Risk & Controls Testing & Assessment, Assistant Vice President

Risk & Controls Testing & Assessment, Assistant Vice President

07 Mar 2024
New York, New york city 00000 New york city USA

Risk & Controls Testing & Assessment, Assistant Vice President

Do you want your voice heard and your actions to count?Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 7th largest financial group in the world. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.In this role you will focus on implementing frameworks designed to identify, evaluate, and manage technology-related risks and controls across the company or a particular business or function. Responsibilities include integrating that framework with business operations and keeping key stakeholders across the organization informed about new or existing technology assets and third-party vendor engagements; leading or supporting various programs, including risk and control self-assessment (RCSA), process, risk, and control, and other risk policies, standards, and processes.As part of an effective risk and control framework, Operations and Technology for the Americas (OTA) documents and executes risk and control assessments across processes related to Operations & Technology. There is a comprehensive coverage and joint accountability model that promotes early identification and assessment of operational and technology risk, effective design and evaluation of controls, and sustainable solutions to mitigate operational and technology risk. Control testing is an integral part of the bank’s compliance with policies and standards, identifying whether controls are operating as intended to mitigate associated risk.RESPONSIBILITIES

Support the execution and documentation of ITGC testing for in-scope processes across technology and First Line of Defense (FLoD) business units

Partner with stakeholders, including process owners and control officers, to document controls, enhance control language, and develop/maintain test scripts that validate controls are being performed in compliance with bank policies, procedures, and regulatory requirements to mitigate technology risk to the firm

Execute testing of ITGCs and application controls based on internal and industry standards and guidelines for design and effectiveness

Participate in technology walkthroughs for ITGCs and application controls and prepare meaningful documentation

Coordinate control testing activities, including logistical scheduling and document retrieval to support control testing in accordance with internal requirements

Provide project management support in tracking and coordinating the execution of policy and standards control testing activities

Liaise with risk assessment team and other stakeholders to ensure control testing is in alignment with broader risk assessment activities

Create synergies by identifying opportunities to repurpose control testing results to satisfy assessment requirements across the bank

Develop and distribute status reporting and communication related to control testing activities

Provide ongoing communication to internal stakeholders throughout the testing process to keep them apprised of progress and findings, escalating when appropriate

Prepare written reports that summarize the objectives, scope, findings, and conclusions for each assigned review

Support iterative review and challenge of assessment results, working with appropriate stakeholders across the lines of defense

Support adoption of automated ITGC testing platform by identifying controls for inclusion and respective prerequisites and logic for automated testing

Work collaboratively with risk and control team to execute against technology risk governance procedures

Coordinate required meetings, reviews, and scheduling needs

Prepare materials for ongoing team meetings and meetings with senior management

QUALIFICATIONS

Bachelor's degree in computer science, information systems, technology management, or equivalent preferred

Preferred: degree from a competitive school, demonstrating a strong academic and extracurricular track record

Preferred: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC)

5-6 years of experience in IT risk and controls

2-5 years of experience in IT risk and controls performing audit and control checks or implementation of control measures

At least 2 years of actual programming experience in Python, and/or Java virtual machine (JVM) languages (Java/Scala)

Experience in creating complex queries using structured query language (SQL)

Experience with process documentation, risk and control assessments, and designing/executing IT General Controls (ITGC) test scripts

Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations

Experience with problem solving in a team environment by thinking outside of the box and providing innovative solutions, with and without technology

Experience in working with multiple IT risk and control domains such as identity and access management, privileged success, vulnerability management, audit logging, privacy, data loss prevention, enterprise architecture, release management and incident response

Knowledge of test-driven development (TDD), behavior driven development (BDD), and/or domain driven design

Working knowledge of unit testing, continuous integration (CI)/continuous delivery (CD) and Jenkins

Experience and working knowledge of any NOSQL databases, design, and architecture

Combined experience in IT external audit, IT internal audit and technology risk and/or ITGC assessment for compliance with Sarbanes-Oxley (SOX)

Experience working in a full software development lifecycle using Agile project delivery

Experience in designing, implementing, and operationalizing continuous control testing and monitoring of technology controls

Preferred: knowledge in technology areas including, but not limited to: access management, network security, enterprise architecture, release management and incident response

Preferred: experience in a project management role

Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality

Ability to support work streams with sometimes limited oversight/information from inception to completion

Ability to identify obstacles and work in conjunction with others to identify options/solutions

Ability to constructively work both independently and in collaborative environments involving all levels of management and employees

Strong written and verbal communication skills to articulate information clearly and effectively

Strong analytical skills that can work with data, dashboards, and reporting

The typical base pay range for this role is between $80K–$100K depending on job-related knowledge, skills, experience, and location. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays.For more information on our Total Rewards package, please click the link below.MUFG Benefits Summary (https://careers.mufgamericas.com/sites/default/files/document/2023-01/mb-live-well-work-well.pdf)The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.#LI-HybridAt MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!Our Culture Principles

Client Centric

People Focused

Listen Up. Speak Up.

Innovate & Simplify

Own & Execute

Related jobs

  • USA 100% remote; full-time / permanent. In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity-not just answers-in all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll, you\'ll contribute to a supportive and collaborative work environment that empowers you to excel. Through a combination of subject matter expertise, global research capabilities and flexible technology tools, Kroll helps clients take a risk-based approach toward meeting obligations or remediating failures regarding cybersecurity, privacy program maturity and related regulatory mandates. Our engagements include Virtual CISO, transactional due-diligence, framework assessments, expert testimony, privacy program building and a myriad of other advisory efforts.RESPONSIBILITIES: Kroll\'s Cyber Risk team works on over 3, 000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client\'s data, people, operations and reputation with innovative assessments, investigations and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience. We are looking for bright, inquisitive minds who are experienced in and passionate about cybersecurity consulting and advisory services. Our Advisory team responds to our Client\'s needs and provide leadership and strategic guidance when and where it is needed the most.

  • Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating new and emerging risks, and using your expert judgement to solve real-world challenges that impact our company, customers and communities. Our culture in Risk Management and Compliance is all about thinking outside the box, challenging the status quo and striving to be best-in-class.

  • Assistant Vice President, Administrative Operations

  • Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating new and emerging risks, and using your expert judgement to solve real-world challenges that impact our company, customers and communities. Our culture in Risk Management and Compliance is all about thinking outside the box, challenging the status quo and striving to be best-in-class.

  • Assistant Vice President Commercial

  • Our Treasury & Trade Solutions and Securities Services businesses provide global solutions that can help clients drive their business forward while investing in innovation to bring new solutions to life. As new technologies open up new opportunities for us to serve our clients, Treasury and Trade Solutions invests in innovation to bring new solutions to life by establishing a digital future through building on a strong legacy of innovation and a unique global trade solution network.

  • Examine and evaluate internal controls in key technology risk areas to ensure compliance with internal policies and applicable rules, laws, and regulations. Execute audit strategies for technology areas by developing audit programs and performing audit fieldwork, including system documentation, evaluations, interviews, and technical analysis for applications. Identify control deficiencies and propose appropriate corrective measures designed to strengthen internal controls, operational and technical policies and procedures, and other weaknesses identified during audits. Lead the preparation of clear and concise audit work-papers and IT audit reports summarizing scope, methodology, and significant conclusions of audit procedures performed within prescribed time frames. Conduct audit planning and closing meetings with Internal Audit Management, focusing on IT and financial service applications, and communicate results of the audits to both audit and client management. Identify potential IT issues and their risk levels, provide remedial recommendations, and develop action plans to mitigate risk. Requirements:Master’s degree in Computer Science, Information Systems, or closely related field, plus three years of experience in the position offered or as IT Audit Manager or IT Audit Senior Manager.One year of the required experience must have included participating in and project managing technology audits including risk assessments, audit planning, audit testing, control evaluation, report drafting, and follow up and verification of issue closure; knowledge of SDLC concepts, financial services, financial reporting, change management, incident management, identity and access management; applying professional standards including IIA, ISACA, and SSAE 16; knowledge of COBIT and controls around third-party governance and oversight; reviewing ITGC and controls around information security to perform IT risk identification, IT risk assessment, risk response mitigation, and risk and control monitoring reporting; and working with MS Excel, MS PowerPoint, and cloud computing in a complex distributed computing environment. This role entails hybrid work, with time split between working in our New York, NY office and flexibility to telecommute from another U.S. location.

Job Details

Jocancy Online Job Portal by jobSearchi.