Vice President, Control Design and Monitoring - Tech, Cyber, Data

Job Level:  Vice President
Job Function:  Governance & Assurance
Location: 

Charlotte, NC, US, 28202

Employment Type:  Full Time
Requisition ID:  8234

Role Description

The Business Control Office (BCO) has the responsibility to ensure the implementation of consistent risk control frameworks and establishment of efficient risk controls across SMBC Group AD. The Control Design and Monitoring function is a central BCO function responsible for overall development and execution of 1st line control testing and monitoring program. The VP, Cybersecurity, Data & Technology Controls Testing and Monitoring is responsible for evaluating the design and operating effectiveness of key Cybersecurity, Data and Technology controls within a financial services environment. This role requires conducting control deep dives, executes controls validation/testing (including sample-based testing), develops and performs ongoing control monitoring routines, and partners with Technology, Data and Cybersecurity stakeholders to identify control gaps, drive remediation, and enhance the overall Information Security control environment.


The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.

 

  • Execute risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
  • Perform Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
  • Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment
  • Prepare detailed work-papers and Monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
  • Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
  • Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
  • Perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
  • Possesses solid background knowledge and understanding of Technology, Data Management, and Cyber Security standards, frameworks, policies and compliance regulations

Qualifications and Skills

  • 5+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with at least 3-5 years of specialized experience within Cybersecurity and Technology Risk and Controls Assurance
  • Hands-on experience performing design and operating effectiveness testing of technology/cyber controls, with ability to document Control testing findings and perform trend analysis and report production
  • Expertise in control frameworks, control assessment and control monitoring programs
  • Strong communication (both written and verbal) and time management ability
  • Experience interacting with senior management within a business environment
  • Strong critical thinking, analytical and organizational skills
  • Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
  • Demonstrated knowledge of cyber security control domains (IAM, vulnerability/patch, monitoring/logging, endpoint, network, cloud)
  • Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA (any combination)


Nearest Major Market: Charlotte