Executive Director, Head of Tech Cyber Data First Line Testing

SMBC

Charlotte (NC)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SMBC in Charlotte, NC seeks an Executive Director, Head of Tech Cyber Data First Line Testing to lead IT, data and cyber control testing and monitoring across the Americas Division Control Office. You will drive risk-based testing programs, coordinate with senior management, and strengthen the first-line control environment within financial services.

The role requires extensive experience in controls testing, data and cyber risk, and the ability to orchestrate cross-functional teams across

Qualifications

  • 10+ years in Audit/Operational Risk/First Line Control Testing in financial services.
  • Specialized experience in Cybersecurity, Data Management and Technology Risk and Controls Assurance.
  • Detail oriented with ability to question status quo and apply risk principles.

Responsibilities

  • Lead planning and execution of risk-based control testing across cybersecurity, data and technology domains.
  • Develop control monitoring/testing routines with documentation and analyses.
  • Assess control effectiveness and recommend enhancements to control environment.
  • Prepare detailed workpapers and monitoring reports within deadlines.
  • Communicate requirements and results with stakeholders; drive remediation.
  • Oversee deep dives to identify control weaknesses and process inefficiencies.
  • Demonstrate strong knowledge of applicable frameworks and regulatory requirements.

Skills

Audit/Operational Risk
Control Testing
Cybersecurity Risk
Data Management
Regulatory Knowledge
Documentation & Reporting
Communication Skills
Root Cause Analysis
Process Mapping
Time Management
Senior Stakeholder Interaction
Audit Methodologies
GRC Frameworks
Regulatory Compliance

Job description

Select how often (in days) to receive an alert:

Executive Director, Head of Tech Cyber Data First Line Testing

Job Level: Executive Director

Location: Charlotte, NC, US, 28202

Employment Type: Full Time

Requisition ID: 8233

Role Description

The Americas Division Control Office (AD CO) has the responsibility to ensure the implementation of consistent risk and control frameworks and establishment of efficient controls across SMBC Group AD. The Control Design and Monitoring function is a central CO function responsible for overall development and execution of 1st line control testing and monitoring program. The position of the Control Testing ED focuses on leading the execution of the IT, Data and Cyber Controls Testing and Monitoring program. This role requires background experience in controls testing and monitoring; controls validation; and/or IT, cyber and data risk management, assessing and evaluating the control environment within a financial services environment, including adequacy of the GRC control designs, operating effectiveness of processes/activities and remediation of gaps/ findings. The role will oversee the Cybersecurity, Data and Technology control testing as well as establish control monitoring routines. This position will help enhance the controls through leading targeted deep dives, root cause analysis, developing process maps and overall assistance with the design and execution of control effectiveness assessments.

The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.

Responsibilities
  • Lead the planning and execution of risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
  • Develop Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
  • Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment, as well as enhancement of the first-line control testing and monitoring methodology and guidance
  • Oversee and prepare detailed workpapers and monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
  • Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
  • Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
  • Oversee and perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
  • Possesses solid background knowledge and understanding of Technology, Data Management and Cyber Security standards, frameworks, policies and compliance regulations
Qualifications and Skills
  • 10+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with specialized experience within Cybersecurity, Data Management and Technology Risk and Controls Assurance
  • Detail oriented, with proven ability to question the status quo and apply risk management principles to enhance processes, as appropriate
  • Ability to document Control testing findings and perform trend analysis and report production, and adopt emerging control testing/monitoring solutions (e.g., Artificial Intelligence; other automation tools)
  • Expertise in control frameworks, control assessment and control monitoring programs
  • Expertise in process and control design, including process mapping and process reengineering
  • Exceptional communication (both written and verbal) and time management ability
  • Proactive self-starter with ability to prioritize efforts across multiple projects and manage competing deadlines
  • Experience interacting with senior management within a business environment
  • Strong critical thinking, analytical and organizational skills
  • Demonstrated working knowledge of NYDFS 500, including hands-on experience implementing, monitoring, and maintaining compliance with regulatory requirements
  • Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
  • Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA, CDPM (any combination)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Executive Director, Head of Tech Cyber Data First Line Testing
Executive Director, Head of Tech Cyber Data First Line Testing

SMBC Group • Charlotte (NC), Northern (KY)

On-site
USD 180,000 - 240,000
Vice President, Control Design and Monitoring - Tech, Cyber, Data
Vice President, Control Design and Monitoring - Tech, Cyber, Data

SMBC • Charlotte (NC)

On-site
USD 180,000 - 240,000
Healthcare benefits
401(k) matching
Bonus opportunities
Vice President, Control Design and Monitoring - Tech, Cyber, Data
Vice President, Control Design and Monitoring - Tech, Cyber, Data

SMBC Group • Charlotte (NC)

On-site
USD 180,000 - 260,000
Executive Director, Cyber, Data & Tech Controls Testing
Executive Director, Cyber, Data & Tech Controls Testing

SMBC Group • Charlotte (NC), Northern (KY)

Hybrid
USD 180,000 - 240,000
Executive Director, Cyber & Data Control Testing Leader
Executive Director, Cyber & Data Control Testing Leader

SMBC • Charlotte (NC)

On-site
USD 180,000 - 240,000
IT Risk & IT control testing (Second Line of Defence – 2LOD)
IT Risk & IT control testing (Second Line of Defence – 2LOD)

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 170,000
IT Risk & Control Analyst
IT Risk & Control Analyst

CloudIngest • New York (NY)

Hybrid
USD 120,000 - 190,000
IT Risk & Control Senior Analyst (W2 Only) (USC or GC Only)
IT Risk & Control Senior Analyst (W2 Only) (USC or GC Only)

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

TechDigital Group • Phoenix (AZ)

On-site
USD 120,000 - 150,000