img
Permanent

Assistant Vice President, IT Risk and Control

City of Westminster
money-bag Negotiable
Posted 2 days ago

Overview

The IT Risk, Security and Control (RSC) department works across Technology and the Business to perform Cybersecurity and Technology protection, governance, risk management and reporting. The department is made up of a number of specialist teams ultimately responsible for managing Cybersecurity and Technology risks in line with MUFG risk tolerance. IT Risk and Control (ITRC) is one team within RSC responsible for Technology risk and control management. Key responsibilities of ITRC include the risk and control framework, risk and control self-assessment (RCSA), key control testing, key risk indicators, governance and reporting and internal and external audit oversight. To be an integral member of the ITRC team with a primary focus on planning and executing key control testing, reporting and enhancing key risk indicators, and monthly governance and reporting, which will involve liaising with all Technology departments and some business functions and other teams as necessary.

Responsibilities

Perform control testing to assess the design and operating effectiveness of key cybersecurity and technology controls, and report conclusions to risk and control owners.

Support efforts to sustain and enhance our risk and control framework to ensure material regulatory requirements are being assessed, tested and reported on.

Manage and enhance key risk indicators that support risk appetite and residual risk measurement and reporting to the firm''s executive leadership and risk committees.

Support the execution of cybersecurity and technology risk management and its strategic roadmap, including management and development of new key risk indicators to enable our stakeholders to understand risk posture.

Play an active role in monthly governance and reporting activities, in particular managing materials and actions relating to the monthly ITRMC meeting.

Support complex, firm-wide initiatives towards successful completion and develop reports to communicate progress to senior management, risk committees, and Board of Directors.

Work closely with cybersecurity and technology teams, in particular risk and control owners to enhance control effectiveness, drive remediation and closure of open issues.

Understand current cybersecurity and technology strategy and help to mature it on a continuous basis through targeted initiatives.

Collaborate with stakeholders to understand gaps and process improvements to enhance business operations.

Analyse and measure the effectiveness of existing business processes and develop sustainable, repeatable, and quantifiable improvement recommendations (business requirements definition, gap analysis, cost-benefit analysis).

Recommend solutions (in terms of both technology and business outcomes) based on root cause analysis, cost / benefits, feasibility analysis, and research of sound industry practices.

Leverage industry frameworks, best practices, and changes in financial services sector that may impact reporting for cybersecurity and technology program and project developments.

Stay abreast on current state understanding of information security program developments, industry frameworks, and changes in the company that may impact reporting.

Qualifications

Experience in IT security and risk management, preferably in financial services sector

Experience in IT controls assurance and testing

Experience in IT controls governance and reporting

Experience in developing and providing executive level reporting

Certified CRISC / CISA or other relevant qualifications desirable

Personal requirements

Excellent communication skills

Identifies multiple paths to success using analytical and critical thinking as well as decision-making skills

Exercises sound judgement, prioritises effectively, and strives for continuous improvement

Effectively collaborates with colleagues

Leverages available technology to drive efficiency and results

Understands and applies industry trends and best practices

Exhibits optimism, resilience, flexibility, and openness to others\'' ideas

Values learning as a lifelong professional objective

Engages inclusively and with intent

Always acts with integrity

Iterative problem-solving

Acts as a trusted advisor

Strong interpersonal skills

Strong organisational, critical thinking and problem solving skills

Ability to articulate key messages to a range of audiences

We are open to considering flexible working requests in line with organisational requirements.

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world\''s leading financial groups. Across the globe, we\''re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world. With a vision to be the world\''s most trusted financial group, it\''s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career. Join MUFG, where being inspired is expected and making a meaningful impact is ..... full job details .....

Other jobs of interest...

Citibank (Switzerland) AG
London
money-bagNegotiable
HICX
London
money-bag£250,000 per annum
JPMorgan Chase & Co.
City of Westminster
money-bagNegotiable

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!