Job Description
What is the opportunity?
This role participates in and leads some of the execution of the Wealth Management Technology (WMT) Operational Risk Annual Plan and execution of operational risk management (ORM) and IT Risk management within WMT. The role is also responsible for participating in planning and managing Operational Risk Management programs and processes as they flow across WMT.
Technical manager with 1-2 direct reports, expert understanding of IT, Cyber & Operational risk management practices, providing control and advisory services to: application development, support teams and the Wealth Management Business. Services provided cover IT, Cyber & operational risk analysis, risk & compliance exposure reporting, risk awareness & advisory, and regulatory response.
What will you do?
- Lead identification, assessment and treatment recommendations for IT, Cyber & Operational risks
- Lead vulnerability management program for WMT covering all Application and Infrastructure assets
- Lead WMT cyber security operations in response to the current and emerging threat landscape
- Responsible for execution and completion of security exemption and acceptance workflow process from start to finish
- Lead preparation and participate in execution of executive level meetings (attended by WMT SVP and Senior Leadership Team) on various control and risk topics (e.g. areas of focus and risk acceptances)
- Lead execution of risk profile review meetings (attended by Vice Presidents/Senior Directors and their delegates) to ensure SMT risk profiles are adequately managed
- Lead/manage direct reports to ensure risk register workflow is executed effectively
- Contribute to the delivery of the WMT IT & Operational risk awareness program
What do you need to succeed?
Must-have
- Experience conducting threat risk assessments on enterprise applications
- Expert knowledge in IT and operational risk management processes, methods and tools
- Expert knowledge of Cybersecurity threats, Application and Infrastructure security including
- Experience with Penetration testing & DevSecOps with focus on SAST, DAST, SCA, Container and Server security assessments
- Experience with emerging AI driven cyber threat landscape
- Experience with building Agentic AI driven solutions and automation
- Strong knowledge of IT infrastructure & software security architectures
- Demonstrable technical knowledge and experience covering the operating systems (e.g. Unix, Windows, zOS) and database systems (e.g. Oracle, SQL Server, Sybase, DB2) in use in Finance IT
- CRISC or CISSP Certification
- Good communication (verbal and written) skills, including strong appreciation of relationship management
Nice-to-have
- CCSP certification
- Knowledge of GRC tools (e.g. ServiceNow, Archer)