The position at a glanceThe CIB Americas AMER ICT Control, Assurance & Audit team is seeking an experienced candidate with in-depth knowledge and experience in IT & Cyber risk & controls to join their team. The successful candidate will be responsible for coordinating assurance reviews, monitoring remediation of control weaknesses, reviewing control documentation, and providing recommendations to improve quality of control and overall risk posture.
In detail- Performs quality assurance assignments on IT and IS topics to ensure technological processes align with corporate standards.
- Conducts risk assessments in collaboration with stakeholders to evaluate and document potential threats for the control remediation roadmap.
- Reviews control documentation against corporate policies to identify gaps and recommend necessary enhancements.
- Monitors the remediation of control weaknesses to confirm that corrective actions meet policy standards and are resolved in a timely manner.
- Analyzes medium to large data sets to verify that controls are functioning effectively as documented.
- Facilitates process improvement initiatives by mapping workflows and delivering a prioritized roadmap to resolve identified pain points.
- Implements a continuous improvement feedback loop by collecting lessons learned to prevent the recurrence of identified control gaps.
- Interacts with IT Risk Management and auditors to advise on the execution and closing criteria of new findings.
- Provides reasoned advice to management regarding internal controls to elevate the efficiency of the bank's risk posture.
Staff supervision/ Organizational Structure:
The successful candidate will be part of a geographically distributed team across New York, New Jersey, Montreal, São Paulo, and Mumbai.
The strengths and skills that will help you succeed- Master Degree in Computer Science or related field
- CISA, CISM, and/or CISSP
- The knowledge of English is required.*
- Minimum of five (5) years recent experience in Information Technology audit or IT/Cyber Risk & Control/GRC
- In-depth knowledge of IT & Cyber risk and controls when evaluating organizational security posture
- Reasoned evaluation of deviations from good business practices, policies, and procedures to maintain compliance
- Collaborative teamwork and interpersonal skills when working within geographically distributed teams
- Responsible multi-tasking to coordinate across multiple simultaneous projects and teams
- Commited communication skills for discussing IT & Cyber controls with bank management and stakeholders
- Advanced Microsoft Excel, PowerPoint, and SharePoint skills for data analysis and reporting
- Familiarity with FFIEC IT Examination Guidelines to ensure regulatory alignment
- Familiarity with Windows and Unix operating systems, middleware, networks, and databases to support technical assessments
*Given the vast majority of our clients, both internal and external, are based outside of Quebec and Canada, specific language requirements may apply. Professional working proficiency in English language is required
What's in it for youIn addition to competitive compensation, we offer flexible benefits including a family and spouse insurance program, a defined contribution pension plan and paid days for volunteering. Hybrid work arrangements are available for most positions. In-office presence is required a minimum of 3 days per week, one of which must be on a Monday and/or a Friday. BNP Paribas provides excellent training and personal development programs, as well as opportunities for career development within the company and internationally.
To find out more about our range of benefits, click here
What you need to know- We will review candidates as they apply, so don't wait to submit your application;