About this role
Job title: Lead, Technology and Cyber Risk Management
About the Role This role is an individual contributor position responsible for executing activities supporting IT and Cybersecurity Risk Management, including regulatory interactions, IT risk and control assessments, information security initiatives, and management reporting. It plays a key part in identifying, assessing, managing, and reporting technology and information security risk, delivering work across core practice areas within the Information Security and Technology Risk Management Program.
What You'll Do
- Develop and maintain technology and cybersecurity risk metrics and assessments to inform the firm of its risk posture
- Manage preparation and delivery of materials for key engagements, including regulatory interactions, audit examinations, and senior management meetings
- Identify and assess risks associated with internal technologies and externally hosted systems
- Define requirements and execution plans for information security and technology risk management programs
- Ensure risk management programs align with applicable regulations, industry standards, and compliance requirements
- Communicate security policies and requirements clearly to ensure organisational understanding and adoption
- Produce meaningful, measurable metrics for owned risk management programs
- Review and assess technology and security controls using established frameworks
- Drive risk reduction through defined risk treatment and remediation processes
- Document, track, and report risk findings and remediation plans to management
- Collaborate with Information Security, Privacy, and Enterprise Risk teams to enhance policies, standards, and frameworks
- Evaluate and provide risk advice on strategic business and technology initiatives
- Participate in cybersecurity incident response activities as required
- Stay current on industry trends, emerging threats, technologies, and regulatory developments and advise management on their potential business and financial impact
What We're Looking For
- Strong experience in IT Risk Management, Technology Risk, or IT Audit
- Experience creating metrics and reporting using tools such as Power BI and PowerPoint
- Required certification: CISA, CISM, CRISC, CISSP, or equivalent
- Bachelor's degree in Accounting, Finance, Information Technology, MIS, Computer Science, or related discipline
- Advanced degree in an IT-related field is desirable
- Strong ability to develop effective technology and cybersecurity risk metrics, assessments, and executive-level presentations
- Experience assessing IT processes including information security, system development and change management, computer operations, and data protection
- Working knowledge of Financial Services regulatory requirements, including FFIEC handbooks and relevant country-specific regulatory bodies
- Hands-on experience applying industry frameworks such as COBIT 5, ISO 27001/27002, and NIST 800-53
- Exposure to one or more information security disciplines (e.g. forensics, secure development, threat intelligence, penetration testing)
- Strong analytical skills with the ability to assess complex data and formulate sound, well-justified risk decisions
- Proven ability to manage multiple priorities with urgency and attention to detail
- Excellent written and verbal communication skills, including the ability to produce clear, well-structured documentation and reports
- Ability to work effectively both independently and within global, multi-national teams
- Professional presence and ability to build strong working relationships across all organisational levels and with third-party providers
Nice to Have
- Advanced degree in an IT-related field is desirable
Compensation & Benefits
- Working with Us: Flexible and collaborative work culture; movement within the organization is encouraged; senior leaders are accessible; a company with a greater purpose and commitment to communities; inclusive workplace with flexible working requirements.