Risk Controls Self-Assessment (RCSA) Control Owner – Insider Threat
BNYAbout the role
Risk Controls Self-Assessment Control Owner – Insider Threat
At BNY, our culture empowers you to grow and succeed. As a leading global financial services company at the center of the world’s financial system we touch nearly 20% of the world’s investible assets. Every day around the globe, our 50,000+ employees bring the power of their perspective to the table to create solutions with our clients that benefit businesses, communities and people everywhere.
We continue to be a leader in the industry, awarded as a top home for innovators and for creating an inclusive workplace. Through our unique ideas and talents, together we help make money work for the world. This is what #LifeAtBNY is all about.
We’re seeking a future team member for the role of Risk Controls Self-Assessment Control Owner to join our – Insider Threat team. This role is in Pittsburgh, PA, Lake Mary, FL –HYBRID.
In this role, you’ll make an impact in the following ways:
1. Control Assessments and Facilitation:
- Host and support business units in performing Risk Control Self-Assessments (RCSA) for insider threat controls.
- Ensure alignment with regulatory requirements and organizational policies throughout the assessment process.
- Provide guidance and expertise to business unit stakeholders to identify, document, and assess control effectiveness.
2. Monitoring and Reporting:
- Continuously monitor the effectiveness of insider threat controls across the organization.
- Develop and maintain metrics and reporting mechanisms to evaluate control performance.
- Identify and escalate control deficiencies, gaps, or risks, and support business units in developing remediation plans.
3. Scorecard Development and Presentation:
- Design and maintain scorecards to summarize insider threat control performance and effectiveness metrics.
- Present quarterly scorecards to enterprise control managers, highlighting key findings, trends, and recommendations for improvement.
4. Collaboration and Communication:
- Partner with Insider Risk, Compliance, and Audit teams to ensure proper governance and oversight of insider threat controls.
- Act as a liaison between business units and enterprise control managers, ensuring clear communication of risks, expectations, and outcomes.
5. Continuous Improvement:
- Contribute to the development and enhancement of RCSA processes, tools, and frameworks to ensure efficiency and accuracy.
- Stay informed about emerging risks, regulatory changes, and best practices in insider threat management.
To be successful in this role, we’re seeking the following:
Education: Bachelor’s degree in risk management, Business Administration, Cybersecurity, or a related field.
Experience:
- 5+ years of experience in risk management, internal controls, audit, or insider threat programs in a highly regulated environment.
- Strong understanding of RCSA processes and enterprise risk management frameworks (e.g., COSO, NIST).
- Familiarity with insider threat risks, behaviors, and mitigation strategies in financial institutions.
Skills:
- Exceptional analytical and problem-solving skills.
- Strong written and verbal communication skills with the ability to present complex information to senior stakeholders.
- Proficiency in developing metrics, scorecards, and dashboards (e.g., Excel, Power BI, Tableau).
- Ability to manage multiple priorities and deadlines in a dynamic environment.
Preferred Qualifications:
- Experience with insider threat detection and monitoring tools.
- Knowledge of regulatory requirements (e.g., FFIEC, SOX, GLBA) and their application to insider risk.
- Professional certifications such as CISA, CRISC, CISSP, or similar are highly desirable.
At BNY, our culture speaks for itself. Here’s a few of our awards:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s