GRC Manager - Associate

SMBCCharlotte, NC
Hybrid

About The Position

SMBC Group is a top-tier global financial group with a 400-year history, headquartered in Tokyo. It offers diverse financial services and has a significant global presence. In the Americas, SMBC Group operates across several countries, providing commercial and investment banking services. The Audit & Regulatory Management (ARM) team at JRI-A is seeking an ARM Manager to specialize in managing audit and regulatory requirements for the Information Security team. This role involves a hands-on approach to independently execute the ARM process, coordinating and facilitating audit requests and issue management from start to finish. The ARM Manager will lead audits or sections of larger audits, manage issue closure, and serve as the primary point of contact for these processes. Key responsibilities include managing all audit requests, ensuring timely and accurate artifact gathering, tracking responses, and managing stakeholder relationships. This is not an auditor role, but prior experience as an auditor or assessor is a plus.

Requirements

  • Bachelor’s degree in Information Technology, Information Security, or related field.
  • 5 plus years of IT audit (Big 4 preferable), assurance, or consulting experience.
  • Designations in the information security and IT risk fields such as CISA, CISSP, CISM, CRISC.
  • Strong knowledge of General IT Controls, risk, and best practices, especially in relation to Information Security.
  • Strong knowledge of IT Auditing - the core concepts, audit process, types of audits.
  • Strong knowledge of Cyber Security regulations (e.g., NYS DFS Cybersecurity, GDPR, FCA) and information security best practices and industry frameworks (e.g., ISO27002, FFIEC, NIST).
  • Detailed, thorough, diligent technical ability, with good analytical skills, a customer service mindset.
  • Strong written, verbal, and interpersonal communication skills; must be able to clearly articulate a point and be a persuasive communicator.
  • Ability to demonstrate a self-motivated and disciplined approach to learning and working.
  • Ability to display initiative and innovation; independently manage ARM assessments, including all related ARM activities from start to finish.
  • Ability to take ownership of complex tasks, drive projects forward for timely completion.
  • Excellent time management skills; should be able to prioritize, multitask, and manage multiple projects simultaneously.

Nice To Haves

  • Individuals with an auditor/assessor or similar background would be a plus.

Responsibilities

  • Lead role for a single audit or full responsibility for multiple sections across a group of audits.
  • Responsible for the coordination and facilitation of the audit and issue closure from start to finish, ensuring the process is efficient and well-coordinated.
  • Actively manage all audit requests and evidence review and challenge, ensuring right artifacts are gathered and audit requests are tracked and responded to on time.
  • Responsible for the assigning and reviewing of work of junior team members and timely escalation to ensure deliverables stay on track.
  • Manage the facilitation and coordination of audit request and issue management activities, including interviews, documentation requests, artifact requests and review, logistical support for walkthroughs/meetings, facilitating follow-up queries with various stakeholders, reviewing Issue Closure Packs, and facilitating management review and approval.
  • Communicate effectively and timely with auditors to affirm their understanding of controls and ensure audit testing is effective, requests are appropriate and clear.
  • Clearly explain requests to Evidence Providers and Control Owners, outlining risks and controls being tested, and assisting them to ensure the correct artifact is provided.
  • Articulate to auditors and stakeholders the key controls in place and identification of compensating controls, and be able to defend and advocate for these controls.
  • Manage preliminary audit findings by engaging with auditors early to ensure completeness and accuracy of understanding.
  • Review preliminary findings for plausibility and reasonability, engaging with Control Owners, Senior Management, and Relevant Subject Matter Experts.
  • Provide further information or evidence to the auditor which may result in the preliminary finding being revised or removed.
  • Assist Service Providers and Control Owners in drafting formal management responses to confirmed findings for Information Security management review.
  • Manage and track audit issues to closure per action milestones, providing periodic status updates to Information Security Management.
  • Maintain the ARM Evidence Repository, enabling evidence to be leveraged for similar audit requests across the firm.
  • Promote the use of the central ARM tool, providing information to maintain up-to-date audit status.
  • Review dashboard metrics to ensure information is up-to-date and accurate for ARM Management and Information Security Management.
  • Take an active role in projects designed to expand and ensure continuous improvement in the ARM Program, leading certain aspects of the project.
  • Take ownership for directing the ARM Specialist and ARM Senior Specialist in the performance of their tasks.
  • Ensure adherence to the ARM Process and Standards.
  • Work with the ARM team to continuously identify areas for improvement, document, and implement these.
  • Share best practices of ARM activities and processes with the ARM team and take a lead role in rolling out improved processes.
  • Ensure documentation is up-to-date.
  • Create professional training materials on ARM Process and Tools and lead initiatives to educate Information Security team members by conducting classes and socialization meetings.
  • Provide direction to ARM Specialist and ARM Senior Specialist in the assignment and completion of audit requests.
  • Complete independently ARM activities requested by management, clients, auditors, and regulators.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service