Overview
In this role you drive independent oversight of technology and cybersecurity risk for Employee Platforms, shaping a multi-risk-stripe review strategy across on-prem and cloud environments. You’ll lead risk assessments, review third-party and cloud risks, and ensure governance aligns with policy and regulatory standards. You’ll work with cross-functional tech teams to identify control gaps and drive effective mitigation, impacting how hundreds of thousands of employees interact with technology. You will engage in risk governance forums and regulatory-facing interactions, bringing AI/LLM insights to accelerate quality outcomes.
Responsibilities
- Perform proactive risk management of operational risk through targeted assessments of global and regional technology processes for the Employee Platforms function
- Develop data-driven strategies to monitor risks, leveraging enterprise tools for feedback and analytics
- Engage and collaborate with wider 2LoD technology teams to understand the technology and control environment supporting Employee Platforms
- Understand third party risks and resiliency related to specific technology area
- Participate in assessment of emerging risks and stay updated on technology trends, vulnerabilities, and new tech
- Continuously monitor advancements and integrate risk considerations into oversight and risk assessments of Employee Platforms
- Monitor and assess significant events where technology is a factor, including incidents driven by third parties or threat actors
- Understand and utilize AI/LLM trends to streamline assessments and improve turnaround times
Key requirements
- BS/BA degree in computer science or equivalent experience with deep and broad understanding of cybersecurity and technologies, and associated risks (10+ years in product, data, cyber, or tech ops)
- Strong understanding of cybersecurity principles, practices, and frameworks (e.g., NIST, ISO 27001)
- Familiarity with third-party outsourcing, cloud, data protection, and privacy regulations (e.g., GDPR, CCPA)
- Ability to collaborate with high-performing teams and individuals across the firm
- Excellent written communication; ability to translate technical information into clear language
- Curiosity and understanding of AI/LLM’s with capability to integrate usage where appropriate
- collaboration
- clear written communication
- attention to detail
- cybersecurity frameworks (NIST, ISO 27001)
- third-party risk management and outsourcing
- cloud and data protection
…
