Director - Operational, Technology and Cyber Risk (OTCR)

Standard CharteredNew York, NY
39dHybrid

About The Position

The Operational, Technology and Cyber Risk (OTCR) department within the Risk function, is the second line-of-defence (2LoD) and provides independent challenge, guidance, and oversight of first line-of-defence (1LoD) risk management. OTCR is led by the Global Head, Operational, Technology and Cyber Risk, who has delegated authority from the Group Chief Risk Officer. OTCR comprises OTCR Business / Function Coverage Leads and OTCR SMEs who support the Global Head, OTCR. OTCR sets the methodology managing Information and Cyber Security (ICS) and Technology Risks across the Group. Risk Management authorities for ICS and Technology Risks are executed in line with the Bank's risk management activities i.e., Risk Acceptance and Treatment Plan Escalation, Approval and Closure Authorities. This OTCR T&O Country Coverage Lead, Americas position spans two roles; OTCR ICS & Tech Risk SME and Technology and Operations (T&O) Coverage. It is a permanent role, requiring strong business acumen and familiarity with the Americas (North and South America) regulatory landscape, deep knowledge and experience in the ICS and Technology risk field. For the OTCR T&O Coverage role, the person will be responsible for: Review, challenge and (where relevant) approval on core ICS and Technology Risk matters that are not aligned to a specific business or function. ICS and Technology Risk management and stakeholder engagement / escalation. Approvals / veto on risk decisions within ICS and Technology Risk. End-to-end oversight of risk performance for ICS controls and core Technology. Interfacing with 1LoD (i.e. Principle Point of Contact) for ICS and core Technology. For the OTCR ICS and Tech Risk SME role, the person will help, guide, and support informed decision making and risk management with specialist knowledge and expertise. The role will be delivered through consultation, stakeholder engagement and SME insights. It does not involve approval responsibilities. Key Responsibilities The successful candidate will have a strong understanding of operating in a second line ICS and Tech Risk capacity and strong experience working with Americas regulators. They should be able to respond flexibly and collaboratively to evolving business, regulatory and threat requirements. The role reports directly to the Head, OTCR, Strategic & Emerging Risks, with a matrix management Cluster Head, OTCR, Americas & Country Head, US. The role will provide oversight and challenge of ICS and Technology risk management as a risk partner to country leadership as defined in the Bank's ICS and Operational & Technology Risk Type Frameworks and under delegation from the Group OTCR. The primary purpose of this position to ensure that the management of ICS and Technology Risk is operating effectively and efficiently, providing assurance that the risks are appropriately managed. In addition, given the rapidly evolving ICS and Technology regulatory environment, the successful candidate will have a strong acumen for working with regulators and understanding relevant policies with an ability to articulate new requirements to be included in the ICS and Technology risk management process. Work closely with the rest of OTCR to address ICS and Technology Risk and support its integration into the Bank's overall Enterprise Risk Management. The role will be expected to focus on the following key risk activities: Regulatory Engagement o Regulatory obligations to be implemented at a local/country-level may emanate from both Extraterritorial Regulation (ETRs) and local regulatory authorities. The Country RFO is the Country Operational, Technology and Cyber Risk Head, (Country OTCR Head). o ICS and Tech Risk SME role is responsible for presenting and providing opinions on ICS and Technology risk to regulators. o T&O Coverage is consulted on risk opinions for ICS & Tech risk, to be shared with the regulator.

Requirements

  • Proven experience in an information security office, senior governance and policy, ICS/ Technology Risk or Operational Risk or Audit role
  • Thorough understanding of IT security business process risks, threats, and internal controls relevant for managing and mitigating risks.
  • Strong knowledge of cyber security and technology frameworks, information security principles, architecture.
  • Technical knowledge across a broad range of ICS and technology risk capabilities including Cyber Defence, Security Monitoring, Analytics, DLP, Access management, Cloud etc. etc.
  • Strong leadership, negotiation and collaboration skills, and ability to work effectively in a complex multicultural and multi-time zone organization.
  • Strong interpersonal and stakeholder management skills with experience across various levels in the organization including senior leadership teams, in influencing key decisions taken in the business and in support teams.
  • Ability to collect and analyse data, establish facts, and make recommendations based on sound risk management principles.
  • A passion for keeping technical knowledge and skills up to date and horizon scanning new and emerging thematic risks from new technology or techniques.
  • Ability to articulate inherent and residual risk with specific ability to communicate complex ICS, technology and process risk clearly, concisely, and accurately to non-technical stakeholders in a lucid way.
  • Must be a self-starter who is able to initiate and successfully drive initiatives to completion with little or no management supervision.
  • Degree in Cyber Security or Technology or equivalent

Nice To Haves

  • Professional certifications related to ICS and Technology risk are desirable (e.g., CCSP, CRISC, CISA, CISSP, CISM, GIAC etc).

Responsibilities

  • Review, challenge and (where relevant) approval on core ICS and Technology Risk matters that are not aligned to a specific business or function.
  • ICS and Technology Risk management and stakeholder engagement / escalation.
  • Approvals / veto on risk decisions within ICS and Technology Risk.
  • End-to-end oversight of risk performance for ICS controls and core Technology.
  • Interfacing with 1LoD (i.e. Principle Point of Contact) for ICS and core Technology.
  • ICS and Tech Risk SME role is responsible for presenting and providing opinions on ICS and Technology risk to regulators.
  • T&O Coverage is consulted on risk opinions for ICS & Tech risk, to be shared with the regulator.

Benefits

  • Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
  • Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
  • Flexible working options based around home and office locations, with flexible working patterns.
  • Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
  • A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
  • Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Director

Industry

Credit Intermediation and Related Activities

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service