Consult control owners and leaders about the risk profile of their portfolios of processes and applications
Serve as a trusted risk advisor to aligned Technology leaders
Identify and address risks before they impact objectives
Oversee and enable the aligned Technology team’s compliance with existing and new requirements
Evaluate and consult on the risks associated with strategic priorities or major programs and projects
Provide actionable information to help prioritize risk-mitigation actions across the portfolio of platforms/applications managed by the leader
Design and enhance effective control environments for technology products and services
Simplify the existing control environment using process/control re-engineering and automation
Respond to unexpected events and findings
Collaborate to drive strategic outcomes for the good of the overall team
Provide guidance to ensure complete, accurate, and authoritative inventories of technology assets, software, and configuration items
Provide guidance on sustainable compliance with regulatory requirements
Perform risk assessments to evaluate compliance with existing policies, standards, and procedures and to accurately identify risks and drive remediation processes to ensure that compliance and security gaps are addressed
Use data analysis to help aligned Program Leaders develop proactive and anticipatory approaches to risk management
Support aligned Technology or Business Line team in demonstrating evidence of control effectiveness and identify and escalate control gaps in a timely manner
Deliver targeted and actionable risk reporting across various leadership levels
Serve as a functional liaison between the Business Line and second and third lines of defense
Requirements
Bachelor’s Degree, or equivalent work experience
Typically more than 10 years of applicable experience
10+ years of Technology Risk, IT Operations, Asset Management, Configuration Management, Information Security, or Audit experience
Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact their assigned line of business
Advanced understanding of the business line’s operations, products/services, systems, and associated risks/controls
Thorough knowledge of Risk/Compliance/Audit competencies with experience supporting regulatory examinations, audits, and assessments involving inventory management and technology governance controls
Strong management skills in processes, projects and people
Excellent presentation, interpersonal, written, and verbal communication skills
Strong analytical, problem-solving and negotiation skills
Proficient computer skills, especially Microsoft Office applications
Applicable professional certifications (e.g. CRISC, ITIL, CISSP, CGEIT, etc.)
Experience evaluating IT Asset Management (ITAM) programs
Experience with ServiceNow CMDB, Discovery, Service Mapping, ITAM, and SAM
Experience evaluating software inventory completeness and technology ownership frameworks
Experience assessing controls supporting configuration management and asset lifecycle processes
Knowledge of open-source software governance and software supply chain risk management practices
Familiarity with software licensing, entitlement management, and software rationalization practices
Experience with technology lifecycle management and asset retirement processes
Tech Stack
ServiceNow
Benefits
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law