Responsibilities
- Provide independent 2nd line risk oversight by assessing 1st line technology risk practices
- Provide risk-based challenge and escalation support
- Review, assess, and provide credible challenge to 1st line technology risk identification
- Review Key Indicators and trend analysis for technology domains
- Provide targeted, risk-based second line oversight of technology risk areas
- Evaluate specific areas of elevated or emerging technology risk
- Participate in and contribute to relevant governance forums
- Monitor alignment with ERM policies
- Engage and provide credible challenge in the Risk and Control Self-Assessment governance cycle
- Draft and support technology risk reporting for executive management and Board level materials
- Promote risk awareness across the Bank and serve as a 2nd line subject matter resource
Qualifications
- Bachelor’s degree in technology, business or a related field
- A minimum of seven (7) years of technology or technology risk experience
- A minimum of three (3) years of experience in IT Risk & Governance and/or 2nd line/ERM oversight (or Internal Audit covering technology risk) providing independent challenge
- MBA or other advanced degree (PLUS)
- IT/ITIL Certifications (PLUS)
- IIBA Certification (PLUS)Certified in Risk and Information Systems Control (CRISC) (PLUS)
- Certified Information Security Manager (CISM) (PLUS)
- Certified Information Systems Security Professional (CISSP) (PLUS)
Core Competencies
Demonstrates extensive experience in technology risk oversight, governance, and independent challenge, with a strong focus on risk identification and reporting. Proficient in engaging with governance forums and promoting risk awareness across the organization.