Overview
In this role, you will lead and execute first-line control testing to verify ICT risk, resilience, and third-party controls align with regulatory requirements. You will translate technical findings into clear business insights for stakeholders and support audit readiness. You’ll coordinate testing plans, evidence collection, and remediation tracking across multiple domains, contributing to continuous improvement of the Digital Operational Resilience program. This position offers impact by strengthening regulatory compliance, control effectiveness, and audit readiness in a global financial ecosystem.
Responsibilities
- Plan and execute first-line control testing aligned with regulatory requirements across ICT risk, incident management, resilience, and third-party risk
- Assess design and operating effectiveness of key controls supporting regulatory compliance
- Conduct walkthroughs, evidence reviews, and sampling following defined testing methodology
- Maintain traceability and consistency of testing across controls, entities, and domains
- Document test procedures, results, and conclusions with clarity
- Identify control gaps and non-compliance, translating findings into actionable business recommendations
- Produce management reports, working papers, and summaries on control effectiveness
- Track remediation actions, validate closure, and support retesting activities
- Ensure audit-ready documentation for DOR-related controls (policies, procedures, evidence)
- Coordinate responses to internal/external audits and regulatory requests
- Strengthen control narratives and evidence quality to meet regulatory expectations
- Contribute to lessons learned and continuous improvement post-assessments
- Coordinate testing plans, timelines, and dependencies across stakeholders
- Engage with technology, risk, compliance, and business teams to facilitate testing and remediation
- Provide structured updates to governance forums on progress, risks, and findings
- Escalate issues with clear recommendations and mitigation options
- Enhance testing methodology, templates, and quality standards aligned with DOR
- Promote best practices in evidence management, traceability, and documentation
- Identify opportunities to improve efficiency, consistency, and automation in testing and reporting
Key requirements
- University degree in IT/Engineering/Science
- 5–8 years of experience in technology risk, internal controls, audit, or compliance testing
- Proven experience in control testing and audit readiness in regulated environments
- Exposure to DORA or similar regulatory frameworks is highly desirable
- Understanding of technology risk domains (ITGCs, resilience, security, outsourcing)
- Excellent attention to detail and commitment to high-quality deliverables
- Ability to articulate technical findings into business-oriented insights
- Strong planning, coordination, and stakeholder engagement skills
- High degree of ownership, autonomy, and accountability
- Structured, analytical, and solution-driven mindset
- Experience with control repositories, evidence management, and reporting tools is an asset
- Attention to detail
- Strong communication
- Stakeholder management
- ICT risk
- Resilience
- ITGCs
…
