The position at a glanceThe role consists in coordinating / driving the remediation of Major Findings and key Internal Programs to reinforce our IT and Cyber procedures, governance & control framework among IT & Cyber departments within CIB Americas. This is a unique opportunity to work with a wide range of technology and business experts, to learn about IT Development, IT Production and Information Security best practices.
In detail The team member will be responsible for the following activities:
- Review the requirementsand/or identified findings and, in collaboration with the owner/implementation manager, define a remediation plan based on the assigned deadlines
- Present the remediation plan to senior management and obtain validation from the sponsors
- Drive the delivery of the remediation plans while updating ITO management with appropriate status reports highlighting key risks & issues.
- Meet with the stakeholders regularly and continuously check and challenge the deliverables from IT/IS in line with the validated requirements.
- Prepare the final reportor submission ensuring all evidence is complete and in line with the initial requirements, and coordinate the validation of the remediation and associated deliverables with the appropriate stakeholders
- Prepare the project closure with a recap of risks and control framework and communicate to Management.
- Analyze any relevant external standards and practices (i.e. FFIEC, NIST) to improve and propose enhancements to our internal frameworksContribute to the development and maintenance of local standards and methodologies for CIB Americas IT and Cyber
Staff supervision / Organizational Structure:
The Americas ICT Risk & 1LoD Reviews department covers 2 main areas:
- ICT Risk Management in charge of ICT Risk Governance, ICT Risk Monitoring & Reporting, and Regulatory exam support.
- ICT Controls, Assurance & Audit in charge of Audit coordination and Control assurance
The department reports to CIB AMERICAS ITO CCCO, and the team is fully integrated covering Americas scope across 2 locations in the US (Jersey City, NJ) and Canada (Montreal). This position is within the ICT Risk Management department, under the Remediation delivery & Regulatory exam support team.
The strengths and skills that will help you succeed- Bachelor or Master of Science / Engineering, ideally in computer science
- Any of the CRISC, CISA, CIA, CISM, CISSP, PMP Certifications are valued.
- Minimum of five (5) years recent experience in Information Technology audit or IT/Cyber Risk & Control/GRC
- Professional working proficiency in English language is required *
- Knowledge and experience in IT & Cyber risk & controls
- Knowledge of Information Technology and Information Security processes and practices within the financial services industry
- Familiarity with FFIEC IT Examination Guidelines (e.g., Development and Acquisition IT Handbook) and other major Cyber and Risk management industry frameworks
- Experience in managing high-end and strategic projects
- Excellent communication skills (verbal, written, presentation) and presentation skills to develop and deliver informative progress reports and proposals to senior stakeholders
- Ability to coordinate across multiple tasks and teams
- Ability to work independently, in a fast-paced environment and under pressure
- Ability to obtain buy-in, align multiple leaders from different opinions, and mediate among SMEs to find the best suitable solution.
- Ability to demonstrate tactical and strategic thinking, innovation, and creativity
- Exceptional analytical abilities and attention to detail (i.e., examine large volumes of data)
- Advanced knowledge of Microsoft Excel / PowerPoint / SharePoint / PowerBI / Power Automate.
*Given the vast majority of our clients, both internal and external, are based outside of Quebec and Canada, specific language requirements may apply. Professional working proficiency in English language is required.
What's in it for youIn addition to competitive compensation, we offer flexible benefits including a family and spouse insurance program, a defined contribution pension plan and paid days for volunteering. Hybrid work arrangements are available for most positions. In-office presence is required a minimum of 3 days per week, one of which must be on a Monday and/or a Friday. BNP Paribas provides excellent training and personal development programs, as well as opportunities for career development within the company and internationally.
To find out more about our range of benefits, click here
What you need to know- We will review candidates as they apply, so don't wait to submit your application;
- BNP Paribas is committed to accessibility and inclusion. During the recruitment process, accommodation needs are available at all times for candidates. You will have the chance to make a request for an accommodation during your application.
- You must be legally eligible to work in the Greater Montreal area and, if applicable, hold a valid work or study permit. Physical presence in BNP Paribas' office(s) is an essential function of this position;
- If you are applying and accepted to a position which requires working in/for the U.S. securities industry, you will be required to provide your fingerprints and undergo additional background checks by the FBI. BNP Paribas Securities Corporation is required to maintain a supervisory program over the conduct of its Associated Persons; some of your personal data will be transmitted to the United States of America and made available to US regulators. Please reach out to BNPP for additional information; or you can also find an overview here: 3110.Supervision FINRA.org
*** While the description above describes our ideal candidate, we encourage applicants to apply even if they do not fully meet the complete list of qualifications noted***