Executive Director, Head of Tech Cyber Data First Line Testing

Job Level:  Executive Director
Job Function:  Governance & Assurance
Location: 

Charlotte, NC, US, 28202

Employment Type:  Full Time
Requisition ID:  8233

Role Description

The Americas Division Control Office (AD CO) has the responsibility to ensure the implementation of consistent risk and control frameworks and establishment of efficient controls across SMBC Group AD. The Control Design and Monitoring function is a central CO function responsible for overall development and execution of 1st line control testing and monitoring program. The position of the Control Testing ED focuses on leading the execution of the IT, Data and Cyber Controls Testing and Monitoring program. This role requires background experience in controls testing and monitoring; controls validation; and/or IT, cyber and data risk management, assessing and evaluating the control environment within a financial services environment, including adequacy of the GRC control designs, operating effectiveness of processes/activities and remediation of gaps/ findings. The role will oversee the Cybersecurity, Data and Technology control testing as well as establish control monitoring routines. This position will help enhance the controls through leading targeted deep dives, root cause analysis, developing process maps and overall assistance with the design and execution of control effectiveness assessments.

 

The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.

 

Responsibilities

  • Lead the planning and execution of risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
  • Develop Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
  • Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment, as well as enhancement of the first-line control testing and monitoring methodology and guidance
  • Oversee and prepare detailed workpapers and monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
  • Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
  • Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
  • Oversee and perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
  • Possesses solid background knowledge and understanding of Technology, Data Management and Cyber Security standards, frameworks, policies and compliance regulations

Qualifications and Skills

  • 10+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with specialized experience within Cybersecurity, Data Management and Technology Risk and Controls Assurance
  • Detail oriented, with proven ability to question the status quo and apply risk management principles to enhance processes, as appropriate
  • Ability to document Control testing findings and perform trend analysis and report production, and adopt emerging control testing/monitoring solutions (e.g., Artificial Intelligence; other automation tools)
  • Expertise in control frameworks, control assessment and control monitoring programs
  • Expertise in process and control design, including process mapping and process reengineering
  • Exceptional communication (both written and verbal) and time management ability
  • Proactive self-starter with ability to prioritize efforts across multiple projects and manage competing deadlines
  • Experience interacting with senior management within a business environment
  • Strong critical thinking, analytical and organizational skills
  • Demonstrated working knowledge of NYDFS 500, including hands-on experience implementing, monitoring, and maintaining compliance with regulatory requirements
  • Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
  • Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA, CDPM (any combination)


Nearest Major Market: Charlotte