Identity Access Operational Risk & Control Senior Manager
Sia PartnersAbout the role
Company Description
Sia Partners is a next-generation management consulting firm. We offer a unique blend of AI and design capabilities, augmenting traditional consulting to deliver superior value to our clients. Counting 3,000 consultants in 19 countries, we expect to achieve USD 420 million in turnover for the current fiscal year. With a global footprint and expertise in more than 30 sectors and services, we optimize client projects worldwide. Through our Consulting for Good approach, we strive for next-level impact by developing innovative CSR solutions for our clients, making sustainability a lever for profitable transformation.
Why Join The Sia Village?
Excellence | Entrepreneurship | Innovation | Teamwork | Care & Support | Employee Wellbeing
These are the six core values that guide all our actions. As an expression of our values, our Sia Village concept describes our commitment to fostering a sense of community within and among our offices. We believe that knowledge sharing is the key, not only to innovation, but to the growth and development of our people.
Your experience at Sia Partners will be enriched by a(n):
- Entrepreneurial journey
- Career advocacy program that supports achieving professional development goals through guidance, and real-time feedback
- Continuous learning & development opportunities
- Diversity, equity, and inclusion programs with an ever-growing list of global affinity initiatives
Job Description
Business Expertise Skills
- Support practice, thought leadership, and people development activities firmwide
- Cultivate knowledge related to a specific business challenge, issue, or deepen understanding within a sector and function domain
- Share experiences related to business issues and demonstrate a capacity for knowledge transfer amongst peers and junior staff
- Understanding of frameworks, including: NIST CSF v1.1 and v2.0, NIST 800-53, ISO 27001, etc.
Experience with regulatory frameworks including NYDFS 500 and FRB FFIEC
Understanding of IAM / PAM governance frameworks and policies and control frameworks
Experience with implementing Zero Trust, RBAC, authentication and authorization protocols including MFA and SSO, privileged accounts, recertification, etc.
- Risk Control Framework Development:
- Design, implement, and continuously enhance comprehensive risk control frameworks tailored to the specific needs of the client organization(s).
- Collaborate with key stakeholders to ensure alignment with business objectives and regulatory requirements.
- Familiarity with RCSA (Risk and Control Self-Assessment) methodologies and execution
- Risk Identification and Assessment:
- Conduct thorough assessments to identify operational risks across various business units and processes.
- Control Implementation and Monitoring:
- Oversee the implementation of risk controls, including policies, procedures, and automated tools.
- Establish key performance indicators (KPIs) and metrics to monitor control effectiveness and compliance with established standards.
- Risk Mitigation Strategies:
- Develop and implement strategies to mitigate identified risks, including control enhancements, process improvements, and training initiatives.
- Provide guidance and support to business units in implementing risk mitigation measures.
- Regulatory Compliance:
- Stay abreast of regulatory requirements and industry best practices related to operational risk management and control frameworks.
- Ensure that risk control practices align with relevant regulations and standards.
- Regulatory familiarity with NYDFS 500 and FRB FFIEC
- Risk Reporting and Communication:
- Prepare and disseminate regular reports on operational risk exposures, control effectiveness, and mitigation activities to senior management and relevant stakeholders.
- Communicate complex risk concepts in a clear and concise manner.
- Risk Culture Promotion:
- Foster a strong risk-aware culture within the organization by promoting the importance of risk management and control practices.
- Provide training and awareness programs to employees on risk identification, assessment, and control techniques.
- Nice to have: Strong understanding of NIST, ISO 27001
Consulting Skills
- Client delivery as part of an on-site or remote project team
- Demonstrate the capacity to plan assigned work and identify priorities/interested parties of the project/assignment, conducts regular points of progress
- Present complex ideas, critical points and decisions req
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s