About this role
What You’ll Be Doing
- Build and run an independent, enterprise-wide risk and audit function across KAST.
- Own the enterprise risk framework: identify, assess, and track risks across all business areas, not just technology.
- Define and drive risk management activities, including Risk and Control Self Assessment (RCSA) and Key Risk Indicators (KRIs).
- Drive internal audit activities enterprise-wide and across the full audit lifecycle, including management reporting and closure of audit findings.
- Provide neutral, independent validation of controls and compliance work already underway rather than duplicating it.
- Review and assess security and technology controls, systems, policies and processes, including data access, data sharing, system access workflows and other high-risk processes.
- Assess cybersecurity practices and identify potential risks and gaps; ensure appropriate penetration testing, vulnerability assessments, and remediation are in place.
- Own enterprise resilience practices such as business continuity and disaster recovery (BCP/DR) and business impact assessments.
- Conduct annual BCP and DR exercises
- Partner with Engineering, Security, Legal, Compliance, Finance, and other teams to address identified risks and improve controls, while remaining independent of them.
- Develop and maintain risk and audit frameworks, policies, and processes across the org.
- Provide regular risk and audit updates to the leadership team.
What You’ll Bring
- 8+ years of experience in risk, audit, cybersecurity, or controls, with an enterprise-wide, not purely t