Public Cloud Risk and Controls Analyst Lead
SynechronAbout the role
We are
At Synechron, we believe in the power of digital to transform businesses for the better. Our global consulting firm combines creativity and innovative technology to deliver industry-leading digital solutions. Synechron’s progressive technologies and optimization strategies span end-to-end Artificial Intelligence, Consulting, Digital, Cloud & DevOps, Data, and Software Engineering, servicing an array of noteworthy financial services and technology firms. Through research and development initiatives in our FinLabs we develop solutions for modernization, from Artificial Intelligence and Blockchain to Data Science models, Digital Underwriting, mobile-first applications and more. Over the last 20+ years, our company has been honored with multiple employer awards, recognizing our commitment to our talented teams. With top clients to boast about, Synechron has a global workforce of 14,500+, and has 58 offices in 21 countries within key global markets.
Our challenge
We are looking for a highly skilled candidate who would Identify risk, assess residual risk, and coordinate Corrective Action Plan (CAP) completion through collaboration with information security and engineering teams Negotiate with IA (Internal Audit; Third Line of Defence) and ORM (Operational Risk Management; Second Line of Defence), and with Policy Owners when more cloud-friendly policy changes need to be influenced.
Additional Information*
The base salary for this position will vary based on geography and other factors. In accordance with law, the base salary for this role if filled within Irving, TX is $130k - $140k/year & benefits (see below).
The Role
Responsibilities:
- Advise engineers on application of Policy across multiple concurrent technology domains such as compute, container, DB, middleware, etc.
- Research origins of Policy in Regulations collaboratively with ICRM (Independent Compliance Risk Management)
- Engage with and lead advocacy efforts with regulators in Asia and EMEA on Public Cloud in partnership with Government Affairs and Regulatory Engagement teams.
- Design processes for building and maintaining services in Public Cloud with control in mind
- Maintain continual assessment of Management Controls Assessment (MCA) Efficacy for Public Cloud
- Monitor exceptions to dispute policy and identify common root causes of exceptions.
- Leverage data to examine impacts to Customer Experience and Regulatory breaks.
- Appropriately assess risk and demonstrate consideration for the firm's reputation and safeguard Citigroup, its clients, and assets, by:
- Driving compliance with applicable laws, rules and regulations
- Adhering to Policy
- Applying sound ethical judgment regarding personal behavior, conduct and business practices
- Escalating, managing, and reporting control issues with transparency
- Influence Application Teams on best practices for MCA
Requirements:
You are:
- Undergraduate degree in related field or equivalent experience
- 7+ years relevant work experience in Technology Risk & Controls in a large organization in a heavily regulated industry
- 3+ years relevant work experience in Public Cloud Technology (Amazon Web Services, Google Cloud Platform, Snowflake, MongoDB Atlas, Azure, etc.)
- MS Excel required. MS Access, SQL a plus.
- Consistent, clear, and concise written communication skills
- Ability to explain concepts consistently to stakeholders, including non-technical audiences
- Ability to firmly communicate the requirements and position of Policy that must be satisfied
- Ability to see the big picture with high attention to critical details
- Demonstrated ability to develop and implement strategy and process improvement initiatives
- Demonstrated ability to influence change and common-sense approaches to modern risk complexity
- Demonstrable interest in Public Cloud risk identification and mitigation
- Strong collaboration and interpersonal skills.
It would be great if you also had:
- Experience working directly with regulators of the financial industry in Asia regionally, or Singapore locally.
- Risk certifications such as the CIA, CISSP, CISA, CRISC, CGEIT, CDPSE, etc.
- Certifications in Public Cloud such as AWS Certified Cloud Practitioner, or AWS Certified Security Specialty
- Experience working with NIST, COBIT, ITIL, CSA, and/or ISO risk and ITSM frameworks
- Experience in an influence management discipline such as project management or prod
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s