The Senior Manager Information Security manages / leads a team of Technology Controls / Information Security experts in the development and/ or management of relevant strategies, programs, tools, frameworks and policies and provides specialized oversight / control / governance activities for a key business line/segment or transformational (change the bank) strategic initiative / program, liaising across the organization and primarily interfacing with executive and/or functional stakeholders to minimize overall technology risks to the Bank for own area. Provides leadership, oversight, and execution management for the U.S. CISO Regulatory Remediation Assurance program, including objective 1B testing and challenge activities for regulatory remediation commitments, management action plans (MAPs), and associated corrective actions. Responsible for Gate 1 (Design Review), Gate 2 (Design Effectiveness and Operational Readiness), sustainability testing, and closure readiness assessments. Leads a team of Regulatory Remediation Assurance professionals responsible for developing testing strategies, reviewing remediation evidence, executing risk-based assurance testing, and producing defensible conclusions regarding remediation effectiveness and sustainability. Ensures consistent execution of testing standards, methodologies, and quality expectations across all assigned reviews. Reviews and approves all Regulatory Remediation Assurance testing results, observations, and conclusions. Provides objective challenge of remediation design and implementation, identifies potential control gaps, and escalates material risks, testing exceptions, and remediation concerns to U.S. CISO executive leadership and governance forums as appropriate. Partners closely with remediation owners, Enterprise Testing, CRQA, Internal Audit, Governance, Second Line of Defense, and Technology stakeholders to facilitate effective remediation oversight, promote transparency, and ensure testing activities are aligned with regulatory expectations and management commitments. Establishes and maintains forecasting, resource management, quality control, reporting, and governance processes to support the timely execution of assurance reviews and drive continuous improvement across the Regulatory Remediation Assurance program. Provides oversight and reporting on the status, results, observations, and emerging risks associated with Regulatory Remediation Assurance engagements, communicating key developments to U.S. CISO leadership, remediation stakeholders, and governance committees. Oversees the expanding U.S. CISO 1B Assurance Testing program, which is expected to expand to include and challenge of Critical and High-rated Internal Audit findings and Self-Identified (Self-ID) issues (in addition to regulatory remediation activities), applying a consistent risk-based assurance methodology to validate remediation design, implementation, effectiveness, and sustainability.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager