Duties:
Provide critical support to the Director of Operational Risk to evaluate IT and Security risks by assisting with risk assessments and applying aspects of the risk management framework across the process, risk, and control universe. Collaborate with IT, Security, TPRM, Legal, Compliance, and Internal Audit to ensure that ORM contributes to strengthening the overall effective management of IT and Security risk across the organization. Lead the OCC’s risk identification and assessment process (Risk Intake) for IT, Security and business risks, and verify the consistency and reliability of the associated frameworks and systems. Drive adherence to methodologies, guidance, and standards applicable to risk identification and assessment frameworks. Maintain risk inventories, taxonomies, and other elements supporting IT & Security risk management and compliance activities. Lead and execute the IT and Security risk assessment process, while aligning to the risk and control universe, and regulatory requirements and expectations. Execute risk identification, analysis, and enterprise risk assessments to verify consistency and reliability with NIST and COBIT frameworks and align with regulatory requirements by leveraging RSA Archer, JIRA, and ServiceNow. Develop Artificial Intelligence governance assessment protocols encompassing onboarding risk analysis, control gap evaluations, and continuous monitoring, and create AI risk registers aligned to NIST AI Risk Management Framework using RSA Archer, JIRA, and ServiceNow. Audit technology program utilizing Distributed Ledger Technology (DLT), assessing functional and non-functional requirements traceability, vendor entitlement configurations against contractual obligations, and architectural integration risks of DLT into existing clearing and settlement environments using SpiraTest, SailPoint, and RSA Archer. Administer and review Identity and Access Management (IAM) controls and access governance processes, including Role-Based Access Control (RBAC), user access reviews, entitlement reviews, least-privilege controls, and group-based access policies, using IAM tools such as Microsoft Active Directory, ManageEngine ADManager Plus, and Microsoft 365 Admin Center. Communicate results of risk assessments to governance committees, business owners, and various levels of leadership. Collaborate on the enhancement and maintenance of ORM program methodologies, policies, procedures, and job aides, including the development of new program activities. Track and update ORM team internal findings, external exam issues, and business area self-identified issues resulting from Enterprise Risk Assessment. Up to 40% telecommuting permitted. OCC offers a standard benefits package.*This position qualifies for The Options Clearing Corporation’s Employee Referral Program.*
Education & Experience Required:
Bachelor’s degree in computer science, information systems, business information technology, or related and three (3) years of experience as an operational risk management associate, security intern, project manager, or related
Special Skills Required:
Must have work experience with each of the following: 1) Execute risk identification, analysis, and enterprise risk assessments to verify consistency and reliability with NIST and COBIT frameworks and align with regulatory requirements by leveraging RSA Archer, JIRA, and ServiceNow; 2) Develop Artificial Intelligence governance assessment protocols encompassing onboarding risk analysis, control gap evaluations, and continuous monitoring, and create AI risk registers aligned to NIST AI Risk Management Framework using RSA Archer, JIRA, and ServiceNow; 3) Audit technology program utilizing Distributed Ledger Technology (DLT), assessing functional and non-functional requirements traceability, vendor entitlement configurations against contractual obligations, and architectural integration risks of DLT into existing clearing and settlement environments using SpiraTest, SailPoint, and RSA Archer; and 4) Administer and review Identity and Access Management (IAM) controls and access governance processes, including Role-Based Access Control (RBAC), user access reviews, entitlement reviews, least-privilege controls, and group-based access policies, using IAM tools such as Microsoft Active Directory, ManageEngine ADManager Plus, and Microsoft 365 Admin Center. Up to 40% telecommuting permitted.
Salary
$106,808-$120,000
Apply:
OCC offers a standard benefits package. See a full list of benefits here: . Apply online at www.theocc.com. No calls.