IT, Data and Cyber Risk Oversight Associate

Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of experience in financial services, focusing on IT risk management, control testing, regulatory/audit, or cybersecurity.
  • Familiarity with enterprise risk management concepts, including risk assessment and control design.
  • Working knowledge of technology, cyber, and data risk domains (e.g., SDLC, application security).
  • Understanding of industry frameworks and standards like NIST, ISO, and COBIT.
  • Strong organizational and communication skills, particularly in reporting and presentation to management.
  • Proficiency in Excel and PowerPoint; familiarity with Power BI or data visualization tools is a plus.
  • Bachelor's degree required; master's degree and relevant certifications (e.g., CISA, CRISC) preferred.

Responsibilities

  • Support TDCRO management in governance and control of IT and cybersecurity risks.
  • Conduct independent reviews and challenge assessments of 1st Line of Defense risk management processes.
  • Assist in updating the risk management frameworks, policies, and standards related to technology and data management.
  • Review and challenge IT and data management policies, risk metrics, and control frameworks.
  • Prepare risk reporting for management and committees, ensuring effective issue tracking and escalation.
  • Collaborate with diverse teams across risk, technology, cybersecurity, and data domains.

Benefits

  • Hybrid work model allowing employees to work remotely or from the office.
  • Opportunity for professional development and obtaining advanced certifications.
  • Engaging work environment with cross-functional collaboration opportunities.
Full Job Description
Role Description

The Risk Associate role supports the operationalization of the second line of defense Risk oversight of information technology, cybersecurity, and data risk for the SMBC Group Americas Division (AD) by performing independent review, effective challenge, and risk analysis in alignment with regulatory expectations, internal/head office policies, and industry standards.

The Risk Management Department (RMDAD) is the second line of defense in its role of monitoring and assessing business practices as related to the risk appetite framework for SMBC. Within the RMDAD, the Tech, Data and Cyber Risk Oversight (TDCRO) establish technology, data and cyber risk management policies and framework with defined roles and responsibilities across first and second lines.

Role Objectives: Delivery

Supports the TDCRO management in ensuring IT, data management, and cybersecurity risks are adequately governed, managed and controlled.

Supports the independent review and credible challenge of 1st Line of Defense risk assessments, controls, metrics, and remediation plans related to IT, data, and cyber risk domains.

Assist in the maintenance and periodic update of technology, data, and cybersecurity risk management frameworks, policies, standards, and procedures.

Provides review and challenge on IT, data management and cybersecurity policies, standards, control framework, risk metrics/indicators, risk and control self-assessment ("RCSA").

Support the preparation of technology, data, and cybersecurity risk reporting for management and risk committees, including issue tracking and escalation.

Collaborate with cross-functional stakeholders across risk, technology, cybersecurity, and data teams

Qualifications and Skills

Well-versed in technology & cyber risk practices with the ability to connect and align with the firm's operational risk management processes.

2+ years of direct work experience within the financial services industry, with IT risk management, control testing, regulatory/audit, or cybersecurity experience.

Foundational understanding of enterprise risk management concepts, including risk assessment, control design, issue management, and RCSAs.

Working knowledge across multiple technology, cyber, or data risk domains (e.g., SDLC, application security, Data Management, IT governance, infrastructure Architecture, IT asset management (incl. End of Life and Shadow IT), Infrastructure management application lifecycle management, change management, back-up and availability of critical systems, Service management, Event, Problem and incident management, Helpdesk, SLA- service quality, Cloud, ... ).

Familiarity with technology, cyber and data risk management industry frameworks and standards (e.g., NIST, ISO, COBIT).

Foundational knowledge of Tech/Cyber/Data Management regulatory guidance

Strong written communication skills, with experience supporting management or committee-level reporting.

Proficiency in Excel and PowerPoint; experience with Power BI or data visualization tools preferred.

Strong organizational skills with ability to successfully manage multiple, concurrent priorities.

Work effectively in a matrixed environment and across various organizational levels, where flexibility, collaboration, and adaptability are important.

Strong desire to deliver a quality work product in a timely and efficient manner.

Bachelor's/University degree required and Master's degree preferred.

CISA, CRISC, CISM, CISSP certifications (or exam taken) preferred.

SMBC's employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.

About Sumitomo Mitsui Financial Group, Inc.

Sumitomo Mitsui Financial Group, Inc. Careers

There has never been a more opportune time to join the dynamic team at Sumitomo Mitsui Financial Group, Inc. (SMFG)—a leading force in the financial services industry recognized for its leadership in innovation and diversity.

Explore Job Opportunities

Sumitomo Mitsui Financial Group, Inc. offers a plethora of job opportunities that cater to a variety of skills and interests. The company is renowned for its commitment to professional growth and leadership development, making it an ideal environment for ambitious individuals looking to advance their careers.

Experience Professional Growth

At SMFG, career advancement is not just a possibility but a priority. The company supports its team members with extensive training programs, including leadership development and diversity training, ensuring that every employee has the tools and knowledge necessary to succeed.

Join a Diverse and Inclusive Team

Diversity and inclusion are at the core of the company culture at Sumitomo Mitsui Financial Group, Inc. With a global team that values unique perspectives and fosters a collaborative and inclusive environment, SMFG is a place where everyone can thrive.

Internship Programs

For those starting their career journey, SMFG offers internship programs that provide a robust foundation in the financial sector. Interns gain invaluable experience, working alongside seasoned professionals and engaging in projects that offer real-world applications of their studies.

Benefits and Culture

Sumitomo Mitsui Financial Group, Inc. is dedicated to not only attracting but also retaining top talent by offering competitive benefits that enhance both personal and professional life. The company culture promotes work-life balance, employee well-being, and continuous learning.

Innovative Work Environment

Innovation is a key driver of SMFG’s success. Employees are encouraged to bring forward-thinking ideas to the table and are provided with the resources to transform these ideas into actionable solutions that drive the financial industry forward.

Networking and Career Development

Networking opportunities within SMFG are abundant. Employees are encouraged to connect with colleagues and industry leaders through various platforms and events, enhancing their professional network and opening doors to myriad career opportunities.

Apply for a Position

Sumitomo Mitsui Financial Group, Inc. is actively hiring and looking for talented individuals who are passionate, curious, and driven. Explore open positions that match your skills and interests on the SMFG careers page.

Stay Connected with SMFG Careers

Keep up to date with the latest career tips, industry insights, and company news from Sumitomo Mitsui Financial Group, Inc. Subscribe to receive updates and stay informed about new job openings and employment trends.

Prepare for Your Interview

Aspiring to join SMFG? Prepare your resume to reflect your best self and gear up for the interview process where you can showcase your skills and passion for finance and innovation.

Career Opportunities Await

At Sumitomo Mitsui Financial Group, Inc., the potential for professional development and personal growth is limitless. Discover the exciting and rewarding career opportunities that await at SMFG, where every position contributes to the company’s global success and leadership in the financial industry.
Learn more about Sumitomo Mitsui Financial Group, Inc.

Similar Jobs

More Jobs at Sumitomo Mitsui Financial Group, Inc.

More Finance & Insurance Jobs

Find similar IT, Data and Cyber Risk Oversight Associate jobs: