The position at a glanceThe CIB Americas ICT Risk & 1LoD Reviews team is seeking an experienced candidate with in-depth knowledge and experience in IT & Cyber Risk & Controls to join their team. The successful candidate will be responsible for coordinating audit reviews while also assisting in the management of risk, and controls for the key IT & Cybersecurity activities
In detailThe new team member will be responsible of the following activities:
• Coordinating audit reviews (Internal & external reviews and regulatory exams) with a focus on ensuring auditors' expectations are addressed
• Monitoring the remediation around control weaknesses to ensure appropriate and timely resolution, confirming that corrective actions meet policy standards.
• Assist IT & Cyber teams in identifying risks, assess risks and implement proactive framework for identification and remediation (advisory role)
• Ensure IT & Cyber Risks have been identified for the IT & Cyber Processes, mapped to controls and the controls address the risk (Risk Card review / C&C)
• Monitor and Report IT & Cyber Risk and the risk treatment (i.e., risk mitigation / acceptances) status to Management.
• Assist IT & Cyber in developing remediation action plans associated to documented risk (Risk Card), documenting them in the self-identified action plan book of record (Risk360), and tracking them until completion.
• Assist in RCSAs exercises and provide control results for the execution of the ICT RCSAs for South Americas.
• Document, maintain and communicate the Americas IT & Cyber Risk Management Program (procedure and documentation for Risk Management, SIAP and Shadow)
• Ensure the Americas IT & Cyber Risk Management Program continues to be aligned with Regulatory, Group / Global and Local IT & Cyber Risk Management programs.
• Ensure the IT & Cyber Teams adhere to the Americas IT & Cyber Risk Management Program
• Keep up with the established Global IT & Cyber Risk Management Framework
The strengths and skills that will help you succeed• Bachelor or Master of Science / Engineering, ideally in computer science
• Any of the CRISC, CISA, CIA, CISM, CISSP, PMP Certifications are valued.
• Minimum of 5 years of recent experience in Information Technology audit or IT/Cyber Risk & Control/GRC
• Professional working proficiency in English language is required. Spanish is a plus *
• In-depth knowledge and experience in IT & Cyber risk & controls
• In-depth knowledge of Information Technology and Information Security processes and practices
• Familiarity with FFIEC IT Examination Guidelines (e.g., Development and Acquisition IT Handbook) and other major Cyber and Risk management industry frameworks
• Breadth of knowledge in the financial services industry with transversal knowledge of a wide range of banking products, processes, and application
• Ability to recognize and evaluate deviations from good business practices, policies, and procedures
• Strong organization and teamwork skills
• Excellent communication skills (verbal, written, presentation) and presentation skills to develop and deliver informative progress reports and proposals
• Ability to manage and multi-task to coordinate across multiple simultaneous projects and teams
• Ability to work independently
• Ability to demonstrate business tactical and strategic thinking, innovation, and creativity
• Exceptional analytical abilities and attention to detail (i.e., examine large volumes of data)
• Comfort in discussing IT & Cyber Controls with bank's management
• Advanced knowledge of Microsoft Excel / PowerPoint / SharePoint / PowerBI.
• CISA (Certified Information Systems Auditor) a plus
• CISM (Certified Information Systems Manager), and/or CISSP (Certified Information Systems Security Professional) a plus
*Given the vast majority of our clients, both internal and external, are based outside of Quebec and Canada, specific language requirements may apply. Professional working proficiency in English language is required.
What's in it for youIn addition to competitive compensation, we offer flexible benefits including a family and spouse insurance program, a defined contribution pension plan and paid days for volunteering. Hybrid work arrangements are available for most positions. In-office presence is required a minimum of 3 days per week, one of which must be on a Monday and/or a Friday. BNP Paribas provides excellent training and personal development programs, as well as opportunities for career development within the company and internationally.
To find out more about our range of benefits, click here
What you need to know- We will review candidates as they apply, so don't wait to submit your application;