The Business Control Office (BCO) has the responsibility to ensure the implementation of consistent risk control frameworks and establishment of efficient risk controls across SMBC Group AD. The Control Design and Monitoring function is a central BCO function responsible for overall development and execution of 1st line control testing and monitoring program. The VP, Cybersecurity, Data & Technology Controls Testing and Monitoring is responsible for evaluating the design and operating effectiveness of key Cybersecurity, Data and Technology controls within a financial services environment. This role requires conducting control deep dives, executes controls validation/testing (including sample-based testing), develops and performs ongoing control monitoring routines, and partners with Technology, Data and Cybersecurity stakeholders to identify control gaps, drive remediation, and enhance the overall Information Security control environment.
The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.
Execute risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
Perform Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment
Prepare detailed work-papers and Monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
Perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
Possesses solid background knowledge and understanding of Technology, Data Management, and Cyber Security standards, frameworks, policies and compliance regulations
Qualifications and Skills
5+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with at least 3-5 years of specialized experience within Cybersecurity and Technology Risk and Controls Assurance
Hands-on experience performing design and operating effectiveness testing of technology/cyber controls, with ability to document Control testing findings and perform trend analysis and report production
Expertise in control frameworks, control assessment and control monitoring programs
Strong communication (both written and verbal) and time management ability
Experience interacting with senior management within a business environment
Strong critical thinking, analytical and organizational skills
Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
Demonstrated knowledge of cyber security control domains (IAM, vulnerability/patch, monitoring/logging, endpoint, network, cloud)
Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA (any combination)
Numbers & Facts
Location
Charlotte, NC
Skills
Analysis Skillsunmatched
Banking Servicesunmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Control Objectives for Information and related Technology (COBIT)unmatched
Corrective Actionunmatched
Data Managementunmatched
Design Evaluationunmatched
Document Controlunmatched
Documentationunmatched
Financial Servicesunmatched
ISO (International Organization for Standardization)unmatched
Identify Issuesunmatched
Information/Data Security (InfoSec)unmatched
Internal Auditunmatched
Internet Securityunmatched
Maintain Complianceunmatched
Operational Auditunmatched
Organizational Skillsunmatched
Process Analysisunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Riskunmatched
Risk Managementunmatched
Security Information and Event Management (SIEM)unmatched
Software Patchesunmatched
Technical Leadershipunmatched
Test Plan/Scheduleunmatched
Testingunmatched
Time Managementunmatched
Trend Analysisunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Validation Testingunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.