Jobs and Careers
SA

USA Sr. Analyst, Technology Risk

Santander
REMOTE - Georgia, United StatesRemotefull_timeVerifiedPosted 22 Oct 2024
💰 $87,500/yr($50,625/yr$87,500/yr)

About the role

USA Sr. Analyst, Technology Risk

Country: United States of America

Job Description - Senior Analyst, Technology Risk Management

USA Job Family Description: Monitors activities to minimize the company's exposure to technology and information risk. Activities may include technical risk analysis, risk identification and remediation. Represents or supports the reputation of the company to minimize compliance and regulatory risk by resolving issues and ensuring adherence to regulatory requirements, industry good practice frameworks and company and legal standards. Responsible for ensuring that all of the company's activities adhere to the necessary rules and regulations, and that the company complies with legal/regulatory statutes and jurisdictions.

USA Job Function Description: The Senior Analyst, Technology Risk Management within the Technology and Information Risk Management organization reports to the Senior Director or Director and is responsible for ongoing oversight, assessment, management and reporting of technology and cybersecurity risks across all operating entities. This role is established in the second line of defense and requires collaboration across IT, CISO, Data Office, Operational Risk, Internal Audit and other relevant functional stakeholders within the organization in the management of Technology risks. A good understanding of the evolving regulatory landscape in the US and EU are vital for success in this role.

The day-to-day focus may vary depending on the requirements of the overall second line of defense program priorities directed by the Head of Technology Risk and may include: planned or ad-hoc technical risk reviews, review of risk and technical control assessments, review and challenge activities of IT or Business initiatives, Risk reporting, development as well as review and challenge of technical risk framework and methodologies.

Essential Functions/Responsibility Statements:

  • Identify and assess technology risks to ensure awareness and accountability for their management.
  • Analyze IT risk data from various sources (e.g. external events, control deficiencies, risk register etc.) to identify and measure levels of risk, concentration, trends and patterns; drive automation, risk analytics & aggregation and risk visualization.
  • Execute independent testing and assurance of technical domains.
  • Support process for constructive engagement across the Lines of Defense regarding risk appetite, risk metric determination or evaluation, issue management and action plans.
  • Participate in evaluation of new products / Business changes / projects and assess related technology risks and impact to the technology risk profile.
  • Participate in the evaluation and management of risks related to third-party suppliers involved in technology projects.
  • Perform review and challenge of first line of defense risk management processes, data and outcomes (e.g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.).
  • Prepare information to enable governance committees / working groups in the management oversight of technology risks.
  • Researches a wide variety of topics and issues including emerging risks and trends and risk management best practices; summarizes and communicates observations internally to the team.

Qualifications: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education:

  • Bachelor's Degree in a technical discipline or equivalent work experience: Computer Science, Information Technology, Information Systems, Information Security. Req
  • Master's Degree in related technical disciplines. Pref
  • Professional Certifications in one or more domains of technical expertise. Req.

Work Experience:

  • Practitioner experience in Technology or Cybersecurity risk management with an ability to perform technical risk assessments, identify and assess risks, document findings and opinions, and develop risk reporting.
  • Good understanding of regulatory requirements e.g. FFIEC, FDIC, OCC requirements and industry frameworks and practices e.g. COBIT, ITIL , ISO, NIST 800-53, CSA-CCM v4, Fed Ramp, CIS Benchmarks.
  • Overall professional experience of 3+ years or more in technology risk audit & assurance or technology risk management role or a Governance, Risk & Controls role in a matrix organization.
  • Experience within a highly regulated environment such as the financial services industry (Pref)

<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Santander

View company profile →