Director IT Embedded Risk
Role details
Job location
Tech stack
Job description
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT capabilities, analyze and remediate risk items (e.g., issues, policy deviations), and for proactively identifying gaps in processes and controls.
The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and lead or participate in projects within assigned areas of responsibility.
In carrying these responsibilities, the incumbent must work collaboratively with the IT Risk Management team (including Management Control Testing and Center of Excellence functions), other risk & control functions (e.g., Internal Audit, Technology Risk Management), as well as with IT line management (1st line).
Your Primary Responsibilities:
- Proactively lead and support efforts to identify, assess, and mitigate risk within the Enterprise Product & Platform Engineering (EPPE) department
- Develop, communicate, and ensure alignment to department risk policies, procedures and standard methodologies
- Contribute to documentation of processes and controls across cloud, mainframe, network, and database technologies
- Advise and periodically review inherent and residual risk assessments for supported IT capabilities for their impact on business and functional areas incorporating indicators of control environment strength (e.g., key metrics, issues)
- Contribute to reviews, and validate the accuracy of, risk assessments conducted by the second line of defense (New Initiatives, Third Party Risk, Compliance)
- Reassess existing processes and create new ones that most optimally anticipate, lead and reduce risk to DTCC and its participants
- Cultivate an environment of regulatory awareness and ensure regulatory compliance
- Demonstrate and embed the behaviors and proficiencies that build a risk management attitude in your organization
- Support ongoing staff education; mentor and develop team members on technical capabilities and risk management concepts
- Drive successful action plan and issue closures by assessing root causes of issues, defining appropriate action plans, and ensuring sustainability of implemented solutions
- Support reviews of initiative portfolio risks with initiative sponsors, key stakeholders and the New Initiatives Office
- Lead review of risk incidents, corresponding root cause analysis and remediation plan development. Proactively identify issues and trends resulting from risk incidents
- Develop and strengthen relationships with IT partners and control evaluation functions across the 3 lines of defense
Requirements
- Minimum of 10 years of related experience
- BA / BS and/or equivalent experience. Advanced degree preferred
- Audit or Technical Certification preferred (CISA, CRISC, CISM, CISSP, etc)
Talents Needed for Success:
- 10+ years' experience as a senior risk and control professional, preferably within technical auditing/ examination and focus in financial services industry (or other highly supervised industry)
- Background in financial services information technology or Big 4 technical advisory services a plus
- Highly motivated, detail-oriented, self-starter, who can set priorities, take initiative and work both independently and proactively in a diverse, multi-location team environment
- Excellent analytical and problem-solving including for data identification, analysis, measurement and reporting
- Excellent written and verbal communication skills; ability to tailor messaging to various levels of management including to risk committees
- Demonstrated ability to oversee and own an IT risk team that serves as a decision-making tool for management
- Strong planning and project management skills; ability to define, communicate and balance priorities across the team
- Knowledge of the security markets, post-trade processing and clearing and settlement infrastructure preferred
- Ability to lead technical, risk focused discussions with key stakeholders to analyze vulnerabilities and deviations from standards (e.g., security requirements)
- Understanding and working knowledge of cloud technologies including cloud engineering, private cloud delivery, and server virtualization
- Understanding and working knowledge of disaster recovery and infrastructure resiliency concepts including data center operations and rotation
- Technical understanding of mainframe and network technologies including application of quantum computing readiness principles (encryption, key management)
- Exposure to risk and control concepts including technical diagrams (network diagrams), risk and control identification, control evaluation (design and operating effectiveness), and related reporting
Benefits & conditions
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).