Vice President, Control Design and Monitoring - Tech, Cyber, Data

SMBC
  • Charlotte, NC
    12 days ago

    Job Description

    Role Description

    The Business Control Office (BCO) has the responsibility to ensure the implementation of consistent risk control frameworks and establishment of efficient risk controls across SMBC Group AD. The Control Design and Monitoring function is a central BCO function responsible for overall development and execution of 1st line control testing and monitoring program. The VP, Cybersecurity, Data & Technology Controls Testing and Monitoring is responsible for evaluating the design and operating effectiveness of key Cybersecurity, Data and Technology controls within a financial services environment. This role requires conducting control deep dives, executes controls validation/testing (including sample-based testing), develops and performs ongoing control monitoring routines, and partners with Technology, Data and Cybersecurity stakeholders to identify control gaps, drive remediation, and enhance the overall Information Security control environment.


    The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.

     

    • Execute risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
    • Perform Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
    • Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment
    • Prepare detailed work-papers and Monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
    • Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
    • Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
    • Perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
    • Possesses solid background knowledge and understanding of Technology, Data Management, and Cyber Security standards, frameworks, policies and compliance regulations

    Qualifications and Skills

    • 5+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with at least 3-5 years of specialized experience within Cybersecurity and Technology Risk and Controls Assurance
    • Hands-on experience performing design and operating effectiveness testing of technology/cyber controls, with ability to document Control testing findings and perform trend analysis and report production
    • Expertise in control frameworks, control assessment and control monitoring programs
    • Strong communication (both written and verbal) and time management ability
    • Experience interacting with senior management within a business environment
    • Strong critical thinking, analytical and organizational skills
    • Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
    • Demonstrated knowledge of cyber security control domains (IAM, vulnerability/patch, monitoring/logging, endpoint, network, cloud)
    • Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA (any combination)

    Numbers & Facts

    LocationCharlotte, NC

    Skills

    • Analysis Skillsunmatched
    • Banking Servicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Corrective Actionunmatched
    • Data Managementunmatched
    • Design Evaluationunmatched
    • Document Controlunmatched
    • Documentationunmatched
    • Financial Servicesunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identify Issuesunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Maintain Complianceunmatched
    • Operational Auditunmatched
    • Organizational Skillsunmatched
    • Process Analysisunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Software Patchesunmatched
    • Technical Leadershipunmatched
    • Test Plan/Scheduleunmatched
    • Testingunmatched
    • Time Managementunmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Validation Testingunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder