Salary
💰 $170,000 - $282,500 per year
About the role
- Act as the ETRM advisor to the IT organization and first line of defense (FLOD) control function on matters relating to the IT risk posture of State Street
- Ensure technology risks and non-compliance with internal and external standards are proactively identified, prudently managed, and effectively challenged
- Identify/assess/monitor risks and support FLOD in planning/executing controls and additional compensating controls
- Participate in various risk governance forums and execute real time oversight and challenge
- Monitor technology risk appetite, report breaches, escalate exceptions and challenge risk acceptances
- Provide an independent opinion on FLOD Technology risk management and recommend appropriate improvements
- Participate in adoption of the Enterprise Technology Risk Framework for technology processes
- Interact with Enterprise Process Owners for Technology Processes and foster deeper FLOD/SLOD relationships and embedded risk management
- Communicate and drive implementation of ETRM risk management policies, framework, tools, guidelines and standards across the business
- Provide strategic leadership, vision and ongoing support to FLOD and IT leaders regarding information technology best practices and trends
- Advise IT and FLOD in prioritization of risks, risk initiatives, and risk mitigation alternatives
- Review and appropriately challenge technology risk decisions, direction, and initiatives undertaken by the FLOD
- Provide support and advice to ETRM and stakeholders for regulatory exams and regulatory findings
- Collaborate with and support regional (APAC and EMEA ETRM) peers in matters related to technology risks
- Deliver assigned ETRM services annual book of work (risk assessments, continuous monitoring, issues management, reporting etc)
- Utilize Enterprise Risk and Operational risk management tools (NBPRA, MRI, RCSA, KRI’s, Incident data, Loss event data) to proactively monitor the Technology control environment
- Keep abreast of new products, services, technologies and applications and their impact on the organization’s risk profile
- Serve as a subject matter expert in technology risk, controls, compliance, and best practices
Requirements
- Minimum 15 years of experience in the financial, and or technology industries
- Seasoned Technology Risk Leader with more than 15 years’ experience in financial services and/or technology industry
- Well versed in identifying, managing and monitoring technology risks across Technology Resiliency, Technology Change Management, Obsolescence, IT Asset Management and Technology Risks related to Third parties
- Exceptional interpersonal and communication skills; superior communication, interpersonal, negotiation, presentation and intergroup skills
- Ability to translate technical issues into risk terms that business can understand
- Strong initiative and ability to perform well under pressure while managing multiple diverse assignments
- Experience interacting with C-level executives (CTO, CIO, Chief Architect, etc.)
- Prior experience with regulators and regulatory exams and responses is strongly desired
- Experience with Cyber and Information Security
- Experience with Cloud Risk Management (AWS, Azure)
- Experience with Enterprise Architecture
- Experience in risk management, compliance or audit, including design & implementation of control frameworks
- CRISC, CISSP, TOGAF, CCSK appreciated but not mandatory
- Working knowledge of industry and regulatory risk and control standards and frameworks - FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM etc expected
- Advanced degree or undergraduate in technology discipline or equivalent