Jobs and Careers
SU

Director, Information Security Functional Control Officer

Sumitomo Mitsui Banking Corporation
New York City, United Statesfull_timeVerifiedPosted 16 Jul 2024
💰 $240,000/yr($190,000/yr$240,000/yr)

About the role

 SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.

 

In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC Rail Services LLC, Manufacturers Bank, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.

 

The anticipated salary range for this role is between $190,000.00 and $240,000.00. The specific salary offered to an applicant will be based on their individual qualifications, experiences, and an analysis of the current compensation paid in their geography and the market for similar roles at the time of hire. The role may also be eligible for an annual discretionary incentive award. In addition to cash compensation, SMBC offers a competitive portfolio of benefits to its employees.

Job Summary

The Information Security Functional Control Officer (FCO) is a function-aligned change agent and risk management individual contributor.  The FCO provides the Information Security Functional Unit with guidance on processes and control design, ensures effective assessment of risk across the transaction lifecycle, and supports interaction with 2nd Line of Defense (LoD) functions including Risk Management and Compliance.

Scope

The Information Security Functional Control Officer is primarily an individual contributor, who will play a pivitol role for the full scope of Information Security processes & controls. This person will be reporting directly into the Head of Functions Controls Officer with a dotted line reporting structure into the head of the Risk & Controls Management tower of Information Security.

This individual may have 0-2 direct reports.

Primary Responsibilities

The job responsibilities are described herein:

  • Supports Information Security by providing expert guidance on assessment of processes and controls across the end-to-end transaction lifecycle, proactively assessing threats, vulnerabilities, and possibility of future incidents.
  • Performs process re-engineering to improve efficiency and strengthen controls within the Information Security Function.
  • Coordinates Information Security interactions with 2nd Line of Defense functions and the Audit & Regulatory Management team, pertaining to processes and controls.
  • Coordinates management of risk appetite, limits and guideline setting & issue management for the Information Security Function.
  • Supports and coordinates risk management framework and related risk assessements of Information Security.
  • Support 1st LoD via performance of issue management & root cause analysis.
  • Liaises between Information Security and control functions to support the execution on risk assessments (e.g., RCSAs), as required.
  • Partners with the Regulatory Change Management team to ensure that Information Security is operating in compliance with applicable laws, rules, and regulations, provides oversight of processes designed to comply with the aformentioned requirements.
  • Provides Information Security with SME knowledge and expertise in the implementation of their programs.
  • Support Information Security to assess key metrics and ensure operational effectiveness.
  • Ensures that risk management considerations are embedded in daily processes and business strategy; identifies and reports on new/emerging risks.
  • Creates production of management reporting and presents escalation items to Management committees.                                

Critical Job Knowledge and Core Competencies/Skills

  • Functional knowledge of process and control design, including process mapping and process reengineering.                                
  • Functional knowledge of risk assessment and issue management.                                
  • Functional knowledge of chang

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sumitomo Mitsui Banking Corporation

View company profile →