Aon is in the business of better decisions At Aon, we shape decisions for the better to protect and enrich the lives of people around the world. As an organization, we are united through trust as one inclusive, diverse team, and we are passionate about helping our colleagues and clients succeed. What the day will look like Policy & Standards Management Create, maintain, and govern technology policies, standards, and procedures in partnership with stakeholders. Ensure documentation is current, consistent, and aligned to organizational risk appetite and regulatory requirements. Drive periodic policy reviews, approvals, and communication across impacted teams. Provide guidance and interpretation of policies and standards to technology and business teams. Technology Controls & Assurance Design, implement, and maintain technology control library aligned to policies, frameworks, and regulatory expectations (e.g., access management, change management, incident management, data protection, resilience, etc.) Ensure critical systems and data are safeguarded, and controls are regularly reviewed for effectiveness and compliance Partner with Technology and Cybersecurity teams to remediate control gaps and strengthen the control environment. Coordinate and support internal/external audits, control testing, and assurance activities Track issues, findings, and remediation plans to timely closure, escalating when necessary Technology Risk Management Identify, assess, and monitor technology risks across applications, infrastructure, and services. Develop and maintain technology risk registers, ensuring risks are clearly documented, assessed, and tracked to remediation. Provide risk guidance for new initiatives, technology changes, and vendor engagements. Support the definition and monitoring of risk appetite, key risk indicators (KRIs), and metrics. Regulatory Governance & Compliance Monitor relevant regulatory requirements, industry standards, and best practices related to technology risk (e.g., cybersecurity, operational resilience, data protection). Support regulatory exams, inquiries, and responses for technology-related topics. Translate regulatory expectations into practical control and process requirements for technology teams. Prepare and deliver governance materials and risk reporting for senior management and governance forums/committees. Stakeholder Engagement & Governance Forums Partner with Technology, Cybersecurity, Compliance, Internal Audit, and Business stakeholders to align on risk priorities and remediation plans. Prepare clear, concise reporting on technology risk posture, key issues, and trends for leadership. Promote a risk-aware culture by providing training and guidance on technology risk, controls, and governance.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level