation validation practices.
- Strong analytical, organizational, and problem-solving skills.
- Excellent written, verbal, and presentation skills with the ability to communicate complex technical and risk concepts to diverse audiences.
- Ability to present findings and recommendations clearly, objectively, and independently.
- Ability to manage multiple priorities and deadlines while maintaining attention to detail.
- Ability to work independently as the subject matter expert for the Controls Testing Program and drive continuous improvement initiatives.
Additional Information
Candidates residing in locations within BankUnited's footprint may be given preference.