Vice President, Control Design and Monitoring - Tech, Cyber, Data

SMBC, L.C.
Charlotte, NC, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Document Management Systems Identity and Access Management Data Logging Data Management

Job description

The Business Control Office (BCO) has the responsibility to ensure the implementation of consistent risk control frameworks and establishment of efficient risk controls across SMBC Group AD. The Control Design and Monitoring function is a central BCO function responsible for overall development and execution of 1st line control testing and monitoring program. The VP, Cybersecurity, Data & Technology Controls Testing and Monitoring is responsible for evaluating the design and operating effectiveness of key Cybersecurity, Data and Technology controls within a financial services environment. This role requires conducting control deep dives, executes controls validation/testing (including sample-based testing), develops and performs ongoing control monitoring routines, and partners with Technology, Data and Cybersecurity stakeholders to identify control gaps, drive remediation, and enhance the overall Information Security control environment.

The role requires strong expertise in IT risk management, data management and cyber security, and control assurance, with demonstrated ability to operate across first line technology teams, second line risk/compliance, and internal audit.

  • Execute risk-based control testing across cybersecurity, data management and technology domains to ensure compliance with internal policies and applicable rules, laws, and regulations
  • Perform Control Monitoring/ Testing routines with detailed documentation, walkthroughs, analysis and evaluation of the current processes
  • Assess the effectiveness of the controls and make recommendations for enhancement and strengthening of the control environment
  • Prepare detailed work-papers and Monitoring results reports summarizing scope, methodology, and significant conclusions of testing/ monitoring performed within prescribed time frames
  • Clearly communicate the Program requirements and the results with stakeholders and drive remediation where needed
  • Assist in the reporting and tracking of identified issues and corrective action plans to validate remediation efforts
  • Perform deep dives of Cybersecurity, Data and Technology controls across all assets to identify areas of control weaknesses and process inefficiencies that may need enhancement
  • Possesses solid background knowledge and understanding of Technology, Data Management, and Cyber Security standards, frameworks, policies and compliance regulations

Requirements

  • 5+ year experience in Audit/ Operational Risk/ First Line Control Testing with strong understanding and knowledge of financial services industry, with at least 3-5 years of specialized experience within Cybersecurity and Technology Risk and Controls Assurance
  • Hands-on experience performing design and operating effectiveness testing of technology/cyber controls, with ability to document Control testing findings and perform trend analysis and report production
  • Expertise in control frameworks, control assessment and control monitoring programs
  • Strong communication (both written and verbal) and time management ability
  • Experience interacting with senior management within a business environment
  • Strong critical thinking, analytical and organizational skills
  • Strong understanding of control frameworks and standards such as NIST CSF / NIST 800-53, ISO 27001, CRI Profile, CSA CCM, COBIT, FFIEC and/or internal banking control frameworks (FRB, NYDFS)
  • Demonstrated knowledge of cyber security control domains (IAM, vulnerability/patch, monitoring/logging, endpoint, network, cloud)
  • Preferred Certifications: CISA, CISSP, CISM, CRISC, CIA (any combination)

EOE, including Disability/veterans

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:43 min

Reviewing deterministic security controls and compliance frameworks

Carey Liu Carey Liu · World Congress 2026 Europe

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all