Jobs and Careers
SU

GRC Sr Manager - Vice President

Sumitomo Mitsui Banking Corporation
Irelandfull_timeVerifiedPosted 12 Dec 2025

About the role

<p>SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.</p> <p> </p> <p>In the Americas, SMBC Group has a presence in the US, Canada, Ireland, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.</p> <h2>Role Description</h2> <p>SMBC is seeking a Cyber Governance, Risk and Compliance professional with 7+ years of experience and strong professional background in Cybersecurity/Information Security and Information Technology audit execution and coordination, controls governance, design, and operation, as well as a deep understanding of Governance Risk and Compliance programs and is interested in further developing their career with a fast growing and leading global bank. This role reports to the Director of Governance, Risk and Compliance (Information Security).</p> <p> </p> <p>This role is hybrid, requiring 2-3 days of the week to be conducted from the Tralee, Ireland office.</p> <p> </p> <p>The candidate would support the GRC Team: Audit and Regulatory Management (ARM). As a VP on the ARM Team, the candidate will primarily be leading the successful coordination of various assessments or assessment activities on behalf of Cybersecurity. These assessments may include, but are not limited to: Internal Audits, External Audits, Compliance Reviews, as well as US State, US Federal, and other Region-specific Regulatory Exams that SMBC must comply with regularly. The ARM VP will serve as a primary liaison between Cybersecurity and its assessors through the management of issue reporting, audit remediation activities including validation efforts, and the intendent evaluation of control design and operating effectiveness prior to the delivery of evidence to the assessors.</p> <p> </p> <p>Please note this is NOT an auditor role, the ARM Team is a Cybersecurity function reporting through to the SMBC CISO. However, individuals with certifications or professional experience as an IT/Cyber/InfoSec auditor or similar background would be notable candidates.</p><h2>Role Objectives</h2> <ul> <li>Lead role for a portfolio of assignments; Lead the successful coordination of various assessments or assessment activities on behalf of Cybersecurity. These assessments may include, but are not limited to: Internal Audits, External Audits, Compliance Reviews, as well as US State, US Federal, and other Region-specific Regulatory Exams’; Familiarity with controls testing program delivery, including conducting walkthroughs, and supporting design and operating effectiveness testing. Enhance coordination efforts each year ensuring inefficiencies identified in previous years are actively addressed and improved. Direct &amp; provide guidance to other members of the ARM team in the performance of their tasks .</li> <li>Collaborate closely with key stakeholders across the 2LoD (Operational Risk) and 3LoD (Internal Audit) as they undertake assessment / audits over Information Security controls;  Communicate effectively and timely with auditors where necessary to affirm their understanding of controls in place to ensure the audit testing approach is effective and their requests are appropriate and clear. Able to confidently &amp; clearly articulate to auditors / stakeholders controls in place and identification of compensating controls; In turn be able to clearly explain the request to Evidence Providers or Control Owners outlining the risks controls being tested assisting them where necessary to ensure the correct artefact is provided (Please note this is NOT an auditor role – The  Cyber Governance, Risk and Compliance Manager will serve as the liaison with the Assessors )</li> <li>Collaborate with stakeholders to identify continuous improvement opportunities in Controls, Processes and Procedures. Assist ARM Leadership to strategically manage and develop the ARM program.</li> <li>Engage with auditors at early stage in preliminary findings to ensure c

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sumitomo Mitsui Banking Corporation

View company profile →